Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ever encountered Google ReCaptcha when you've turned off third party cookies or while in incognito/private mode? It's a nightmare, even if you're logged into a Google account. You can be shown upto 7-8 challenges, painfully slow loading images and Google's insistence that they encountered malicious traffic from your IP when attempting to use the audio version. What's even worse is they track your mouse movements and fast solvers like me are penalized since they think I'm not human anymore.

As much as I hate third party cookies, turning them on drastically simplifies the captcha solving process. So much so, I now use a separate browser profile with third party cookies allowed, just for the sake of captcha heavy sites.

Given that Google benefits by tracking my activities and free labor from my captcha solving, they will always punish privacy conscious users via such dark patterns.



The optimist in me thinks that if browsers started to disallow third party cookies, ReCaptcha might have to adapt to the change and make it easier to solve if third party cookies are blocked. After all, if they didn't, they'd risk website owners moving away from ReCaptcha because visitors could no longer interact with the site.

The pessimist in me thinks that if a browser were to disallow third party cookies, users might simply switch to a different browser that does allow them.


I don't think it has so much to do with reCAPTCHA as much as it has to do with Cloudflare and website owners themselves. Most reCAPTCHA challenges come in the form of Cloudflare challenge passage pages. Website owners have 5 options to choose from regarding challenges:[1]

— Essentially off: Challenges only the most grievous offenders

— Low: Challenges only the most threatening visitors

— Medium: Challenges both moderate threat visitors and the most threatening visitors

— High: Challenges all visitors that have exhibited threatening behavior within the last 14 days

— I’m Under Attack!: Should only be used if your website is under a DDoS attack (Visitors will receive an interstitial page while we analyze their traffic and behavior to make sure they are a legitimate human visitor trying to access your website)

I think a lot of companies set it to "High" and forget about it, not realizing that it's ruining the experience for a lot of users.

[1]: https://www.cloudflare.com/a/firewall/ebelinski.com#security...


It doesn't ruin the experience of anyone except a couple of overly technical users and customers in the wrong locations.

It's very good at blocking malicious traffic though and it's totally worth losing a pair of users for that.


Yes, it's the users that are wrong!


> The optimist in me thinks that if browsers started to disallow third party cookies, ReCaptcha might have to adapt to the change and make it easier to solve if third party cookies are blocked.

That needs to bring everybody to the same table, Firefox will not do that alone and Google Chrome is not there for nothing.

Basically, Google must accept the proposal of disabling third-party cookies by default which will effect their income negatively, so they may just refuse to implement that feature for Chrome and even may prevent that feature from become a standard.

Sad.


Chrome already has a "Block third-party cookies" feature in Privacy and security > Content settings > Cookies.

Kinda hard to find though.


Users tend to blame websites rather than browsers when the websites don't work. So by using bad CAPTCHAs, i'd guess, users would more liekly blame those sites using them.


This is what finally made me switch my default search engine away from Google. I will put up with a lot of crap, but I'm not going to spend 60s to solve a CAPTCHA every time I do a search.


Bear in mind that Google might be correctly identifying your IP address as a botnet source. If you start seeing lots of CAPTCHAs, it's worth it to take a look around your network for open ports or weak ssh passwords etc., or just look at a traffic monitor to see if there's a lot of egress from your net.


Oh, I'm sure there are a million reasons for them to block me. I normally use a VPN, incognito searches, limited script blocking, and cookie blocking. Pretty sure they don't want me as a customer, not that I can completely blame them. Anyway, I've discovered that there are other reasonably effective search engines with a different business model, and I'm fine using those and giving them a modest amount of revenue. (I don't block ads that don't track me.)


I've never seen a CAPTCHA when simply doing a search - is that because I refuse to log in to Google?


Perhaps Firefox could fake thirdparty cookies instead of disallowing them.


Then you'd probably never pass captcha.


firefox is big enough that captcha would be forced to change, so long as firefox stuck to it.

I make no claim that the above is a good idea. It is possible, but it strikes me there are unintended consequences that I won't think of.



This has been a huge problem of mine when using tor, after disabling 3rd party cookies and also using Firefox containers. Took me two days to just love duck duck go and now it's been set on my laptop, phone and all tables, where Firefox with uBlock origin are to browse the web.


ReCaptcha means to me that I need to blacklist your site and never come back. F@ck that noise


I got very sick of this crap from Google, which is why I switched my default search engine to DuckDuckGo.


Yeah we need to have a talk about captchas and privacy. They're pretty plainly used by providers (Google) to force people into being tracked.


I can't even get recaptcha to work when I have the umatrix extension turned on, even when I turn off the functionality of umatrix by whitelisting everything. I need to go into my browser extensions and turn off the whole extension just to get past a recaptcha.


Using the logger is key to solve that sort of issues. As stated in the documentation, the per-scope switches keep having an effect even if you disable matrix filtering. The logger will show you what is still modified by uMatrix if there is anything.


With umatrix, try unchecking the 'Spoof HTTP header' option. I was able to get it working this way. There's no need to disable the extension itself.


I sympathize. It's terrible when a computer thinks you must not be human because you're not slow and don't make enough mistakes.

I've been accused of being a bot before also.


I tried making a throwaway account on Protonmail account while on the Tor network. I swear, I probably had to go through 25 captchas before it worked.


Google’s recaptcha doesn’t work even when you are logged in sometimes.


I've always had to solve 3-4 captchas. They are insufferable and I have simply stopped using most of the sites that use recaptcha unless they are vital to me.

It feels like Google is using me as a mechanical turk to solve their autonomous car rubbish, which will make them millions, and I have no choice but to do it, or I'm barred from the sites I need to access. It's profoundly despicable, as if I didn't hate Google enough already.


>It feels like Google is using me as a mechanical turk to solve their autonomous car rubbish

That explains why the majority of ReCaptchas I get are along the lines of "Click the squares that contain a street sign" or "Click the squares that contain a bicycle."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: