top | item 19659471

Hacking Google ReCAPTCHA v3 Using Reinforcement Learning

55 points| ArtWomb | 7 years ago |arxiv.org | reply

43 comments

order
[+] mosselman|7 years ago|reply
"Our proposed method achieves a success rate of 97.4% on a 100x100"

I think that is higher than what I get when I do it myself.

[+] westondeboer|7 years ago|reply
I can never get the street lights one, and then it gives me the bus one, which i can never get right either and then finally it gives me the bus one. Which I am 100% at, maybe.
[+] ve55|7 years ago|reply
ReCAPTCHA is one of the worst things that has happened to the Internet. Please consider an alternative if you are a webmaster that has a choice. It's overkill for most purposes.
[+] jasonhansel|7 years ago|reply
Also: by using ReCaptcha, you're essentially giving Google free money, in the form of training samples for self-driving cars. Surely there are CAPTCHAs for things that benefit the public at large?
[+] cadence-|7 years ago|reply
What’s the alternative?
[+] TrinaryWorksToo|7 years ago|reply
Recaptcha gives Google exclusive automated access to your website. Do you want Google to grow as company because of this?
[+] gingerlime|7 years ago|reply
Any recommendations?
[+] gurpreetsatwal|7 years ago|reply
I don't have much data to back this up, but I but I've noticed that I get the recaptcha challenge and almost every single time when I use Firefox. Whereas if I use Chrome I only get it once after not using Chrome in a while.

Also on Firefox mobile, not only do i get the challenge, but I get multiple challenges.

[+] jgowdy|7 years ago|reply
I'm somewhat glad to hear I'm not the only one who has been subjected to extremely excessive recaptcha tests according to these comments. Especially when I'm filling these out just to login to websites of which I'm a customer. I get it for ordering, but if you put this on your customers logging in, it's like you're begging for cancelations. Google is the one determining your paying customer's user experience.

And if I pass your captcha, can you not cookie me with a signed token indicating that I already proved I was human for 30 days? It's like these lazy people can't handle bot login spam, so they just throw recaptcha on their login form and call it a day.

If your login form requires paying customers to fill in recaptcha each time, you're doing it wrong. Please stop. Or go out of business faster.

[+] Sylamore|7 years ago|reply
The fastest way for me to get flagged is to request the audio test instead of the visual test, More than 7 out of 10 times it will halt and say my computer is sending automated queries and that I should try again later.

I've even gotten caught in a reCAPTCHA loop where I successfully complete the capctha only to have to redo it again as soon as the page reloads.

[+] ezoe|7 years ago|reply
It's probably related to credit card fraud.

There are large sets of stolen credit card numbers. Most of them are disabled. Crime group automated purchase process to determine if the number is live.

So online stores really want to eliminate the automation.

[+] xdrxd|7 years ago|reply
I wonder how to setup browser history, cookies and Ip address in chrome. You some got idea please share.