Hacker News new | past | comments | ask | show | jobs | submit login

For Google ReCaptcha, simply install the Buster addon, it solves the captcha for you via speech-to-text.

For captcha's in general, I think we should stop pretending that we can prevent bot traffic from a dedicated attacker without annoying the users.

A simple captcha from the 2000's (the ones with lines over a word or number of letters and numbers), should be good enough to hold off basic script kiddies. Same for a basic TTS audio clip.




Google won't even serve the audio captcha in the first place to many users who use firefox, adblockers, etc.


It always serves an audio captcha for me on Firefox with Adblocking and Script Blocking on Linux.


> A simple captcha from the 2000's (the ones with lines over a word or number of letters and numbers), should be good enough to hold off basic script kiddies

The problem is that while the kiddies may not be sophisticated their scripts can be - the solutions will work its way in the scripts sooner than later.


Fighting against AI cracking is the same battle that AV vendors have fought in the past decades. It ultimately ends by selling snakeoil.

Any dedicated attacker can nowadays circumvent your captcha solution, it's at best now to get the low level background noise to go away, similar to IP blocking SSH when an IP makes too many attempts.

If your site security relies entirely on the captcha not being broken, your site security needs an update.


Unfortunately Buster no longer works. Google detects it now and makes you start over.


The next release will use native messaging to send native user input events to the browser. It's already working well, I just need to finish the app installation bits.


Thanks!


Buster works if you set it to another STT service than the Google API Demo. They seem to have caught onto that one.


Yes, and it is also working with google cloud speech using your own key.


This. Google just disables captcha immediately. Also I tried clicking the audio manually, it immediately disables with a notice that “we are getting .... please try again later”.


Use on of the other STT apis than the Google Speech demo.


Old captchas allowed you to see the content without need to pass it. I'm too tired to see cloudfront pages with recaptcha.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: