Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You hit a nerve. I have to go through two reCaptchas to prove that I am not a robot so that I can pay my children’s school activities. Why would they care if I am a robot that wants to pay them? For some time checking in for COVID in NSW Aus took 3 reCaptchas if you were in private mode on your browser. Similar in many government services where they are pervasive and injected right in the middle of potentially very private workflows.


> Why would they care if I am a robot that wants to pay them?

I’ve seen scammers find obscure payment portals and run through a bunch of card numbers to see if they approve/deny. Recaptcha prevents that. It’s obviously not the only way, but it’s low dev effort and it works.


This is an easy fix. Just require being signed in and only allow payment with a valid child attached to the account. You can allow anonymous payments only if you have a valid child account code.


>Why would they care if I am a robot that wants to pay them?

Because payment systems that allow for cheap transactions are often leveraged to test stolen credit card data before making a transaction in person.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: