▲ 420 ▼ Scan to Verify You're Human (thelemmy.club) submitted 2 months ago by sidebro@lemmy.zip to c/mildlyinfuriating@lemmy.world 105 comments fedilink hide all child comments No I don't think so
[–] gressen@lemmy.zip 105 points 2 months ago (3 children) Name the offending website please. permalink fedilink source hideshow 6 child comments replies: [–] lemmyng@piefed.ca 141 points 2 months ago (2 children) Google. It's their recaptcha service doing that. The QR code validation also gets rejected if you're using a privacy oriented mobile OS like Graphene. permalink fedilink source parent hideshow 4 child comments replies: [–] markz@suppo.fi 50 points 2 months ago At the cost of conditioning people into following orders from random qr codes permalink fedilink source parent [–] dieTasse@feddit.org 14 points 2 months ago* (1 child) you mean it was google,com? Or on which website was this recaptcha? permalink fedilink source parent hideshow 2 child comments replies: [+] lemmyng@piefed.ca -12 points 2 months ago (1 child) Recaptcha is a service offered by Google. It doesn't matter on which site the user encountered the QR code verification request - the problem is with Google (the company.) permalink fedilink source parent hideshow 2 child comments replies: [–] MartianSands@sh.itjust.works 70 points 2 months ago (3 children) It does matter, because that Google integration didn't happen by magic. Whatever the site is, they chose to do things that way. The only way Google stops things like this is if they get actual pushback, and the only realistic way to achieve that is to make the people using their service reconsider. permalink fedilink source parent hideshow 6 child comments replies: [–] dieTasse@feddit.org 1 point 2 months ago Exactly this! permalink fedilink source parent [–] kuberoot@discuss.tchncs.de 1 point 2 months ago (1 child) The screenshot looks like it might be a cloudflare verification page, which would put another layer of separation between the site owner and the QR system. permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 2 points 2 months ago* Cloudflare don't use reCaptcha, they use turnstile permalink fedilink source parent [–] lemmyng@piefed.ca -1 points 2 months ago and the only realistic way to achieve that is to make the people using their service reconsider. So what exactly will naming the site achieve? If someone wants to boycott recaptcha (which I'm 100% onboard with, btw) they'll just not comply with the captcha and leave the site when they encounter it. On the other hand, someone who would not otherwise visit the site cannot reduce traffic to the site by direct action. Telling their friends "don't use that site, it uses recaptcha" is no more effective than telling them "don't use any site that requires you to do QR recaptchas." permalink fedilink source parent [–] sidebro@lemmy.zip [S] 21 points 2 months ago (1 child) archive.is in this case permalink fedilink source parent hideshow 2 child comments replies: [–] 9bananas@feddit.org 7 points 2 months ago (1 child) are they fucking serious with this shit? what the hell... permalink fedilink source parent hideshow 2 child comments replies: [–] woelkchen@lemmy.world 15 points 2 months ago (2 children) Archive.is is a Russian propaganda bot net. Don't use it. permalink fedilink source parent hideshow 4 child comments replies: [–] 9bananas@feddit.org 3 points 2 months ago (1 child) ah, that explains it...i half-remembered that something is off about that site, but couldn't remember what it was...thanks for the heads up! permalink fedilink source parent hideshow 2 child comments replies: [–] cows_are_underrated@feddit.org 4 points 2 months ago They also launched DDOS attacks against multiple other sites (e.g. Wikipedia). permalink fedilink source parent [–] SystemDisc@feddit.org 1 point 2 months ago (1 child) What are good alternatives? permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 3 points 2 months ago Ghost archive permalink fedilink source parent [–] wander1236@sh.itjust.works 18 points 2 months ago (1 child) It looks like a Cloudflare interstitial. I also don't think sites get to choose which challenge types show up in reCAPTCHA, so this is on Google. permalink fedilink source parent hideshow 2 child comments replies: [–] fizzle@quokk.au 20 points 2 months ago (1 child) Isn't the site choosing to use recaptcha? permalink fedilink source parent hideshow 2 child comments replies: [–] wander1236@sh.itjust.works 7 points 2 months ago (1 child) The site is using Cloudflare for DDoS protection, and unfortunately Cloudflare is probably the most effective tool for this. It also looks like it might be archive.org in the screenshot, and they've been dealing with a lot of DDoS attacks lately. I don't think Google advertises "we force you to scan a QR code" as a feature of reCAPTCHA either, so it feels a little weird to me to blame the site for using a DDoS protection tool that in turn uses reCAPTCHA for human verification when Google randomly decides to add a new stupid challenge type. permalink fedilink source parent hideshow 2 child comments replies: [–] VonReposti@feddit.dk 5 points 2 months ago As far as I know, Cloudflare doesn't use reCaptcha. I think they use a version of hCaptcha running on their own workers. permalink fedilink source parent
