Research Findings:

  • reCAPTCHA v2 is not effective in preventing bots and fraud, despite its intended purpose
  • reCAPTCHA v2 can be defeated by bots 70-100% of the time
  • reCAPTCHA v3, the latest version, is also vulnerable to attacks and has been beaten 97% of the time
  • reCAPTCHA interactions impose a significant cost on users, with an estimated 819 million hours of human time spent on reCAPTCHA over 13 years, which corresponds to at least $6.1 billion USD in wages
  • Google has potentially profited $888 billion from cookies [created by reCAPTCHA sessions] and $8.75–32.3 billion per each sale of their total labeled data set
  • Google should bear the cost of detecting bots, rather than shifting it to users

“The conclusion can be extended that the true purpose of reCAPTCHA v2 is a free image-labeling labor and tracking cookie farm for advertising and data profit masquerading as a security service,” the paper declares.

In a statement provided to The Register after this story was filed, a Google spokesperson said: “reCAPTCHA user data is not used for any other purpose than to improve the reCAPTCHA service, which the terms of service make clear. Further, a majority of our user base have moved to reCAPTCHA v3, which improves fraud detection with invisible scoring. Even if a site were still on the previous generation of the product, reCAPTCHA v2 visual challenge images are all pre-labeled and user input plays no role in image labeling.”

  • someguy3@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    4 months ago

    I kinda figured. It was annoying to do one, but then they wanted you to do two or three and that’s absurd. Whenever it comes up now, I usually just close out.

    • Bezier@suppo.fi
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 months ago

      they wanted you to do two or three and that’s absurd

      Yea how about 20

      • LucidNightmare@lemm.ee
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        VPN? Google will just go in a loop with these things, so I just stopped using Google completely.

      • Dudewitbow@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        4 months ago

        if you have to do that many, you either have some privacy setting on or on a flagged ip given from a VPN

          • Dudewitbow@lemmy.zip
            link
            fedilink
            English
            arrow-up
            0
            ·
            4 months ago

            its abnormal to them because vpns are often also used by bad actors. your use is not abnormal but its a there are other people misusing it making it worse for everyone else.

            • Landsharkgun@midwest.social
              link
              fedilink
              English
              arrow-up
              0
              arrow-down
              1
              ·
              4 months ago

              Wow, way to blame individuals who take basic precautions instead of the corporations who are blantly invading your privacy. Good job making the world a better place, bud.

  • Churbleyimyam@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 months ago

    Getting served a captcha often results in me closing the tab. I’m not doing stupid puzzles for you.

  • Mubelotix@jlai.lu
    link
    fedilink
    English
    arrow-up
    0
    ·
    4 months ago

    I bypassed 35000 google recaptcha v2 using bots. Don’t ever rely on this for security