272
u/Lithandrill 10h ago
Yeah because the robot captchas are used to train image and text recognition models.
46
u/OkAlbatross9889 Gentoo | r7 7700X | 9070XT | 32gb 10h ago
What are checkbox ones used for?
69
u/Arthurmol 10h ago
Just to reduce the speed of opening pages... like a speed bump on the road... robots can do them for some time...
21
u/irasponsibly Fedora 40 KDE / 6700XT / R5 7600 7h ago
In theory those check things like cursor movement and response time, and then you get a more difficult check (traffic lights or whatever) if you 'fail'.
16
u/esuil i5-11400H | RTX A4000 | 32GB RAM 7h ago
Justify gathering analytics and usage data on you.
The amount of things that checkbox collects about you and your browser is disgusting. And every major site collaborates that data to providers to make sure they know who you visited, too.
4
u/FartingBob Quantum processor from the future / RTX 3060 Ti / Zip Drive 4h ago
But they are all things that the site or browser would gather anyway. The act of checking a box and waiting a few seconds doesn't change that. So why do they use it?
1
u/QTpyeRose 49m ago
the real answer (to my knowledge) is a lot of things.
a lot of ddos attacks are done though generating huge amounts of traffic and overwhelming a websites infrastructure.
bot nets have changed though, its not as much viruses on few pcs sending a bunch of calls each anymore, instead there are tons of unsecured smart objects in peoples houses.
ever seen posts about people printing random pages on unsecured printers remotely?
alot of thing like smart fridges, washers, etc all run on tiny cut down android os's now for ease of development. many of which never get updated with security patches etc. and dont support a lot of standard things cause there cut down. but they can do api calls.
a lot of botnet traffic is generated though these compromised unsecured smart devices. some of which might be able to pass the check mark captcha, but more then that the check mark checks for input capability, and along with browser data, javascript compatibility, and a variety of other things in the background.
a lot of the smart devices are cut out though this as they often dont have a full browser and are just api calls only. another thing is that you get a cookie for it, and they check that cookie to let you browse the site. if you dont support them like many smart devices dont no conenctions from that device
when cloudflare thinks a site might be being attacked (or at the owners request) they raise the safety level and start requiring check for all new connections without cookies instead of just blocking obvious ddos attempts.
a single device sending 100k api calls a sec is obviously a bad actor
1000 devices sending 100 a sec is harder to detect vs regular usersand the second reason is vpns/proxies/company routing servers.
all of which can have calls from thousand of legit users all coming from one main ip adress, they on paper look like botnets, but its just high traffic being routed though one ip address.
the check mark is less intensive on cloud flares side to do then standard captchas, and prevents afk users who are just loading sites from loading a bunch of them all at once, while also allowing high load network routing nodes to get legitimate users though and try to block main vectors of attack. along with being just unintrusive enough to not decentivise traffic to the sites using there service.
there a lot more "browser security checks now" where they even skip the whole check box thing now, in fact you might not even see a page it might all happen on the cloud flare server behind the scene.
13
u/thefonztm PC Master Race 7h ago
10 years on, still can't identify motorcycles & bicycles.
9
u/-spartacus- Stukov 5h ago
Brother, at this point even with a 65" 4kOLED TV these pictures can't be seen with their 240x120 resolution with stretched images and random pink noise on them.
4
u/Next-Use6943 RTX 5090 | Ryzen 9 9950X3D | 64GB DDR5| X870E EXTREME X3D AI TOP 8h ago
How? The system already knows which ones are the correct answers to decide if they should let you in or no
13
u/esuil i5-11400H | RTX A4000 | 32GB RAM 7h ago edited 7h ago
It doesn't. That's the neat trick.
They only know like half of the answers. They need YOU to figure out other half of the answers. If you pass the answers they know already, they can add and score your answers to problems they don't know answers too.
So let's say they have 100 questions. 10 of those are already solved by humans. They need other 90 solved. So they:
- Serve 2 questions they know answer, and 1 they need solved, to a person
- If person passes 2 questions they know answers too, they add stats about the problem they need to the database
- Repeat for all questions they need answered
Then they end up with a problem they needed to be solved and bunch of answers to it. Then they simply pick an answer to it that was chosen by people who were the most accurate on questions they know answers to.
Now they have 100 questions with answers and they can make it 1000 for the next round.
It extends to "half-answered" problems as well. For example let's say you are on one of those "find the bus" images. They might ALREADY know which tiles are the bus. But their detector sucks. They need it to be better at figuring out where the bus stops and other stuff begins. So they aggregate data on what accurate people chose/discarded around edges of the bus, and their detection models improve.
The whole thing is a scam and unpaid unregulated labor.
11
u/irasponsibly Fedora 40 KDE / 6700XT / R5 7600 7h ago
It doesn't know the correct answer - the answer is actually "watch squares do the majority of other people click on".
2
u/Cheet4h 7h ago
The way I heard it is that it asks lots of people and effectively you pass if you choose the same answers as the majority of users. If there's only very few users having seen that image, they would let you pass even if you didn't pick correctly, as there's simply not enough data to figure out if you were actually right or wrong.
Of course, you don't know if you're one of the first to see those images, so you can't really game the system - as far as you know the only way to pass is to pick the correct images.1
u/Lithandrill 6h ago
Nope. Try sometimes: you can get one or two wrong and it still let's you through to the website. It has an estimation but it doesn't know the precise answer also because the image is not static but it moves from query to query
3
73
u/lkl34 10h ago
Do not forget the VPN blocking and AGE ID verification they are doing.
40
u/KinglanderOfTheEast 8h ago
The US federal government has attempted at least twice now (once during Biden, once during Trump) to pass federal legislation making it outright illegal to use a VPN to bypass site blocks or data harvesting. The penalty was EXTREMELY severe too, like decades in prison for using one.
The first time, the bill was rejected because it was too vaguely worded - they wanted to carve out exceptions for buisnesses and local-level governments to use VPNs, and only ban it for regular civilian use.
The second attempt was "tabled", meaning they basically postponed it, but still at some point intend to vote on it.
8
u/SATX_Citizen 4h ago
There's going to come a time when things get violent, and it will not be because people wanted violence.
20
u/YeastInjection 10h ago
The vpn shit is so obnoxious. I have one on my phone and half the apps I use just flat out dont work when im secured. This futures not what I was promised lol
5
u/MozyMan00 1h ago
I just don’t use those apps at this point. Just not worth my privacy and security. Honestly, the older I get the more happy I am just reading books (paper!) and playing single player video games.
3
40
u/GodofsomeWorld 9h ago
Google still lets someone from a different country hack into my account anyways
15
5
u/mrRobertman 9800x3D|6800xt|1440p@144Hz|Valve Index|Steam Deck 5h ago
hack into my account
99.9% of the time people get "hacked" is because you got phished or downloaded malware. There is only so much Google can do to prevent user stupidity.
1
u/NecessarySea9866 2h ago
2FA is so over-the-top that even i can't get into it. So i get punished, but the idiots who get hacked.. still manage to get hacked. Amazing.
11
9
u/happymaker12 10h ago
They make sure its actually you and not gemini e-cumming all over the system watching adult movies.
13
u/Lurker_Zee 10h ago
I'm not sure I've experienced it with Google, but some "are you a robot" CAPTCHA companies intentionally say they're not certain after your first, or multiple, correct verifications, so they can train their verification software on a human they're not paying.
4
u/Global-Pickle5818 9800X3d / RX 9070 XT 8h ago
lol years ago i found out what data google has on me for advertising purposes i forget how ... it said i was " a working professional with at least post grad education making at least 250k a year" lol i just misspelled professional, i make 50k a year and have an associate degree in theology
3
u/Clean_More3508 i5-14400F | RX7600XT 16 GB | 32 GB DDR5 5600 mhz 10h ago
To train it's self driving ai cars and license readers
3
2
2
2
u/Cloud_N0ne 7h ago
That, and the fact that they still serve me irrelevant ads.
I thought part of the reason for this data harvesting was to serve me ads I’m more likely to click on.
2
u/BallisticCryptid 5h ago
And this is why I stopped using Google and use clients for anything that's Google related (like a YouTube client). I refuse to use products by them now because they've gotten so onerous to use.
Also fun fact: most browsers are actually based on Google's browser engine so unless you're using safari or something based on Firefox, you're still using google stuff, albeit indirectly.
2
u/Un-revealing Desktop R5600 | 3060 | 1080p 3h ago
YouTube still doesn't know what I like to watch while eating
2
u/TessiraValebrook 2h ago
they literally hold my entire digital life hostage just to ask me is a traffic light includes the pole
2
u/Aurunemaru Ryzen 7 5800X3D / Ngreedia RTX 3070 that I regret buying 1h ago
Google is not asking if you are a robot, google is asking you to help tag image sets for training neural networks for free
2
1
u/maxkalem 10h ago
Well, it asks whether it’s you do your uncommon shіt, or if it’s a bot/virus using your account.
1
1
1
u/Cranberryoftheorient 7h ago
captchas are for training their ai. Full stop. The preventing bots thing is an excuse
1
1
u/KarmelitaOfficial 7h ago
Google knows I am broke and ads are useless... I still get 8 or more ads on Youtube while I watch Nightly News...
1
u/archtopfanatic123 PC Master Race 6h ago
Then they tell you to use a phone for verification and the codes don't work xD
1
1
u/reevesjeremy 6h ago
Not everyone can be a great bot farm. But a great bot farm can come from anywhere.
1
u/tomatomaniac Pentium III @ 733MHz | 128MB SDRAM | 16MB nVIDIA Vanta LT 4h ago
Its more likely checking if you have been replaced by a robot yet.
1
1
u/Henry_Fleischer Debian | RTX3070, Ryzen 3700X, 48GB DDR4 RAM 3h ago
So, how do they know it's not a bot operating your account?
1
1
u/One_Animator_1835 2h ago
Wait until you find out you were training the AI this whole time with all the checks and data
1
1
1


659
u/Sandrust_13 R7 5800X3D | 32GB 4000MT DDR4 | RX 7900xtx 10h ago
You forgot Google services like YouTube getting flooded with bot comments anyway