Google's reCAPTCHA Turns 'Invisible,' Will Separate Bots From People Without Challenges (arstechnica.com)
Google is making CAPTCHAs invisible using "a combination of machine learning and advanced risk analysis that adapts to new and emerging threats." Ars Technica reports: The old reCAPTCHA system was pretty easy -- just a simple "I'm not a robot" checkbox would get people through your sign-up page. The new version is even simpler, and it doesn't use a challenge or checkbox. It works invisibly in the background, somehow, to identify bots from humans. Google doesn't go into much detail on how it works, only saying that the system uses "a combination of machine learning and advanced risk analysis that adapts to new and emerging threats." More detailed information on how the system works would probably also help bot-makers crack it, so don't expect details to pop up any time soon. When sites switch over to the invisible CAPTCHA system, most users won't see CAPTCHAs at all, not even the "I'm not a robot" checkbox. If you are flagged as "suspicious" by the system, then it will display the usual challenges.
the ceiling is the roof
I believe there are accessibility laws most parts of the world ....
"You're either a bot or you're running NoScript!"
For one thing, I never get the checkbox from my residential IP connection. But once I switch to my vpn on my own assigned /24 I get recaptcha's all day. This isn't new, I've been browsing from the same /24 for the last 5 years. Yet for some reason, Google things when I'm coming from there I'm a threat. I know I'm a minority that's going to be drowned out because who cares about the few users caught in the net. It's just an annoying feature that kills any competition for my business. Any remote sites using a squid cache connection get the reCaptcha flag. They switch to a different provider or move the cache server to GCE then everything magically works.
What's a BOFH to do.
Coo coo cha coo
For some reason, I get flagged for captchas all the time, but no matter how vigilant I am at choosing storefronts, mountains, street signs and house numbers, I have to go through at least a dozen pages of them before it believes me.
I wonder whether being behind load balanced proxy servers might have anything to do with it.
Anyone else having similar problems?
Translation: Google have collected enough data of most people's browsing habit from google.com + googleanalytics.com + googleadsense, no need to show you a captcha when they know who you are already.
Given that Google not infrequently flags my web searches as being "suspicious", you'll forgive me if I expect this to work rather poorly in practice. I won't be holding my breath for the pipe dream of seeing captcha images less frequently...
Like most Google products, it works so-so at best.
If they were really smart, they'd just give up so they don't have to dump effort into the arms race anymore and reCAPTCHA would just secretly be a cryptocurrency mining operation.
reCAPTCHA is triggered if you take basic precaution when browsing the web, e.g. blocking unnecessary scripts, cookies, trackers, beacons, and of course ads
If you do, reCAPTCHA will force you to complete a broken AI-training job, collect your behavioral data, and monetize your labor.
It's purpose: to force you to become a PRODUCT of Google, the all-grabbing data company.
And now it's even worse.
Do not endorse reCAPTCHA. Don't put it on your website.
This has been a war over user rights to "camouflage". Google and other ads-funded corporations have feared the "false positive", the background-running random search engine. The recent "are you human" captchas come when I'm not even running an anti-phorm, so I guess I have to prove I'm human because my searches appear to be non-sequetors to Google (though they are not, to me). x2010 http://retroworks.blogspot.com...
Gently reply
The current "identify some bullshit" captchas can be done without javascript. This seems unlikely to have that failsafe. It will be a wad of purposefully hard to reverse engineer javascript, probably with some timing crap to make it hard to do anything with, and that will be that. It will of course ultimately end up generating telemetry.
I sound pessimistic, but this has been the direction we've been heading for some time.
"Yes, I am a robot, but I'm not going to take your job."
Sheesh, evil *and* a jerk. -- Jade
They digitally fingerprint and bubble everyone's searches so honestly, they don't need reCAPTCHA. They can just tell you're human because you act like one.
reCAPTCHA is useless.
There are other very reliable ways of catching automated bots. They are stupid, and make many mistakes that are easy enough to catch even without Javascript.
The real issue is firms hiring people for less than a buck an hour to spam crap. It's impossible to stop without impeding real users... so where do you draw the line?
As it is reCAPTCHA gets in the way more than it should. You're probably better off without it.
Oh dear. Are you trolling yourself by your first link (to Google search)?
> The old reCAPTCHA system was pretty easy -- just a simple "I'm not a robot" checkbox would get people through your sign-up page.
Bullshit. It often made people answer stupid fucking quizzes and once Cloudflare started using it against people on VPNs you had to do it on every fucking website you visited even during the same session. It got to the point where when I saw reCAPTCHA I said "Ha ha fuck you I'm not going to your shitty web site."
A lot of technology has made life easier. Steve Jobs once urged Andy Herzog speed up the Mac startup by a few seconds saying "Imagine that multiplied by the number of people who will do this. Imagine how many human lifetimes you will save."
CAPTCHA has wasted many human lifetimes. CAPTCHA was invented by Mark D. Lillibridge, Martin Abadi, Krishna Bharat, Andrei Z. Broder; Eran Reshef, Gil Raanan and Eilon Solan. Fuck them for the many lost lifetimes and anguish and frustration they caused to so many people.
See my subject: Trolling me by unidentifiable JOOGLE anonymous posts as usual, unable to prove me wrong, lol!
Don't worry - I KNOW how "your kind" is easily controlled: Remove what "your kind" craves, GOLD (ads, lol)! Yes, it's THAT easy to get you to react in such a CRAVEN manner showing your TRUE colors (shit brown/piss yellow).
* Joogle I easily best your NOT so "best & brightest" so bring on your phony PhD's or Rabbi Brin/Eric SHIT so I can dust them publicly & further HUMILIATE your sorry sad "not men" asses, ok?
As to my link? Heh - using their own engine against them is the "coup de gras" of it all, lol!
APK
P.S.=> Pitiful whimps w/ NO balls - no small wonder "your kind" has to HIDE behind anonymous posts - it's all you & yours EVER do vs. me weasels... apk
i AM THE spy
GO GO GOOGLEACHOO
APK Hosts File Engine 9.0++ SR-7 32/64-bit
Hey, Alexander: Can your host list block your incessantly spammed ads here on slashdot?
If not, you've just proven how useless it is with your own spamming. Just sayin'...
Pardon the pun but you should be pissed at these Google scalpers for knocking your cock's block off then https://hardware.slashdot.org/comments.pl?sid=10345479&cid=54011037/
"don't expect details to pop up any time soon", LOL anyone else smell the bullshit here. basically with a few days of this being available you will see published tear downs of it and proposals to work around it.
Jew cock scalper ac hiding harassing apk? Skinning hide off US men's socks for you to hide is twisted https://hardware.slashdot.org/comments.pl?sid=10345479&cid=54011037/ Native americans are pissed at whitemen for scalping! US men should be at you too. You did them much worse!
So now we have an AI trying to decide who is the human, the inverse of the turing test. What it comes down to then is it easier to create an AI that can pass the Turing test or the inverse turing test. If it's easier for a bot to fool a bot then this AI strategy will meet it's match in another AI. On the other hand if it's easier to do the inverse turing test then this new strategy will work. I'm not really sure if it's obvious which test is harder.
Some drink at the fountain of knowledge. Others just gargle.
New captcha uses you computer, phone, tablet, or TV's microphone to listen for your breathing to see if you are human :-).
Fuck you and your ads.
CLI paste? paste.pr0.tips!
How am I supposed to post on /r9k/?
More detailed information on how the system works would probably also help bot-makers crack it...
Flagging you as a robot incorrectly would be less of an issue if it was just Google doing it.
Unfortunately, lots of other websites use the API. There are plenty of Wordpress plugins that add Google's recaptcha to comment forms and I've seen it elsewhere.
It could become a de-facto standard and at that point the issues - in particular for accessibility - become critical. If it's more likely to pop up if you're disabled and using things like screen readers then it's discriminatory.
If nothing else, it'll be something new to keep the EU busy with Google...
Sigs are so 1990s. No way would I be seen dead with one.
Why won't all the bad guys like GNAA and russian hackers just ddos recaptcha into hell where it belongs?
Google is tracking you and logging everything you do.
> I wonder whether being behind load balanced proxy servers might have anything to do with it.
Anyone else having similar problems?
Yes, proxies correlate well to bots. Not all attempts from proxies are bots, but most attempts from bots come through proxies. Open proxies especially. Open proxies are bad anyway, so make sure your proxies aren't open. If possible, use a firewall to limit access to your proxies by IP address.
Windows is also a POS.
At least 1 wordpress plugin weeds out spam without ever presenting captchas. Works pretty well too.
Whatever happened to you happened because the owner of the site chose to use ReCaptcha as a tool to prevent bots. You have no right to insist that a particular website cater a particular user experience to you -- if you don't like it, you can go elsewhere.
What you said applies when a private sector business in a competitive market requires solving a reCAPTCHA challenge or running other proprietary scripts as a condition of accessing a luxury. I don't find it so defensible when a private sector monopolist or even a government requires doing so as a condition of accessing a necessity, as the United States Copyright Office required last year.
Prevention = best medicine (& what u can't touch can't hurt u) via NEW APK Hosts File Engine 9.0++ SR-7 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/
Ads & malware rob speed/security/privacy
Hosts add speed (via hardcodes/adblocks), security (vs. bad sites/malware/poisoned dns), reliability (vs. dns down), & anonymity (vs. dns requestlogs/trackers).
Less power/cpu/ram + IO use vs. DNS/routers/addons/antivirus + less security bugs/complexity & faster vs. addons/routers/remote dns!
Avoids DNSChangers in routers/IP settings & dns redirects (99.999% of ISP DNS != patched vs. it) + lightens DNS load & resolves faster from local system RAM!
* Via what u NATIVELY have built into the IP stack in FASTER kernelmode!
APK
P.S. - Safe https://www.virustotal.com/en/file/e01211ca36aa02e923f20adee0a3c4f5d5187dc65bdf1c997b3da3c2b0745425/analysis/1433430542/
We can just boycott pages that require connections to Google in order to work properly.
Until your national government requires connection to Google in order to exercise the rights of a citizen, such as submitting comments on proposed regulations. It has happened recently; see the Free Software Foundation's 2016 letter to U.S. Copyright Office.
Prevention = best medicine (& what u can't touch can't hurt u) via NEW APK Hosts File Engine 9.0++ SR-7 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/
Ads/Script & malware rob speed/security/privacy
Hosts add speed (via hardcodes/adblocks), security (vs. bad sites/malware/poisoned dns), reliability (vs. dns down), & anonymity (vs. dns requestlogs/trackers).
Less power/cpu/ram + IO use vs. DNS/routers/addons/antivirus + less security bugs/complexity & faster vs. addons/routers/remote dns!
Avoids DNSChangers in routers/IP settings & dns redirects (99.999% of ISP DNS != patched vs. it) + lightens DNS load & resolves faster from local system RAM!
* Via what u NATIVELY have built into the IP stack in FASTER kernelmode!
APK
P.S. - Safe https://www.virustotal.com/en/file/e01211ca36aa02e923f20adee0a3c4f5d5187dc65bdf1c997b3da3c2b0745425/analysis/1433430542/
I'm going to continue using the Host File Engine. Your software is well written, functional. The Host File Engine performs exactly as promised by mmell
his hosts program is actually pretty good by xenotransplant
I've never tried to belittle (APK's) work, I've flat out said it's good by BronsCon
take a look at the APK hosts file engine by SuperKendall
APK is kinda right. I've tried his hosts file generating software. It works by bmo
I like your host file system by Karmashock
I find your hosts file admirable by vel-ex-tech
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg
APK is totally right on this count. Adblock Plus on Firefox mobile is a dog on older, or lower end, phones. A hostfile based adblocker makes for a much better experience by chihowa
* Recommended & hosted by Malwarebytes' hpHosts!
APK
P.S.=> You're outnumbered Fisted (you fake name using punk)... apk
If you can't explain what it does, I won't use it in my projects.
See my subject "Fisted" you punk bitch: You're ALL talk nothing to show for yourself. I can, easily https://hardware.slashdot.org/comments.pl?sid=10345479&cid=54012361/
* Who supports ANYTHING you've EVER done (nothing) motherfucker?
The PRICE of your fuckery (trolling by unidentifiable anonymous posts OR delusional FAKE NAMES for FAKE LIVES like yours) is YOU WILL NEVER, ever, ACCOMPLISH A DAMN THING OF WORTH (& you know it - not thru lack of effort but being "damaged INFERIOR goods" losers).
Motherfucker - "your kind"? You're BORN losers... which is why most of you are HEROIN JUNKIES or on the WELFARE tit. You are, clearly, INFERIOR wastes.
Too much Bisphenol A from plastic milk cartons has turned you into BITCHES, disgusting bitches.
APK
P.S.=> Answer that question bitch - you piece of FUCKING shit bitch do-nothing WASTE of life (makes me sick to see what's coming up behind my generation, it truly does - you're FUCKING wastes on the WELFARE or HEROIN tit fuckers)... apk
"If you are flagged as "suspicious" by the system, then it will display the usual challenges."
Thus giving the bot developers a clue whether they are doing it right.
I know a dude who spams things he doesn't like by writing a front end that displays the recaptcha challenge to a pool of people he pays via amazon mechanical turk to solve them. $10 to spam a site for a day.
This shit has always simply been about tracking users and harvesting as much data as they can.
I'm no advertiser: Google is (you're probably one of their shills OR getting money from them somehow) & you DO care or you wouldn't reply.
* Funny you don't answer the question I asked you (NOT & why's that? You're a "ne'er-do-well" - period).
APK
P.S.=> Dry up & blow away - you're a "ne'er-do-well" do nothing waste of life... apk
I'm going to continue using the Host File Engine. Your software is well written, functional. The Host File Engine performs exactly as promised by mmell
his hosts program is actually pretty good by xenotransplant
I've never tried to belittle (APK's) work, I've flat out said it's good by BronsCon
APK is kinda right. I've tried his hosts file generating software. It works by bmo
I like your host file system by Karmashock
I find your hosts file admirable by vel-ex-tech
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg
APK is totally right on this count. Adblock Plus on Firefox mobile is a dog on older, or lower end, phones. A hostfile based adblocker makes for a much better experience by chihowa
* Recommended & hosted by Malwarebytes' hpHosts!
APK
P.S.=> See subject: YOU troll & do zero vs. threats "ne'er-do-well" - you did better than I? No... apk