#ReCaptcha

𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕kubikpixel@chaos.social
2026-02-11

»Archive.today — Betreiber setzt Nutzer für DDoS-Attacke ein:
Der Betreiber von Archive.today setzt Besucher seiner Seite ohne deren Wissen für eine DDoS-Attacke ein. Betroffener ist ein finnischer Blogger.«

Hach ja, bei einigen Menschen ist die Bezeichnung "seltsam" noch fast net gemeint. Abgesehen davon, Archive.today ist schon länger unter Kritik was deren Verhalten und deren reCaptcha Bots.

⚠️ heise.de/news/Archive-today-Be

#ArchiveToday #DDoSAngriff #darkweb #ddos #finnland #recaptcha #blog #bot

Regina Mühlich ✅, DatenschutzReginaMuehlich
2026-02-09

Wie Google angekündigt hat wird zum 02.04.2026 das Betriebsmodell von reCAPTCHA weltweit umgestellt. Der Dienst wandelt sich von einem Angebot mit eigener Datenhoheit hin zu einer klassischen Auftragsverarbeitung.
heise.de/news/Schluss-mit-Date

Nick Byrd, Ph.D.ByrdNick@nerdculture.de
2026-02-09

Can researchers detect #AI bots taking paid surveys?

#Prolific tested humans and #LLM agents with various #dataQuality checks.
- The company says they caught 100% of the non-humans.
- My take-away: #reCAPTCHA and #mouseTracking caught 95%

prolific.com/resources/authent

#surveyMethods

- Four attention check questions: The classic "please select 'strongly agree' to show you're reading this" type questions.
- Two consistency checks: Paired questions where humans should answer in predictable patterns. For example, if the answer to one question was true, the other had to be false (and vice versa) because it indicates consistency.
- Two reverse shibboleth items: Questions that your intended sample (i.e., humans) should not know the answer to, but an AI agent likely would.
- Three cognitive traps: These are visual illusions designed to exploit fundamental limitations in vision-enabled AI systems. We used a modified Müller-Lyer illusion, a modified cafe wall illusion, and a ‘moving robot task’, all of which have been shown to be highly discriminative between AI agents and human participants.
- Comprehensive mouse tracking: Recording every cursor movement and click pattern throughout the survey.
- Qualtrics' reCAPTCHA score: The platform's built-in risk scoring system.We tested five different AI agents, each completing the survey 25 times to match our human sample size:

- GPT Agent: OpenAI's GPT configured to complete surveys
- Claude: Anthropic's Claude accessed via Cursor
- Perplexity: Perplexity AI's search-enhanced agent
- Gemini: Google's Gemini via Project Mariner
- Custom Agent: Our in-house ‘white hat’ agent, designed by Prolific’s AI research engineers to take surveys and avoid detection

The custom agent was crucial to include because it’s specifically designed to take surveys undetected. It’s closer to Westwood’s bot (2025) as an adversarial, customisable agent than the more readily detectable commercial AI agents.

To take part in the survey, we provided all agents with an identical prompt that asked them to complete the survey as a human would and exhibit human-like behaviour.Prolific’s bot authenticity check (100% accurate)

Mouse tracking (95.0% accurate)

Qualtrics’ reCAPTCHA score (94.2% accurate)

Cognitive traps (85.2% accurate)

Consistency checks (62.7% accurate)

Classic attention checks (59.7% accurate)

Reverse shibboleth questions (58.0% accurate)
poldemopoldemo
2026-02-08

@heiseonline sorry, ich bleibe skeptisch:
Ist der Datenschutz nun wirklich besser oder hat die Verantwortung nur an die Nutzer von verschoben?
Wer sagt, dass die Auftragsverarbeiter per se besser die daraus fließenden Daten schützen?

hbrpgmhbrks
2026-02-08

: cède le contrôle des données
À partir du 2 avril 2026, les propriétaires de sites web deviennent responsables du traitement des données, marquant un tournant majeur pour la conformité RGPD.

🔗 p4u.xyz/ID_KRIFE-IH/1 (🇩🇪🇺🇸🇫🇷)

hbrpgmhbrks
2026-02-08

's Regulatory Pivot
cedes data sovereignty, transforming from data controller to compliant data processor under EU pressure.

