Even so, the constant war of escalation between captchas and anti-captcha measures should eventually lead to the necessity to create a captcha which is impossible for most humans to decipher, once the capability of software to decipher them passes baseline human ability. At that point, just being able to solve the captcha would more or less prove you're probably not a human being. So the basic model of "text a human can read but a computer can't" is probably obsolete, and only still works due to the inertia of programmer laziness, and the fact that breaking captchas probably doesn't have a ROI worth the trouble for most sites.
Constructing more subtle captchas present their own problems, in that they can make cultural assumptions about the user. If you're also using the captcha as a community filter, this may be a feature though (for instance - having a site about anime set up a quiz about anime as a captcha, or having users solve complex programming puzzles.) Even so, any process which a human can perform through rote UI can be automated, so even those tests will fail. Most captchas are poorly designed and leak their solutions one way or another anyway. I've even seen a few posted here which seem to add their solutions in plaintext to the form as a hidden field or something.
I haven't got a clue what Recaptcha can be replaced with once it's thoroughly useless, but i've come to believe that captchas are one of those things it's impossible to do correctly, just adequately most of the time.
Yes, but there remains a cost. The goal of a security measure is to make it so difficult/expensive that it becomes worthless doing.
If we ask nicely, perhaps kogir will show up to say more.
YC now has (at least) two payment processors who could handle the transactions, either in real currency (Stripe.com) or virtual currency (Coinbase.com):
The payment processors will always have upstream fees that need to be paid, but if they're feeling generous, they could waive their profits on the donations.
If for some reason a person objects to donating to the EFF, then just give them a choice of charities, including the YC funded Watsi.org:
http://ycombinator.com/watsi.html
The altruism would also be good promotion for YC, Stripe, CoinBase, Watsi, and whoever else is involved.
If you want to give a break to the starving university students, then let them by-pass the donation requirement with an *.edu email address.
To keep everything fair between new and old users, the tiny donation could be an annual requirement. I sincerely doubt the kinds of hackers who want to contribute to technical discussions will have any problem with making a small contribution to one of many known-good charities.
Using an eventual required donation in conjunction with an initially usable account (e.g. allowing "X" days/comments/submissions before requiring a donation) might be able compensate, but it would not solve the underlying CAPTCHA, drive-by trolling, or spam problems.
It seems safe to assume the increased friction of requiring a tiny $1-5 donation (micro-payment) to a good cause will reduce the desired and beneficial contributions from people associated with a submission.
The tough question is, "By how much?"
It would be difficult to measure when associated people show up to add their contributions to relevant submissions. It would take just about all of the data on HN, and some very elegant code. The results would still be imperfect, but the results might still be useful. Even if actual measuring proves to be too difficult, a rough guess (opinion) of better/worse for before/after could still be useful. (Heck, removing per-comment karma scores "worked" to reduce hostility/competition even though we don't have any solid measurement data to prove it)
And the tougher question is, "Are we sure?"
Contentious comments (dumb/mean) have always been a problem in open discussion systems, and similar is true for abusive manipulation (spam, ring-vote, ring-flag, etc.). Having a gate of an act of altruism could also both assure intent/interest and improve quality enough to actively encourage associated people to consider commenting to be even more worthwhile than it currently is.
In other words, there's also a second less obvious safe assumption; we're far more inclined to join a good discussion on a topic of interest than a bad discussion on the same topic.
Without testing, we just won't know if the added friction of a required donation would be overall harmful, or overall helpful, or roughly even. Prior to Stripe/CoinBase/Watsi/... the idea of requiring a tiny donation just wasn't feasible, but now, it might be an experiment worth running.
But the toughest question is, "How much will it hurt to try?"
If it really did kill off contributions from associated people, then it would certainly need to stop, but other than the possible temporary reduction of associated contributions (which could be reversed), I'm unable to see any other real or lasting harm. Even if requiring a tiny donation turned out to be a totally failed experiment in forum design, it would still do some good in the world.
You might be totally right and it might fail in practice, but until we run the minor risks of actually testing it, we'll never really know.
https://www.google.com/recaptcha/api/image?c=03AHJ_Vutw8XwYq...
You can get so aggressive against new hostile users that you end up being downright hostile to new legitimate users.
For example, automatically marking posts from new users as [dead] without telling them is assuming that they are all bad people. If new accounts making new posts is a problem, then disable it -- don't let innocent new users make new posts and lie to them that they made their post when no one else can see it or comment on it.
I know this job is hard. I request that you simply turn features off instead of silently breaking them.
> automatically marking posts from new users as [dead] without telling them
HN definitely does not do that.
There's a current bug in Recaptcha.
IPs that successfully solve too many captchas get given progressively more difficult challenges, which is fine, but currently Recaptcha is using the IP of the web servers, not the client. This means that the difficulty ramps up for all users quite quickly. It seems the iframe Recaptcha is permanently affected, if you use AJAX its fine after the first reload (I wrote a simple JS hack that makes it reload the first time, see www.mPoll.me)
Only noticed it because I was previously proxying Recaptcha through the server and it run its successful solutions up too high, so when the new bug came in it was immediately obvious what had happened when the first challenge is "wthdyjikhgfyijv" and on reload its "fluffy bunny 18".
On my website I'm currently overwriting the Recaptcha callbacks to allow multiple captchas, just put in a simple check to reload it the first time:
var reloaded = false;
function reloadCaptcha(challenge) {
$(':input[name=recaptcha_response_field]').val('');
$('img.recaptcha').attr('src', '//www.google.com/recaptcha/api/image?c='+challenge);
$(':input.recaptcha').val(challenge);
if(!reloaded)
{
reloaded = true;
Recaptcha.reload();
}
}
Recaptcha.finish_reload = function(challenge,b,c){
reloadCaptcha(challenge);
}
Recaptcha.challenge_callback = function(){
reloadCaptcha(RecaptchaState.challenge);
}
Recaptcha.create(recaptchaKey);Then again... does HN really care about UX? Token expiration after x time when browsing through the listings, ancient unresponsive design, etc.
There comes a point where it'll be more cost effective for spammers to just farm out the solving of CAPTCHA's to people in third-world countries. It just depends if there is enough value in spamming HN for them to bother (probably not, given the user-curated-and-rated content model.
What can work well -- if you're willing to give up on fallback for non-JS users -- is inserting a required form element into the page with JS on submit.
Seems promising given that human visual processing and pattern recognition are lightening fast, and the slider is intuitive and kinda fun.
Anyone know how effective they are at stopping bots?
https://www.google.com/recaptcha/api/image?c=03AHJ_Vutw8XwYq...
My own personal pet peeve is people, on HN, who obscure their gmail address so that it can't be slurped by bots.
I mean why not just use a dedicated gmail account, just for HN, rather than "use my hn handle at that email service that everyone else uses generally". The dedicated account has spam protection and you can forward mail to your primary account as a filter if you want.
I have a couple of web forms with no spam protection at all. The amount of bots that I get isn't so great that I need to trouble people to figure out a captcha. Much less a really difficult one.
I handle about 250,000 submissions a day.
Contact-forms can easily be overwhelmed with spam, it's just a matter of how lucky you are, or not.
Any factors that you have been able to determine that quantifies why someone is lucky or not?
I have some sites with a "contact me" form which get hammered, and others that get one or two hits a month.
(Adding simple captchas, or hidden fields, etc, can work at the low end. The ones that get hammered though have bots/people that deal with that.)
Because starting, configuring, and checking ANOTHER gmail address takes more time and effort than obscuring my current dev-related email address to be human parse-able only. Seems like a strange thing to have a pet-peeve about, as it could only barely affect your ability to get in touch with these people. Unless, you've been trying to slurp email addresses from HN profiles... I could see it being bothersome in that case.
If you forward it it's not another account to check though. Sure you have to set it up.
Also, obscuring it doesn't prevent someone who has written to you having a situation where your email ends up in the wrong hands (for sure you've received, if you don't have spam protection, those emails where someone who has emailed you has had some virus which gets all their email contacts, right?)
If you setup a dedicated gmail you can periodically change that as well "refresh" using your own email you can't do that.
To be sure though the pet peeve is really more just thinking that people are being overly hygienic about protecting their email address I guess. You are right that it's not a huge burden on someone who is sending you an email.
When I used to post my gmail account to my HN profile gmail caught all the spam it wasn't a problem (maybe this was for a year or year and a half that it was in the profile..)
Does it mean you don't want us to contact you?
Still, this ought be more a pet-peeve for myself. I can't see how obscuring my email would bother you, except perhaps in the line of thought that you think it does NOTHING to avoid spam, and I am just wasting a tiny amount of everyone's time by having them parse it while not benefiting personally. I figured if there was ever a profile a geek would write a scraper for, HN would probably be it. It was a single line of defense I saw others use, and adopted.
Appreciate the conversation. The mostly undiscussed behavior of email format preference in HN profiles is something that has always strangely held my attention; I consider myself a geek for micro-behaviors in this and most any community though.
https://www.sublimetext.com/forum
Incredibly frustrating. A CAPTCHA that requires you to email for the code
It sucks, and will shortly go away for most users. When previously our code would refuse or tell you to try again in a few hours, the captcha will be required instead.
CAPTCHA does not stop bots. Captcha solving can, at the very least, be automated away. CAPTCHA's do not work.
http://googleonlinesecurity.blogspot.com/2013/10/recaptcha-j...
Taking an image and turning into a jigsaw puzzle.
Using a proof of work scheme similar to bitcoin.
Do a google image search for say fish . Take 5 of those images and put them on one side put two on the other alongside images of 10 other random objects. Ask the user to pick the two on the right similar to the ones on the left.
Also it seems like HN is using the older recaptcha (without numeric signs), I didn't know you could choose your recaptcha "version" though.
The captcha is actually pretty ridiculous.