HBO Max new Captcha system
twitter.com
twitter.com
Some of the solutions are clearly just wrong. I have a PhD in Computer Science and if I am failing multiple basic addition problems, I assure you that it isn't me, the answers are wrong.
I had to do the same audio puzzles and got the first audio puzzle wrong too, and I even had my partner helping me. It is clearly just a bad test bank. Which begs the question, if the answers are wrong and there are only 3 choices, then what's the point? Regardless of whether you are human or not you are going to guess it eventually in about 5 tries, which is what it gives you before locking you out.
We can probably gleam many insights about the people who made the app (how it works, how big the bundle is, how fast/slow etc.). I haven't used the app so I can't make any judgements about the organization behind it.
It's also an idea older than Conway, presumably, although I don't know for sure.
Often new management wants to put their stamp on things. I've been in situations where we've had to do major redesigns because a new leader wanted to leave their mark. I've been in situations where each new leader wanted a new logo to mark that they made a difference - 3 logos in a decade.
Companies often squander resources in this kind of way. That's not to say that some redesigns and changes aren't warranted, but these things happen often. Why has Google launched a dozen chat apps? Why do some apps get a huge push followed by being abandoned followed by a huge rebranding/recoding push followed by being abandoned again? Many people on here have speculated it's because people get promoted for launching big new things and not for things that seem "easy" like maintenance.
You're rightly baffled from a logical standpoint. When you start thinking about the humans involved in the situation, their egos, their priorities for themselves which might not align with the company's, etc., then it potentially starts to make more sense.
I'm guessing there was some contractual thing (perhaps cable related) around the HBO name or else someone made a very poor choice.
The new CEO from the Discovery side of the merger cancelled a bunch of HBO Max programming that was doing well, because their background is in cheaper to produce reality content. It seems fated to join the very long list of bad media mergers.
I can understand canceling Close Enough and Infinity Train because they're too expensive, but I don't really understand what it's hurting for them to just say on the servers and continue to be streamable. Hard drive space is pretty cheap, especially at HBO's scale.
I've heard it's possibly a tax writeoff, but then I've seen conflicting reports claiming that that's not the case, so I have no idea. How much ongoing costs were involved with keeping the animated shows I like online?
That sort of management-by-spreadsheet without any of the humanity or long-term vision almost every corporation used to have seems to be an ongoing trend, especially in media, and it’s showing. Discovery, who have McDonnel-Douglassed HBO and are behind this mess, are a particularly good example of the kind of garbage heap that leadership style gets you.
https://developer.apple.com/help/app-store-connect/transfer-...
https://support.google.com/googleplay/android-developer/answ...
I call this "New Vice President Urination Syndrome." The stank gets on everything until they learn to use the bathroom.
To be fair, many of the other apps also suck. I think it may be because Apple allows TV apps to be written in JavaScript, and some of them are almost certainly poor ports of Web apps.
My pet peeve on the last version was having a carousel movie expand when you pause on it so that it moves things around and hides what you were looking at.
My pet peeve on the new one is a normal swipe on the remote blows through 80% of the carousel items instead of just one.
Neither annoy me as much as Amazon’s hijacking of the touch pad during video so that I can no longer tap the pad to see how far through the movie I am.
I get it, everyone wants their spin on things. But all I want is a usable, consistent experience. It drives me bonkers.
Hell, HBO Max became available in my country just last year, replacing HBO Go. And I know there used to be HBO Now in some places, so I guess we skipped that one. And no HBO is available in some of the places where you really expect it to be, like German speaking countries.
It's the most bafflingly stupid streaming service I ever had the displeasure of using.
Subsequently having two separate codebase was probably considered preferable to development on one slowing to a crawl while it chased after two diverging requirements lists.
I can see there's no improvement.
A new app gives you a blank slate, which is easier than reverting old ratings.
I remember being nudged for repeated reviews by many apps, some explicitly listing that reason, before that was prohibited by Apple.
Surely that‘s among the worst things you can do from an SEO and customer retention perspectives?
From news reports and interviews with the leaders involved, it appears that new guard wanted to have something new they could own and take credit for, and HBO was owned by the previous regime.
None of Discovery's marques were strong enough, and the $$ to get Discover as a brand into the right place was high.
So, least of all evils, given their problem: scrub HBO off the name, make it one of many brands in the app, and hope "Max" on its own, with some marketing, can expand to fill the gap.
If it works, Discover team takes credit. If not, Discover team blames holdovers from HBO days and says that this was just an intermediate step on the way to a brand new experience that will launch "real soon now".
Lots of problems with this approach, but business isn't always rational.
Having a computer tell me I had to call a mailbox a parking meter is right out of some sort of Forbin Project 1984 mashup.
The hiding the dice under the arrow though is ridiculous.
As for your second question, yes.
This is more or less what cloudflare and such do now as I understand it (as well as checking browser features and such)
I also have a PhD in Computer Science and I assure you that the degree does not give me as much blind faith in my math ability
One of the requirements to getting a PhD is the knowledge that a PhD is not the proof of intelligence you thought it would be when you started. It is better a proof of resilience, patience, and being dead inside.
> Arkose MatchKey challenges have revolutionized CAPTCHAs
Some other choice quotes from the page:
> Users have a bad association with difficult photo CAPTCHAs.
> Instead of type what you hear (or alphanumerics) puzzles, we ask users simple questions using delightful and amusing scenarios
> All are incredibly easy for legitimate users
> Every Arkose MatchKey challenge is tested on humans. We release challenges only when they meet very strict usability benchmarks. Our strongest puzzles, designed for bad actors, have no impact on good user completion-rates.
> In fact, Arkose MatchKey is the strongest CAPTCHA ever made.
My mum regularly asks for help when all she's done is ignore the captcha thinking it's an advert because it stands out like a Google ad (different UI, different font, extra branding etc).
At least she's learnt to automatically ignore ads, but it comes with consequence of ignoring captchas as well...
And continually changing UIs definitely don’t help.
https://www.apple.com/newsroom/2023/05/apple-previews-live-s...
In the HN thread , a lot of people were calling it the grandparent mode.
The main value-add for companies like Arkose is that they have teams monitoring and changing the aggressiveness of the challenges as new attackers try to get around them. With a product like Recaptcha, you are inevitably completely screwed when attackers get around it.
Either these guys are full of crap or they are absolute Schönberg aficionados
Most CAPTCHAs, including ones made by Arkose, have site keys that are unique to that CAPTCHA and public/visible in the browser -- so companies like Anti Captcha can then automate sending challenging CAPTCHAs directly to a human solver in a 'CAPTCHA farm' who can solve it (in a different browser) and have the CAPTCHA return that it was successfully passed, usually all within ~a minute.
So to get around this and -- as Arkose's site says -- make fraud expensive for hackers, Arkose Labs has to make their CAPTCHAs hard/slow to solve. If they do that, then it becomes expensive for bad actors to rely on labor to solve them (anti-captcha.com cites 58 seconds/$3 per CAPTCHA).
As long as the site key is publicly exposed, this basically isn't going to change; you either need to also couple it with other anti-fraud tactics like device fingerprinting, or use a CAPTCHA that doesn't expose the site key at all.
Disclaimer - I work for a company (Stytch) that has a competing CAPTCHA product.
Captchas seem to work best when they reflect the simplest task that AI cannot do rather than a task AI can easily do but with the difficulty ramped up.
Same goes for the people who decided to put it on their websites.
A customer who can't get in isn't costing you precious CPU cycles.
Twitter’s new captchas are also pretty insane, though not quite this bad last I ran into them.
If we don’t have some way to prevent it, services will be increasingly populated by sophisticated bots either selling stuff, attempting security breaches, or pushing political agendas.
That’s a bad thing!
The current internet culture seems quite happy to slap captchas all over the place. When they first rolled out, captchas were predominantly a barrier for "write access" (e.g. make an account, complete a sale, write a comment). But companies like Cloudflare have been putting captchas everywhere for mere read access.
Because Captchas are designed to be easy for ("normal") people but hard for machines, they often disallow disabled users. I'm a ("mostly normal") 35 year old, but I _really_ struggle with captchas. I despise when Cloudflare tosses a captcha challenge before loading a page, as I'll need to spend 3-5 minutes of effort to figure out which tiny pictures have a stoplight, motorcycle, or crosswalk.
Will someone come up with a less restrictive anti-bot solution? I hope so. But even if not, I'm not sure it matters. According to comments in this thread (and elsewhere on the internet about the HBO Max captcha), many of these captchas are _already_ terrible at excluding robots. We're using captchas to exclude low-sophistication robots and disabled users. Seems wrong.
Are you imagining this would spur people to create a different, bot-free (how?) and disabled-human friendly Internet?
As AI becomes more intelligent, you can prove humanity by exploiting our weaknesses.
(Another idea. Have a random image on a page actually be a text box with an image background. You cannot activate it if you focus on it, with your mouse or touch, but a bot doesn't need focus to change input.value.)
CAPTCHA: Say something bad about Biden
ANSWER: I'm sorry, but as a large language model ...
We will soon need this, and I feel government will gladly present a solution: provide your ID when you connect to the Internet, and we will guarantee you are a human.
Who's actually working on this and has released papers I can study? Because all this AI nonsense will only accelerate us towards this total control of the Internet because the spam and AI bots have made it worse for everyone.
I guess spam is an issue currently, but if bots become advanced enough to avoid heuristics, by making insightful and useful comments, they are probably better than most human users.
Proof of work captchas like mcaptcha can stop, or at least make very expensive, (d)dos attacks.
It's all fun and games until foreign agencies are controlling who wins in your elections through misinformation and propaganda.
Or an AI using a human's ID?
https://scholar.google.com/scholar?hl=en&as_sdt=0%2C5&q=capt...
Because in the age of ever smarter AI do you really want to solve CAPTCHA more and more frequently, and not to show you're not a bot, but to prove you are human with a physical body borne from an ovum.
It is not crazy to think we will eventually need to prove this fact somehow.
> We will soon need this, and I feel government will gladly present a solution: provide your ID when you connect to the Internet, and we will guarantee you are a human.'
I'm extremely hesitant to give any State the ability to track an individual user's online activity that intensely. It's been extensively documented that any State will fully utilize its size to violate an individual's personal privacy, with this often being done on a grand scale.
> Who's actually working on this and has released papers I can study? Because all this AI nonsense will only accelerate us towards this total control of the Internet because the spam and AI bots have made it worse for everyone.
The alternative is relatively straightforward: Utilize compute-intensive & memory-intensive tasks in CAPTCHAs.
https://github.com/mCaptcha/mCaptcha
What would only take a few seconds for a single user would take hours for anyone seeking to establish a bot network spanning thousands of pseudo-users. With such tasks, it adds additional friction to the bots at minimal frustration to the user. these can be placed as periodic silent challenges when trying to watch an episode, taking up only a few seconds at the user's end where they wouldn't notice.
but it's absolutely not a captcha: it is not a test to tell humans and computers apart. it's a test that can only be completed by a computer. its only utility is to be expensive. it's not a test to determine if there's a human behind the computer, it's only a test to determine if the computer has more resources than it currently needs, and can tolerate wasting some of them for a while.
The claims on the mCaptcha site contradict this. They say it takes about 2 seconds worst case for a computer to do the work, which is hashing sha 256. Looking around, an unaccelerated celron is about 1/20th the speed of a single ryzen core, and gpus are much faster.
Assuming the attacker has an 8 core ryzen with no gpu, they can hash 160 times faster than the person with an older machine.
Assuming the 2 sec upper bound is correct, this means a sub $1000 desktop can create 80 accounts per second, or 4800 accounts per minute.
If they are operating a botnet, then they presumably have access to more than one machine.
One look at what happened with cryptocurrencies tells me that isn't going to work.
What I am asking for is a reverse Turing test. Because there will come a time that any single site will need you to prove you are a human to do any action, i.e. post a reply or create an account.
We need a better plan than CAPTCHA that takes minutes to solve every time someone needs that type of proof.
I know government ID schemes are awful for privacy, but that is the only decent solution I can think of. If we, the computer people, do not have a better solution, the government will solve it for us, big tech will adopt it, and we have opened the doors to total surveillance.
The U.K. government developed something called GOV.UK Verify for exactly this.
It’s sort of like OAuth via a stateless gateway I think. The promise is that the entity doing the auth doesn’t know what you’re using it for, and the entity receiving the auth doesn’t know how you proved auth and only gets the level of detail about you they asked for (and you agreed to).
For example, if a govt website wants to know whether I’m eligible for something based on my local council, I could authenticate with my bank, who would say where I live with only that granularity, not my full address, and my bank wouldn’t know what service I’m trying to use.
I’m not sure how much of this got put into practice but all the ideas were pretty smart and showed there are good approaches to this sort of stuff.
The PM did not like the idea of the government being the porn passport for the whole country.
To me, that's still *way too much*.
Just from that, the government now immediately knows what site you've been to (via the token that you've given to the service), and what said site has access to, as well as when you've accessed it. On a long enough timescale, the government can build a daily profile of your life, that when coupled with geo-location data, can be used to see what & where an activity's happening in real time.
If I understand the idea correctly, this isn't how it works. Your user agent sends a signed request (with proof of identity) to the GOV.UK verification server, saying "please give me a signed certificate that provides no information other than my age". Because GOV.UK knows who you are, they can provide such a certificate. Your user agent hands this to the porn site, saying "you requested proof I was over 18, here's proof". Because the certificate was signed by an authority the porn site recognizes, they approve the certificate and let you in the site.
So the government doesn't know what site you visit, and the porn site doesn't know any of your personal information.
Each agency holds only the data they need for the time they need it. There are no national ID cards. And in the case of Verify, the verification was purposefully outsourced to private companies that already had this data due to their business (e.g. your bank, PayPal, Amazon who have a trustworthy address history, Experian, and so on).
Commenter 1: System X is evil!
Commenter 2: Actually, here is how system X works: (Demonstrates it does not work how Commenter 1 thinks it works)
Commenter 3: Well that's fine, until they change X to be evil!
I mean, sure, when X becomes evil, then we can say X is evil. But not until then. If your argument is that all systems eventually become evil, that may be true, but it's a different discussion.
This is a pretty dumb argument on the internet.
Me (1995): says something really stupid on the internet
Me (2020): shit hope on one finds that 1995 post and cancels my ass
With internet traffic and logging the default assumption should be: "All this data is logged and monitored for marketing purposes, and there is nearly a 100% chance it will be leaked by some hacker group", with the 2023 corollary of "And then used to train a LLM"
I think our (Germany) national IDs would theoretically have that option using certificates. I didn’t look too much into their online features as I never encountered anything supporting them, but my understanding is that I can prove some fact about myself (age, name, or simply being a citizen/resident), without either the government knowing I did it, nor the company knowing more than what I asked to show.
Visitor A is a legitimate human being from a poor country using a bargain brand Chinese phone with hardware that could be charitably described as "slow as molasses".
Visitor B is a troll for hire with a rack of used crypto mining machines in his basement, running hundreds of Chrome processes proxied through hundreds of hacked residential IP addresses.
Your approach would make the website unusable for human visitor A, while being the tiniest bit inconvenient for visitor B's hundreds of alts.
https://techcrunch.com/2022/06/21/apple-is-introducing-new-t...
But essentially allowing people to make "identities" via cryptography and then use a reputation system. Preferably by allowing people to follow/whitelist/favorite people across websites.
I like hacker new's method of making new people green. And I wish I could make it highlight the big names I recognize.
The problem with this is that nobody has figured out the distribution system for how we communicate the keys - IMO blockchains are the closest but it's so difficult to mention them because 98% of them are money-grabs. PGP/GPG has struggled so hard pypi literally removed support for it.
The second problem is that what will likely happen is sites like twitter will only allow very trusted accounts and never allow new ones - effectively locking you into one account.
git is a really popular blockchain, though I guess GitHub seeking to Microsoft may further the money-grab argument
I mean what people call "blockchain" in the cryptocurrency sense as actual projects - there's so much stigma largely because the motivation of most of the projects appears to be "making money/investing" and not actually solving a technical problem appropriately.
If github was like this there would be a "fee" for making making commits, this fee would be paid in some proprietary coin, initially created with an ICO/airdrop. Suddenly the motivation is holding these coins because developers will need to make commits right? And the more developers that make commits the more the coin is worth, so surely you should buy and hold them right? This will be a feedback loop of endless money! Oh and it'll be a DAO so the more coins the more voting power you get too!
^ This is what I mean, where the focus is on collecting some "coin/token" - this leads to both a lack of focus on the actual problem being solved, and the problem of people associating it with a ponzi scheme.
I'm not picking a fight with distributed graphs themselves, I don't like it when they're tightly coupled with "value" that can be traded as a fiat.
Why do sites need human verification anyway? If the problem is load, then you just need proper rate-limiting in place. Captcha always seems to be mis-identifying the real issue.
Unfortunately crypto folks are too busy selling shitcoins and scams to build this product.
in trying to prevent bots from dominating, we end up making life very difficult for ourselves.
In the movie it is said that humans have scorched the skies in a bid to deny solar energy to the machines. But now humans have to live under dark skies.
I think the fact that users are willing to give the site the finger and leave is a pretty good sign that you're human.
Not sure what a world without capture is going to look like but it's probably not going to be very good, I guess we'll all be forced to identify with a our "world coin(tm)" ID?
That will be the time when I log off most of the internet.
Imagine a non-native-english speaking visually impaired grandma trying to register to a random web service. CAPTCHAs are not a problem, people say, there are the audio versions, so go for it! Oh, you were never able to pick a language? Too bad you dont speak english. Oh, your hearing is not the best? You are clearly not a human, official stamp from SV. Why? Oh, we just couldn't think of any other solution, so we implemented CAPTCHA and just dumped you and your pesky disabled friends. What?! You want to cross the digital divide? Not as long as we are in power!
Or more likely they do not care, grandma is very hard to monetize.
Once during development I got a captcha that said "select the glasses" where my options was a photo of sunglasses, or a pair of glass drinking cups.
I've tried them all, and my success rate doesn't noticeably change.
I think it's based on mouse movements, time delay between clicks, and browser fingerprinting tricks that detect headless browsers
However I think it is quite flexible. That box that is almost completely traffic light probably needs to be clicked, but as long as you pick at least one of those two that contain a corner you will likely pass. I would guess that there is some sort of accuracy score that is mixed in with the bot fingerprinting score.
I had some fun poisoning the well on the older text based captchas by answering the first word correctly and putting "penis" where the last word would go. It always accepted it for some reason.
lets take google/recaptcha/hcaptcha image captchas. english: "click on the images with bikes" this could mean motorbikes or bicycles in english.
in german it says "klicken sie die bilder mit den fahrrädern". fahrrad meaning bicycle exklusively! a motorbike would be "motorrad". then the images will show no bicycles so you skip - wrong - so you click on the motorbikes - wrong - oh there is one image that shows a (german) "motoroller" (a scooter) maybe they mean that? click - correct
this goes on an on and on. they have so many problems with their translations its infurating. i stopped filling them out when not absolutely necessary
loLz666.txt:
For the unlock password visit (somesite.ru/blah) and fill in 3 surveys.
Also, Arkose Labs CAPTCHA (what HBO Max is using) is awful, please don't use it. There's reCAPTCHA, hCAPTCHA, mCAPTCHA, and now even Cloudflare Turnstile. Or better yet, recognize your costumers can still download the movie for free whether your service exists or not and adapt your strategy to provide them with content easier :)
In case someone as been lucky enough to never have used hCaptcha, it looks like this: https://twitter.com/shaunkruger/status/1660671272672722945
https://www.vice.com/en/article/xgwy5n/captcha-is-asking-use...
edit: ah they seemed to have removed all traces of the token stuff from their website, except some small remains in the docs - https://docs.hcaptcha.com/faq/#what-is-one-hmt-worth . I guess they pivoted away, reasonably.
hCAPTCHA has always been easily solvable for me, haven't seen the one you linked yet but that also looks quite trivial
Ideally one just doesn't use CAPTCHAs at all, but my colleagues disagree and so that's unfortunately the company policy to recommend against login brute force and such
In other words. It's not anti-piracy mechanism, it's protection against account stealing.
It's a nuisance obviously, but for such a tiny fraction of people, honestly not bad if they notice that they got phished or use a password guessable within a handful of tries.
I remember one day in class we were doing a group project and using GitHub to share our work, and a friend of mine had trouble to log into his GitHub account and got this captcha.
A team of 4 people in the class went to help him pass the (if I remember correctly) 10 tries you needed to have correct in order to log in.
And they still took about 10 minutes!
It's more of a joke than an interface, like reddit's competition for the worst volume control: https://uxdesign.cc/the-worst-volume-control-ui-in-the-world...
Now you can argue that anything that has hitched a ride on moore's law has improved exponentially. In fact this is what several groups point to: Elon Musk stans love to argue how the world has gotten better not worse thanks to exponential growth and the government loves to point to the declining costs of things like TVs as an indication that inflation is not so bad. Its a red herring though. That new computer is so much better but now has layers of privacy invading/security compromising fat that ye old Windows 95 PC didn't have. That TV might cost a nickel but is more locked down and made out of more of the cheapest throw away components than your old Tube ever had. In a way its an insult to how decent your old TV was.
Never imagined this would be a career worth pursuing; it's grim when you think about it.
I am concerned though that this is just another form of inflation. If you think about it, you need to have the skillset to develop this software to your liking. That itself is a time sink but lets put that aside and assume you already have the skillset because you made the investment for other reasons. You could then argue that the investment made in learning how to make these apps is spread across this as well as anything else you use the skill for: GREAT Right?
Well, you are forgetting that you are sacrificing time to build and then maintain these applications. So in a way you are still paying for these applications.
Also one concern I have about your listing there is the same concern I have every time I force myself to use Linux as my primary system and then give up and go back to Mac: Curation.
Have you considered drawing up a list of typical workflows for a bunch of different kinds of users and then ensuring at least the common use cases are taken care of? As it stands, it seem like you have a lot of interesting apps but they are are just a hodgepodge of random things. There is no cohesive curation or (potential)quality control behind them.
This grinds my gears about Linux. You handmade apps get a pass but your typical distro? no way: They package together whatever desktop environment they like which itself consists of terrible everyday tools that have varying quality. Just open up the Calculator on a Gnome based distro. It is crummy compared to the Mac or Windows(classic) calculator. Then try out each and every other app on the menu. Seems like there was no real cohesion put into it.
Furthermore, lets just accept that you have to tailor these handmade apps to your liking and that eventually there will be a handmade app for everything a user could want. Ok fine, but I still hate the fact that in todays day and age, this idea has to be extend to EVERYTHING in your life. You gotta understand how to maintain your car because good luck finding a mechanic that wont do the bare minimum. How about the slop they serve at many food establishments? You have to "handmade" all your food/liquid intake. Ditto for everything else (maintenance or removing other ways corporations screw you).
How do you even preserve the value of the currency you try so hard to earn? You can't it is slowly going to 0.
It’s stupid and anti-user.
But why (from their perspective)?
They don't make their money from metadata, they make it from content. Every piece of real monkey-making content is going to get a torrent regardless of if it's protected behind a captcha.
Edit: I have some sympathy for this. Engagement is much harder to measure than customer satisfaction. They are looking for the keys under the light because they cannot see anywhere else.
Why be reasonable when you can be unreasonable and make more money.
It makes very little sense to me. Surely WBD wants people to easily find WBD content to watch, and easily be able to pay them to watch it.
I know Netflix has been a holdout (the only one), and it is quite a stupid long term decision in my opinion, but I would not have thought Apple pays WBD, Paramount, Comcast, Disney, Starz, etc to be able to list their purchase-able media in Apple’s TV app.
So it has a real login and, presumably, access to some api from the streamer. But a smaller company that didn’t pay for access could also just login as my accounts and scrape info.
its not strictly required, as in most cases you could just save cookies or similar locally, but weaker login systems are preferred.
Sum the digits on the dies? 5 lines of openCV should do the trick
Find which of 3 (three!) extracts is a repeating pattern?? Could this be any easier? This sounds actually easier for a machine than for a human being!
Not so fast: First the images show dices with a mixture of dots and numbers. Second the images are not from the top, but at 45 degree angle. By that one can also see the numbers/dots on the side of the dices. Distinguishing numbers/dots which are on the side from ones on the top is pretty hard. The algorithm needs to have an understanding of the 3d structure of the dices in the image.
It the remaining time is displayed as a negative integer, and for some reason the system just thinks the move is done and resets it to the beginning.
Seems like a bug that some very basic QA testing should have caught it.
The new rollout seems like a total clown show, and unfortunately it ruined the service and made it impossible for me to view movies, unless it is from a laptop.
I don't think its too much of an exaggeration to say this is what happens when security teams don't receive enough pushback from the higher ups or from other teams. I see this all the time in large big tech companies.
At some point some software engineer had to sit down, look at it, and say, "looks good to ship to production"
Only true if you replace "software engineer" with "person". Just because someone was paid to build it doesn't mean they thought it was a good idea or ready.
Fantastic. Good job.
https://www.tiktok.com/@gavinj1998/video/7237700278647016746
* Click all the dice with value 5.
* Click all the pictures with a roll of 4 and 5. (each picture shows a pair of dice).
If you test for pattern recognizing the number of dots on the top of the dice, then you can just verify only that. No need to make a human user to do a task that a computer can easily do.
I can imagine a bunch of users pulling out their phone calculator app to do the addition, which should tell how stupid this captcha is.
As recently as a few weeks ago I was watching a game downstairs, and it went into multiple overtimes so it was getting late. I decided to go upstairs to bed and tried to watch it on the AppleTV in the bedroom. I was logged out. So I spent over 10 mins trying to log in before eventually giving up and watching it on the iPad, since I happened to still be logged in on that device.
It is for the best, because even after you manage to log in, trying to navigate the menu with the AppleTV remote is an exercise in frustration anyway.
I've given up on websites just by seeing the first captcha made by them.
Incidentally, my other t-shirt would read "I don't care about your stupid app".
I've been told Arkose pay people to run these captchas and present lots of fancy metrics of attacks they've stopped (when in reality with Captcha's like this a lot of that is normal users) which is why some websites seem to be ok with destroying user experience by running this
I'd be surprised if anybody in a technical role decided on this provider
Both that that computers are very good at, and have been good at for decades now?
"All Captcha's could in the USA be illegal aswell under the ADA.... As some people with learning disabilities won't be able to complete them."
But how would you detect click farms with real humans via VPNs or compromised devices?
Not to mention AI, trained by those very click farms which may ramp up significantly the issue.
If a "valid" credit card or a wallet code is provided at account creation, a lot can filtered out (unicity, funds availability, etc).
Actually, there are so many ways to deal with that better than how it is currently done, I would have troubles to know where to start.
It is all about the skills of the people put in charge.
And these... I think epicgames also uses this horrible system, and I was on the brink of smashing something in the room, when I saw it.
There's no captchas on torrents, or trackers like thepiratebay.org
None at all.
Whereas you're evidently the enemy if you legit buy service.
What are these paid subscription platforms trying to protect?
Bravo HBO, you win this round.
/s
Someone recorded a computer screen with their phone. But that's not enough, it's recorded in vertical…
I'm really speechless seeing this level of IT illiteracy.
The completely messed up "captcha" fades away given that video…
Obligatory: https://www.youtube.com/watch?v=OaN2Y8GjIqA