If anyone from OSM is listening, it would be great to have a way to flag malicious uses of captchas, like in phishing attempts. The existing captcha platforms make this very hard.
If anyone from OSM is listening, it would be great to have a way to flag malicious uses of captchas, like in phishing attempts. The existing captcha platforms make this very hard.
This is as user hostile as it gets (and of course always combined with a gdpr pop up followed by a subscribe to email pop up which overlaps with the please login pop up).
100%, I have never passed those captcha, guess I'm really not human.
It's abhorrent. Lying to users, gas-lighting them into thinking they weren't answering correctly and need to try harder when in fact no answer will ever be accepted. Ostensibly meant to be a system which prevents automatic systems from abusing resources meant for people, it becomes an automatic system abusing people. This bullshit should be illegal. If they want to turn people away for defying their surveillance apparatus they should do that upfront, without the inhumane deception.
Victims just click through the captcha without thinking, but it makes automatic verdicting by security scanners a pain because they just see a captcha page: can't tell the brand being impersonated, or even if it's a phishing site
I wrote a post about a number of these which actually pretend to be Cloudflare! https://phish.report/blog/fake-cloudflare-interstitials
But yeah, I wouldn't even know where to report those API keys for abuse