> mCaptcha makes interacting with websites (computationally) expensive for the user. A well-behaving user will experience a slight delay (no delay when under moderate load to 2s when under attack; PoW difficulty is variable) but if someone wants to hammer your site, they will have to do more work to send requests than your server will have to do to respond to their request.
According to the docs (https://github.com/mCaptcha/mCaptcha/blob/master/docs/CONFIG...), you can set three difficulty levels:
MCAPTCHA_CAPTCHA_AVG_TRAFFIC_DIFFICULTY
MCAPTCHA_CAPTCHA_PEAK_TRAFFIC_DIFFICULTY
MCAPTCHA_CAPTCHA_BROKE_MY_SITE_TRAFFIC_DIFFICULTY
The defaults are set such that avg traffic takes ca 0.02s on an average system. Even if you have a really really slow system, I don’t think you‘ll ever spend more than 2s there.
According to the screenshots of XMRig for android you only get about ~35H/s while my laptop does ~2400. That's 68x faster so if it took my laptop 2 seconds it would take a mobile device ~130 seconds.
It screws with mobile users and makes the whole crypto PoW thing about it using too much energy many times worse. Not to mention botnets could make use of enough computing power to easily outpace any captchas thrown at it.
Is that for the specific proof of work algorithm mCaptcha uses? While I don't think you're going to get something that runs equally quickly on a low-end phone and high-end desktop, if it depends entirely on sequential operations and is not optimization-friendly you should be able to get much closer than 68x?
I think we‘d need to compare apples to apples, and not use Monero mining as a benchmark for mCaptcha. Also, as I wrote in another comment, the average case (server is not under attack) is 0.02 seconds on a laptop, and probably 0.4s on an Android device even if we do use xmrig-android as comparison. Compare that to manually identifying stairs on pictures with crappy quality (10 seconds?).
For example a raspberry pi (using as a substitute for a phone) can do about ~100 hashes a second while my laptop does ~2400. That's 24x faster so if it took my laptop 2 seconds it would take a mobile device ~48 seconds.
See the issue yet? :P
EDIT: According to the screenshots of XMRig for android you only get about ~35H/s which means it would take over 2 minutes to pass a captcha on a phone.
If you've got a bot farm tunneling traffic through residential IP addresses (hello, free VPN clients!) then those extra tries aren't such a problem.
Hell, some spammers are paying actual people to solve reCAPTCHAs. Those people do nothing but click fire hydrants all day. There's no way to prevent those clickfarms from working without some advanced traffic analysis that will break the internet for a significant amount of people behind weird carrier middleboxes.
reCAPTCHAs are excellent at keeping away very basic bots, like Python scripts that just call HTTP endpoints. If you're trying to fight bots using browsers (WebDriver and friends), blocking bots becomes significantly harder, to the point your normal users will start to suffer if you set an effective bot prevention limit.
reCAPTCHA v3 doesn't involve clicking on images.