Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What do you mean by "break"?


Passing the captcha through an entirely automated procedure.


In bulk? It's not supposed to stop real users from using a bit of scripting.


It kind of is, actually. Cloudflare, for example, uses a single CAPTCHA to prevent ongoing DDoS attacks. If they switched to this new reCAPTCHA and if a DDoSer can use Selenium to get past the challenge, then the CAPTCHA process has failed.

There are always tradeoffs with this. I strongly suspect Google is going to have to restrict it within a year or so, resulting in the number of users who still have to solve CAPTCHAs closer to 10-20%.


'a bit' being key. It's not like a DDoSer can't already solve captchas for three minutes if that's the only protection.


The work still has to be done manually in those cases, though, whether they type it themselves or rent use of a captcha farm.


In most scenarios you only have to solve one captcha. Those are not going to be significantly affected, since the manual work is minimal. It will provide a multiplier on traffic in the case that a captcha is needed for every single action.


Does your automated process still send your real Google cookies though?


Yeah, it uses real user's cookies to accomplish it, but I was also able to break it with traditional captcha-breaking mechanisms after Google presents the fallback. The point I'm making here is that this change doesn't really help much with proving that you are a human.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: