Hacker News new | past | comments | ask | show | jobs | submit login

I would like this NOT to be broken. reCAPTCHA is currently one of the few captcha systems the still work to some extend. It locks out most spam bots and keeps my sites clean. Of course it's a good idea to try and break it, to see how "secure" it is.



Unfortunately the latest revision of reCAPTCHA has become such a pain that I've come very close to just giving up on signing up for whatever service it is I'm trying to use that has it implemented.

I have to go through several attempts to verify myself because Google didn't like that I missed one box with a car in it and have to start all over looking for street signs.


I often use a VPN and browser extensions that make the new one always asks me to verify. The new tests are just terrible (choose all photos with an apartment building??). It will sometimes take me a few minutes to complete the test when it asks me to check all boxes with a car and the slow fade animation that takes 5 seconds starts. Then it decides that I didn't choose them well enough and starts over again. The old CAPTCHA was much better and I didn't feel like I was just feeding Google's street view.


I've found that disabling JavaScript actually makes the test easier. I often fail the js version but I rarely fail the no-js one.


Next version will ask you to come wash some cars at the Googleplex...


Yeah, it frustrates me a lot too. If I need to pick the squares with street signs about half the time they want me to choose the squares that have the pole and half not! Ditto with the square with the tiny corner of the sign.


I became really good (or really bad) at them, that once I had to go through >8< rounds of reCAPTCHA to get through....I seriously was thinking it was never going to end!


One thing I find works really well is context-based question captchas. You ask human visitors some very simple question about your site, and unless the robot brute-force, it's very hard for robot spammers to get it right.


Yep, I saw this in rtl-sdr.com! They ask, for instance what does the S in SDR stands for, which obviously any legitimate commenter in such a niche site knows.


I think it mostly works by inspecting your browser environment to see if it looks like a bot. I'm not really convinced that the pictures do much.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: