TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

198 pointsby ghuroo13 months ago

15 comments

jp1919193 months ago
I'm at the point now that if I get a CAPTCHA, I'm just going to leave the site. I'll spend my money elsewhere or find an alternative
评论 #43005123 未加载
评论 #43005351 未加载
Dotnaught3 months ago
Google addressed the claims in this paper last year, and one of the authors challenged the company&#x27;s responses. See: <a href="https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;07&#x2F;24&#x2F;googles_recaptchav2_labor&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;07&#x2F;24&#x2F;googles_recaptchav2_l...</a>
评论 #43008717 未加载
eykanal3 months ago
The problem with this paper is that, while technically true, there are many website owners who have found that CAPTCHAs have effectively reduced the spam on their site to zero. The fact that a CAPTCHA _can_ be bypassed doesn&#x27;t mean that it _will_, and most spam bots are not using cutting-edge tech because that&#x27;s expensive.<p>To say &quot;it&#x27;s worthless from a security perspective&quot; is a pretty harsh and largely inaccurate representation. It&#x27;s been tremendously useful to those who have used it. If it wasn&#x27;t valuable, it wouldn&#x27;t be so widely used.<p>Definitely agree with the whole &quot;tons of free $$$ for Google&quot;, but that&#x27;s kind of their business model, so yeah, Google is being Google. In other breaking news, water is still wet.
评论 #43005941 未加载
评论 #43006569 未加载
评论 #43005295 未加载
评论 #43014195 未加载
btown3 months ago
The &quot;cookie farm for profit&quot; point is worth elaborating on. From the original paper <a href="https:&#x2F;&#x2F;arxiv.org&#x2F;pdf&#x2F;2311.10911" rel="nofollow">https:&#x2F;&#x2F;arxiv.org&#x2F;pdf&#x2F;2311.10911</a> :<p>&gt; More concretely, the current average value life-time of a cookie is €2.52 or $2.7 [58]. Given that there have been at least 329 billion reCAPTCHAv2 sessions, which created tracking cookies, that would put the estimated value of those cookies at $888 billion dollars.<p>The cited paper is <a href="https:&#x2F;&#x2F;www.sciencedirect.com&#x2F;science&#x2F;article&#x2F;pii&#x2F;S0167811623000708" rel="nofollow">https:&#x2F;&#x2F;www.sciencedirect.com&#x2F;science&#x2F;article&#x2F;pii&#x2F;S016781162...</a> - but it doesn&#x27;t deal with CAPTCHAs, just with the general economics of third-party cookies.<p>In practice, many of these cookies will have already been placed by other Google services on the site in question, with how ubiquitous Google&#x27;s ad and analytics products are. And it&#x27;s unclear whether Google uses the _GRECAPTCHA cookies for purposes other than the CAPTCHA itself (in the places where this isn&#x27;t regulated).<p>But reCAPTCHA does gives Google an ability to have scripts running that fundamentally can&#x27;t be ad-blocked without breaking site functionality, and it&#x27;s an effective foot in the door if Google ever wanted to use it more broadly. It&#x27;s absolutely something to be aware of.
ghuroo13 months ago
That made us spend 819 million hours clicking on traffic lights to generate nearly $1 trillion for Google.
评论 #43004777 未加载
评论 #43008091 未加载
评论 #43021424 未加载
ChrisArchitect3 months ago
[dupe] Earlier: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=42997755">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=42997755</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=42970780">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=42970780</a>
breppp3 months ago
I get that people are here to hate on Google, but I am just here to say that reCAPTCHA albeit acquired, is an absolutely brilliant idea. The kind that solves two (three? if you count tracking) problems so elegantly
评论 #43006066 未加载
评论 #43008122 未加载
评论 #43006123 未加载
darkwater3 months ago
Naive question: how can clicking on the motorbike or traffic light image help to train an ML algorithm if they already know what image has a motorbike in it, or otherwise the captcha would not make sense. Maybe they put 3 image which are already with a score of &gt;0.90 and one which is just 0.40?
评论 #43005712 未加载
评论 #43016038 未加载
评论 #43005759 未加载
评论 #43018347 未加载
评论 #43005717 未加载
评论 #43005658 未加载
pupppet3 months ago
What&#x27;s the alternative?
评论 #43004911 未加载
评论 #43004824 未加载
评论 #43004723 未加载
评论 #43013251 未加载
评论 #43004854 未加载
评论 #43004493 未加载
评论 #43005092 未加载
评论 #43006270 未加载
评论 #43004879 未加载
unethical_ban3 months ago
What proof of humanity is sufficient? Today it is a phone call, or a verification sent to a real address (limit one registration per household), or a video call. How will we verify humanity in 20 years when audio and video emulation is foolproof?<p>We&#x27;ll have to have in-person attestation or make all services paid, perhaps.
评论 #43004895 未加载
评论 #43004850 未加载
评论 #43023102 未加载
kykeonaut3 months ago
Wouldn&#x27;t some sort of proof of work be a good solution to the captcha problem?<p>Specially since all of the sudden, a bot service running hundreds of thousands of requests will suddenly and inadvertedly have to compute cryptographic hashes at the cost of the user running the bots?
评论 #43014376 未加载
jvdvegt3 months ago
To prevent the cookie wall with no &#x27;reject all&#x27;: <a href="https:&#x2F;&#x2F;archive.is&#x2F;oHc1e" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;oHc1e</a>
nonrandomstring3 months ago
You can get people to do almost anything if you lie to them that it&#x27;s for &quot;security&quot;.
评论 #43020099 未加载
评论 #43003748 未加载
jdietrich3 months ago
-
评论 #43004632 未加载
bigbuppo3 months ago
819 million hours of unpaid labor. And just think, a large chunk of that was performed by children. CAPTCHAs are slave labor in small doses. It&#x27;s also a way of avoiding paying taxes on that labor. But hey, what&#x27;s a few billion dollars in unpaid taxes and unpaid wages and child labor violations between friends?