[–] lemmyng@piefed.ca 141 points 2 months ago (2 children) Google. It's their recaptcha service doing that. The QR code validation also gets rejected if you're using a privacy oriented mobile OS like Graphene. permalink fedilink source parent hideshow 4 child comments replies: [–] markz@suppo.fi 50 points 2 months ago At the cost of conditioning people into following orders from random qr codes permalink fedilink source parent [–] dieTasse@feddit.org 14 points 2 months ago* (1 child) you mean it was google,com? Or on which website was this recaptcha? permalink fedilink source parent hideshow 2 child comments replies: [+] lemmyng@piefed.ca -12 points 2 months ago (1 child) Recaptcha is a service offered by Google. It doesn't matter on which site the user encountered the QR code verification request - the problem is with Google (the company.) permalink fedilink source parent hideshow 2 child comments replies: [–] MartianSands@sh.itjust.works 70 points 2 months ago (3 children) It does matter, because that Google integration didn't happen by magic. Whatever the site is, they chose to do things that way. The only way Google stops things like this is if they get actual pushback, and the only realistic way to achieve that is to make the people using their service reconsider. permalink fedilink source parent hideshow 6 child comments replies: [–] dieTasse@feddit.org 1 point 2 months ago Exactly this! permalink fedilink source parent [–] kuberoot@discuss.tchncs.de 1 point 2 months ago (1 child) The screenshot looks like it might be a cloudflare verification page, which would put another layer of separation between the site owner and the QR system. permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 2 points 2 months ago* Cloudflare don't use reCaptcha, they use turnstile permalink fedilink source parent [–] lemmyng@piefed.ca -1 points 2 months ago and the only realistic way to achieve that is to make the people using their service reconsider. So what exactly will naming the site achieve? If someone wants to boycott recaptcha (which I'm 100% onboard with, btw) they'll just not comply with the captcha and leave the site when they encounter it. On the other hand, someone who would not otherwise visit the site cannot reduce traffic to the site by direct action. Telling their friends "don't use that site, it uses recaptcha" is no more effective than telling them "don't use any site that requires you to do QR recaptchas." permalink fedilink source parent
[–] markz@suppo.fi 50 points 2 months ago At the cost of conditioning people into following orders from random qr codes permalink fedilink source parent
[–] dieTasse@feddit.org 14 points 2 months ago* (1 child) you mean it was google,com? Or on which website was this recaptcha? permalink fedilink source parent hideshow 2 child comments replies: [+] lemmyng@piefed.ca -12 points 2 months ago (1 child) Recaptcha is a service offered by Google. It doesn't matter on which site the user encountered the QR code verification request - the problem is with Google (the company.) permalink fedilink source parent hideshow 2 child comments replies: [–] MartianSands@sh.itjust.works 70 points 2 months ago (3 children) It does matter, because that Google integration didn't happen by magic. Whatever the site is, they chose to do things that way. The only way Google stops things like this is if they get actual pushback, and the only realistic way to achieve that is to make the people using their service reconsider. permalink fedilink source parent hideshow 6 child comments replies: [–] dieTasse@feddit.org 1 point 2 months ago Exactly this! permalink fedilink source parent [–] kuberoot@discuss.tchncs.de 1 point 2 months ago (1 child) The screenshot looks like it might be a cloudflare verification page, which would put another layer of separation between the site owner and the QR system. permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 2 points 2 months ago* Cloudflare don't use reCaptcha, they use turnstile permalink fedilink source parent [–] lemmyng@piefed.ca -1 points 2 months ago and the only realistic way to achieve that is to make the people using their service reconsider. So what exactly will naming the site achieve? If someone wants to boycott recaptcha (which I'm 100% onboard with, btw) they'll just not comply with the captcha and leave the site when they encounter it. On the other hand, someone who would not otherwise visit the site cannot reduce traffic to the site by direct action. Telling their friends "don't use that site, it uses recaptcha" is no more effective than telling them "don't use any site that requires you to do QR recaptchas." permalink fedilink source parent