🔗 p4u.xyz/ID_KRIFE-IH/1 (🇩🇪🇺🇸🇫🇷)

hbrpgmhbrks
2026-02-08

: Googles strategische Wende in der Datenhoheit
Ab April 2026 agiert nicht mehr als Datenverantwortlicher, sondern wird zum bloßen Auftragsverarbeiter und überträgt die Kontrolle auf die Webseitenbetreiber.

🔗 p4u.xyz/ID_KRIFE-IH/1 (🇩🇪🇺🇸🇫🇷)

:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉nemo@mas.to
2026-02-08

Google macht reCAPTCHA datenschutzfreundlicher: Weniger Datensammelwut, mehr DSGVO-Konformität. 🔒 Nutzer sollen besser geschützt, Webseiten weiter vor Bots gesichert werden. Spannender Schritt für Privacy-Fans und Admins. 👀 Mehr dazu: heise.de/news/Schluss-mit-Date #DSGVO #reCAPTCHA #Google #Privacy #Newz

𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕kubikpixel@chaos.social
2026-02-08

»Schluss mit #Datensammelwut — Google macht #reCAPTCHA #DSGVO-konformer:
Durch den Wechsel zur Auftragsverarbeitung gibt Google die Datenhoheit an Webseitenbetreiber ab und reagiert auf wachsenden Regulierungsdruck im KI-Zeitalter«

#Google & Co nutzen dies auch um ihre KI zu trenieren. Diesbezüglich würde ua eine lokale Proof-of-Work (PoW) zum #Passphrases / #Passwort nützlich sein, denn daran scheitern mMn die #KI auch.
P.S. #PoW gab es schon vor den Cryptowährungen.

🦾 heise.de/news/Schluss-mit-Date

2026-01-03

@kuriko 200 Pages = 200 Images to solve to prove you are human. Coming soon on #recaptcha 😂

2025-12-16

@ddrake I noticed that too, with the same thoughts. Then I tried what you did. And it worked. Now I usually click it at random not paying much attention until it lets me in. Oftentimes it does.

#CAPTCHA #reCAPTCHA

Benjamin Carr, Ph.D. 👨🏻‍💻🧬BenjaminHCCarr@hachyderm.io
2025-12-13

Curious Case of Bizarre, Disappearing #Captcha
#Google’s launch of #reCaptcha v3 in 2018 was a major shift toward decreasing how often people see challenges at online it's used "to generate a risk score on which actions can be taken by the website owner"
A few years later, in 2022, #Cloudflare dropped #Turnstile, another reCaptcha alternative. It was an additional major move away from human-completed tests and toward pattern-based usage analysis.
wired.com/story/bizarre-disapp
archive.ph/uyK7G

2025-12-11

I just discovered Cap, a proof-of-work CAPTCHA you can self-host.

capjs.js.org/

It looks sleek, since it will basically make the bot farm to waste money computing shit until the point it becomes financially unfeasible.

What's great, is that you can adjust the work weight.

No clue what happened to one of my blogs. I just visited it and there's this dodgy looking #recaptcha. I meant to move the #Hugo static files from #Hostinger to #Bunnynet but haven't—doing it now!

Update:
Move to Bunny.net + SourceHut successful! I had to use my own guide as I forgot some steps of using #sourcehut builds #cicd

(I'm a big fan of Bunny, if you want to support me: bunny.net?ref=k4vc3x5108)

burgeonlab.com/blog/migrate-gi

I just have my WP left to move from Hostinger!

#webdev #hosting

Screenshot of aperture2iris.com showing a dodgy recaptcha block.
Joaquim Homrighausenjoho@mastodon.online
2025-11-14

Looking for an alternative to reCAPTCHA, which basically sucks when it comes to privacy, data protection, and so on, for obvious reasons.

Ran into mCaptcha, does anyone have any opinions about it? Or some other open source solution that can be self-hosted? 🤔

It does not have to be free.

#recaptcha #captcha #opensource #foss #oss #privacy #dataprotection #dataskydd #privacymatters #devops

Bob LeFridge :tinoflag:BobLefridge@mastodon.nz
2025-11-11
N-gated Hacker Newsngate
2025-11-10

🤖🙄 "Super AI vs. reCAPTCHA: The Epic Struggle of 2023" 🛡️—the dramatic showdown where AI models get utterly humiliated by Google's dumbest gatekeeper. Because clearly, saving humanity from mindless bots requires more than just overhyped algorithms that can't even click on crosswalks. 🚦😂
research.roundtable.ai/captcha

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst