Ask HN: Are others seeing Google's reCAPTCHA rejecting Firefox users?
Is this part of Google's war against ad-blocking and non-Chrome browsers?
Is this part of Google's war against ad-blocking and non-Chrome browsers?
I refuse to pay a company for service and then be required to identify motorcycles and traffic lights every time I sign in. I went a few rounds with Vultr customer service and they said (paraphrasing) "It's not something we can fix, you have to talk to Google about it". Right... Google forced you to put their captcha on your web site.
"Neither a sender nor any person acting on behalf of a sender may require that any recipient pay any fee, provide any information other than the recipient's electronic mail address and opt-out preferences, or take any other steps except sending a reply electronic mail message or visiting a single Internet Web page"
https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C...
A simple reading says, no. But I guess they don't want to put that in writing.
We quickly figured out that the server didn't validate the captcha challenge code with Google. It worked for 3 years until they changed the system to send a code via email to validate your login, and limiting you to 1 session at-a-time. Now we have different problems to deal with...
How do you prevent credential stuffing attacks?
>especially if it blocks important functionality like closing your account.
That just falls under standard tort law, not to mention recent "click to cancel" legislation some states have been introducing.
CAPTCHAs don't work anymore, at this point. AI can trivially solve them.
Rate-limit the number of attempts, test accounts against known-password lists like HIBP, and support 2FA.
The point is to raise the cost, not to create some impenetrable barrier. A $5 vps can make hundreds of requests per second. IP bans and rate limiting forces people to use residential proxies, which are like $5/GB. That's much more expensive, but still cheap. Not sure about the token cost of AI is like, but captcha solving service used to charge around $0.002 per solve, which increases costs even more.
OS, browser, fingerprinting, networked bytes, residential address spaces.
All of it is done.
If a website/app goes passkey only (or, even worse, if it starts relying only on one-time email codes), I won't use it.
I know plenty of others who feel the same, though I don't know if we're numerous enough to put a dent in a company's bottom line or not. I imagine it depends on the company and its target audience.
Passkeys or magic links seem like the way forward here.
That's basically a passkey without its special API.
The point is to stop the attack and prevent users from accidentally hosing themselves.
Email services don't even support true 2FA; many claim to, and ask for a 2FA code for web login, but connecting an email account to a client via POP or IMAP bypasses that.
> Email services don't even support true 2FA; many claim to, and ask for a 2FA code for web login, but connecting an email account to a client via POP or IMAP bypasses that.
"In less than a year, passkeys have been used to authenticate people more than 1 billion times across over 400 million Google Accounts. Passkeys are easy to use and phishing resistant, only relying on a fingerprint, face scan or a pin making them 50% faster than passwords. In fact, on a daily basis passkeys are already used for authentication on Google Accounts more often than legacy forms of 2SV, such as SMS one-time passwords (OTPs) and app based OTPs (such as Authenticator apps) combined."
https://blog.google/innovation-and-ai/technology/safety-secu... (April 2024)
Don't forget: Microsoft is killing passwords. How to set up a Microsoft passkey before August deadline. - https://mashable.com/article/microsoft-passkey-how-to-passwo... - June 20th, 2025
(All major email providers support either passkeys, or in the case of Microsoft, passwordless ["strong authentication"]; we can consider the user creating an app specific secret for an external mail client minimal risk if performed after strong authentication has occurred, as the odds are low of that secret being phished or exfiltrated once configured in their mail client of choice, for the few folks interested in such a user experience with web based email services)
Maybe Lennart needs to write systemd-passkeyd .
That said I have run into a number of unsolvable captchas lately on firefox. Had to use chromium on a healthcorp insurer site.
I do use Firefox. And I couldn't cancel my account myself: had to request it via email since I couldn't login. They were good about doing it right away and said they issued a refund for the balance.
It does it for me if I use a VPN (Mullvad) - if I don't use a VPN then I haven't noticed I get them.
But yeah, very annoying.
https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...
At this point captchas need to be completely removed everywhere. They aren't effective and just waste time.
Edit: looked up the term, DDG shows a Wikipedia card saying "A tarpit is a service on a computer system that purposely delays incoming connections." (purposeful)
It may seem purposeful on Google's part but I bet that if we could get through to the developers for answers, it's probably not designed that way but we're running into a case where the system isn't designed to handle it
Which could be said to be intentional (excluding people with our FOSS setup), I guess
If you can reliably use it, you are not at the "deepest" bot detection level.
It feels like I have to go slowly through it only for it to eventually end in a “please try again” as I sit and wait ten seconds for each square to slowly fade in a new stupid bus for me to click.
How is this fair to the humans?
There is no good automated answer. Things bots do to abuse web pages should be made illegal and then jail (fine...) the people who set the abusive bots loose - but I suspect most abusive bots are foreign and so we can't do anything without sending in an army (obviously unacceptable)
Cognitive overload. There's days I'm just straight up tired and don't realize it until I'm at least one "please try again", page refresh, and endless traffic light game later that I'm probably in the tarpit and wonder why.
The weird thing is that I don't KNOW why. I use good ol' consumer Chrome, good ol' consumer MacOS, a consumer ISP, and my IP isn't in any kind of reputational blacklists that I'm aware of.
cloudflare bot detection has convinced itself I am a bot however (I do a lot of automated web related stuff on my home IP) and that's been an eye opener for sure... I can't enjoy a good 20% of the internet it seems like now.
Doesn't matter how many times I click that cloudflare button, they don't believe me.
And I've been signed in to my cloudflare account (which I've held in good standing with a live credit card for years) the entire time :/
One method that does seem to help is being sloppy when clicking the "I am a human" checkbox. I suspected that bots were more likely to perfectly click the center of the checkbox every time and decided to try clicking the padding around the checkbox instead (which still registers as a click). It seems to be more successful, but it could be my imagination.
This site is exceeding reCAPTCHA Enterprise free quota.
That’s new, but problems/loops aren’t.For me, hCaptcha has stopped working immediately before last weekend, regardless of the site that uses it.
It goes in an infinite loop, despite solving correctly all challenges.
On Linux, I have tested with 2 browsers, Firefox and Vivaldi, and the browser did not make any difference. I do not use any ad blockers, nor any non-standard extension.
So I think that they deployed a version update last Friday, which for some reason is broken on Linux.
It would not be surprising if both hCaptcha and Google ReCAPCHA have made some similar changes, so now they are both broken on Linux.
Meanwhile, some other "Captcha" applications from other vendors, which are used on other sites, still work like before.
I tried searching the interweb for a cause/fix, but couldn't find anything sensible in the flood of low-quality SEO hijacking webcrap returned by multiple search engines. So I asked AI.
The claim is that it could be caused by the blocking of some DNS providers (NextDNS, Quad9, ..), and it suggested using a VPN or phone tethering.
And lo and behold, both suggestions worked, without any browser setting changes.
It's very annoying and inconvenient.
Sometimes the audio recaptcha works. But, most of the time I can't understand the garbled audio.
Closing the tab always resolves the problem.
You may want to use "Buster: Captcha Solver for Humans"[1], which uses the audio option to solve the CAPTCHA.
There are even several speech recognition methods, like wit.ai, which is basically from Facebook:
$ whois wit.ai | grep "Name Server"
Name Server: b.ns.facebook.com
Name Server: a.ns.facebook.com
Name Server: c.ns.facebook.com
Name Server: d.ns.facebook.com
[1] https://github.com/dessant/busterhttps://i.ibb.co/Q7qTtK16/Image.jpg
Note I posted the comment only once a day ago. Thread ID seems the same, but old timestamp is visible in my profile. Important issue for information freedom, HN relevant, so it’s back new on the front page?
Edit: good job Social-Protocols, its graph accommodates this unexpected (to me) scenario: https://news.social-protocols.org/stats?id=49555592
I made this post and it died on its arse initially, didn't even get an upvote. The second chance pool meant that it turned into a useful discussion about a pretty niche element of frontend development.
The worst trigger is searching Google from the address bar.
Loading the homepage first makes the problem notably less common. Or getting a couple wrong.
>archive.today doesn't use a real recaptcha
How? It's loading the script from google, and the images/responses are from google to.
https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...
https://arstechnica.com/tech-policy/2026/02/wikipedia-bans-a...
That whole debacle is even specifically relevant to this thread because the operator of archive.today (aka archive.is) was caught using a script on its captcha page to make visitors' browsers connect to the blog they were mad at. That's how their DDOS attack worked. They used their own visitors, who naturally trusted the captcha page, to commit a crime.
For whatever reason, with the exception of Wikipedia (bless the editors), they seem to have gotten away with this, as well as with deliberately falsifying the content of "archived" pages (as described in the arstechnica article), without consequences.
So, call me crazy or a Russian bot if you want, but I think it's reasonable to be suspicious of any weird captcha behavior from this website in particular.
Presumably you are and do. We differ.
either change the user-agent to the newest version for WINDOWS
and/or use cloudflare warp which is technically a free non-privatizing VPN
on linux you can use warp via wireguard + WGCF
* reddit.com/r/CloudFlare/comments/ty9hke
Separately, if I were seeing a captcha that I can't get past, my first reaction would be to find a different site to see if it's a site specific issue, because some sites intentionally configure their captcha to work like that (e.g. you can't get in until you have been stuck solving captchas for at least a minute). I would see that more as a signal that the site operator is user hostile and not attribute it to a captcha provider.
So is this CAPTCHAing because I refuse to navigate the ad-infested way? How can I rule out a problem on my end if my router is ISP provided with limited functionality ?
Also firefox from linux. Just leave the pages open and refresh them every 20 minutes or so.
I can only guess the goal was to keep users on that page longer to keep sending off more spam requests.
Half the time "Sign in with Google" doesn't work from Firefox either.
Ich bin kein Roboter. Diese Website überschreitet das kostenlose reCAPTCHA Enterprise-Kontingent.
I am not a robot. This website has exceeded the free reCAPTCHA Enterprise quota.
NIH support staff is even worse as they refuse to acknowledge the issue and reply with a scripted useless response.
If I remember correctly, Recaptcha doesn't work on GrapheneOS either which is a separate issue.
Does not reproduce today though, and I never had issues with PMC/NIH before that.
Advertisers on Google should be paying a lot less than they were a year ago.
I wonder how the Google Search page traffic has been affected by the recent AI surge.
Very anecdotally, of course, but in my social circle (middle-class urban Romanians in their late 30s and early 40s) almost everyone I know has replaced a phrase like "I googled it and I found this and this and this" to "I chatGPT-ed and I found this and this and this" (where "chatGPT" can also be sometimes replaced by Claude and, not that often, by Gemini).
but .... my user agent is way more finger printable then it should (e.g. has the Linux x86_64 part) so that might make the difference.
I think it's fair for Google not to fix Firefox's shims, so I don't know who to blame for this. I doubt it's part of some big conspiracy against Firefox, though. I don't think Google cares enough about Firefox to bother annoying Firefox users.
Archive.is has had downtime this weekend when I tried to use it. They also regularly pull shady stuff, so I wouldn't be surprised if they did something stupid again and got themselves banned from reCAPTCHA.
“Um, I know this may be a very personal question, but is it possible that you…could we say…may be…a Robot?”