[+] lemmyng@piefed.ca -12 points 2 months ago (1 child) Recaptcha is a service offered by Google. It doesn't matter on which site the user encountered the QR code verification request - the problem is with Google (the company.) permalink fedilink source parent hideshow 2 child comments replies: [–] MartianSands@sh.itjust.works 70 points 2 months ago (3 children) It does matter, because that Google integration didn't happen by magic. Whatever the site is, they chose to do things that way. The only way Google stops things like this is if they get actual pushback, and the only realistic way to achieve that is to make the people using their service reconsider. permalink fedilink source parent hideshow 6 child comments replies: [–] dieTasse@feddit.org 1 point 2 months ago Exactly this! permalink fedilink source parent [–] kuberoot@discuss.tchncs.de 1 point 2 months ago (1 child) The screenshot looks like it might be a cloudflare verification page, which would put another layer of separation between the site owner and the QR system. permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 2 points 2 months ago* Cloudflare don't use reCaptcha, they use turnstile permalink fedilink source parent [–] lemmyng@piefed.ca -1 points 2 months ago and the only realistic way to achieve that is to make the people using their service reconsider. So what exactly will naming the site achieve? If someone wants to boycott recaptcha (which I'm 100% onboard with, btw) they'll just not comply with the captcha and leave the site when they encounter it. On the other hand, someone who would not otherwise visit the site cannot reduce traffic to the site by direct action. Telling their friends "don't use that site, it uses recaptcha" is no more effective than telling them "don't use any site that requires you to do QR recaptchas." permalink fedilink source parent
[–] MartianSands@sh.itjust.works 70 points 2 months ago (3 children) It does matter, because that Google integration didn't happen by magic. Whatever the site is, they chose to do things that way. The only way Google stops things like this is if they get actual pushback, and the only realistic way to achieve that is to make the people using their service reconsider. permalink fedilink source parent hideshow 6 child comments replies: [–] dieTasse@feddit.org 1 point 2 months ago Exactly this! permalink fedilink source parent [–] kuberoot@discuss.tchncs.de 1 point 2 months ago (1 child) The screenshot looks like it might be a cloudflare verification page, which would put another layer of separation between the site owner and the QR system. permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 2 points 2 months ago* Cloudflare don't use reCaptcha, they use turnstile permalink fedilink source parent [–] lemmyng@piefed.ca -1 points 2 months ago and the only realistic way to achieve that is to make the people using their service reconsider. So what exactly will naming the site achieve? If someone wants to boycott recaptcha (which I'm 100% onboard with, btw) they'll just not comply with the captcha and leave the site when they encounter it. On the other hand, someone who would not otherwise visit the site cannot reduce traffic to the site by direct action. Telling their friends "don't use that site, it uses recaptcha" is no more effective than telling them "don't use any site that requires you to do QR recaptchas." permalink fedilink source parent
[–] kuberoot@discuss.tchncs.de 1 point 2 months ago (1 child) The screenshot looks like it might be a cloudflare verification page, which would put another layer of separation between the site owner and the QR system. permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 2 points 2 months ago* Cloudflare don't use reCaptcha, they use turnstile permalink fedilink source parent
[–] Axolotl_cpp@feddit.it 2 points 2 months ago* Cloudflare don't use reCaptcha, they use turnstile permalink fedilink source parent
[–] lemmyng@piefed.ca -1 points 2 months ago and the only realistic way to achieve that is to make the people using their service reconsider. So what exactly will naming the site achieve? If someone wants to boycott recaptcha (which I'm 100% onboard with, btw) they'll just not comply with the captcha and leave the site when they encounter it. On the other hand, someone who would not otherwise visit the site cannot reduce traffic to the site by direct action. Telling their friends "don't use that site, it uses recaptcha" is no more effective than telling them "don't use any site that requires you to do QR recaptchas." permalink fedilink source parent
[–] sidebro@lemmy.zip [S] 21 points 2 months ago (1 child) archive.is in this case permalink fedilink source parent hideshow 2 child comments replies: [–] 9bananas@feddit.org 7 points 2 months ago (1 child) are they fucking serious with this shit? what the hell... permalink fedilink source parent hideshow 2 child comments replies: [–] woelkchen@lemmy.world 15 points 2 months ago (2 children) Archive.is is a Russian propaganda bot net. Don't use it. permalink fedilink source parent hideshow 4 child comments replies: [–] 9bananas@feddit.org 3 points 2 months ago (1 child) ah, that explains it...i half-remembered that something is off about that site, but couldn't remember what it was...thanks for the heads up! permalink fedilink source parent hideshow 2 child comments replies: [–] cows_are_underrated@feddit.org 4 points 2 months ago They also launched DDOS attacks against multiple other sites (e.g. Wikipedia). permalink fedilink source parent [–] SystemDisc@feddit.org 1 point 2 months ago (1 child) What are good alternatives? permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 3 points 2 months ago Ghost archive permalink fedilink source parent
[–] 9bananas@feddit.org 7 points 2 months ago (1 child) are they fucking serious with this shit? what the hell... permalink fedilink source parent hideshow 2 child comments replies: [–] woelkchen@lemmy.world 15 points 2 months ago (2 children) Archive.is is a Russian propaganda bot net. Don't use it. permalink fedilink source parent hideshow 4 child comments replies: [–] 9bananas@feddit.org 3 points 2 months ago (1 child) ah, that explains it...i half-remembered that something is off about that site, but couldn't remember what it was...thanks for the heads up! permalink fedilink source parent hideshow 2 child comments replies: [–] cows_are_underrated@feddit.org 4 points 2 months ago They also launched DDOS attacks against multiple other sites (e.g. Wikipedia). permalink fedilink source parent [–] SystemDisc@feddit.org 1 point 2 months ago (1 child) What are good alternatives? permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 3 points 2 months ago Ghost archive permalink fedilink source parent
[–] woelkchen@lemmy.world 15 points 2 months ago (2 children) Archive.is is a Russian propaganda bot net. Don't use it. permalink fedilink source parent hideshow 4 child comments replies: [–] 9bananas@feddit.org 3 points 2 months ago (1 child) ah, that explains it...i half-remembered that something is off about that site, but couldn't remember what it was...thanks for the heads up! permalink fedilink source parent hideshow 2 child comments replies: [–] cows_are_underrated@feddit.org 4 points 2 months ago They also launched DDOS attacks against multiple other sites (e.g. Wikipedia). permalink fedilink source parent [–] SystemDisc@feddit.org 1 point 2 months ago (1 child) What are good alternatives? permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 3 points 2 months ago Ghost archive permalink fedilink source parent
[–] 9bananas@feddit.org 3 points 2 months ago (1 child) ah, that explains it...i half-remembered that something is off about that site, but couldn't remember what it was...thanks for the heads up! permalink fedilink source parent hideshow 2 child comments replies: [–] cows_are_underrated@feddit.org 4 points 2 months ago They also launched DDOS attacks against multiple other sites (e.g. Wikipedia). permalink fedilink source parent
[–] cows_are_underrated@feddit.org 4 points 2 months ago They also launched DDOS attacks against multiple other sites (e.g. Wikipedia). permalink fedilink source parent
[–] SystemDisc@feddit.org 1 point 2 months ago (1 child) What are good alternatives? permalink fedilink source parent hideshow 2 child comments replies: [–] Axolotl_cpp@feddit.it 3 points 2 months ago Ghost archive permalink fedilink source parent
[–] wander1236@sh.itjust.works 18 points 2 months ago (1 child) It looks like a Cloudflare interstitial. I also don't think sites get to choose which challenge types show up in reCAPTCHA, so this is on Google. permalink fedilink source parent hideshow 2 child comments replies: [–] fizzle@quokk.au 20 points 2 months ago (1 child) Isn't the site choosing to use recaptcha? permalink fedilink source parent hideshow 2 child comments replies: [–] wander1236@sh.itjust.works 7 points 2 months ago (1 child) The site is using Cloudflare for DDoS protection, and unfortunately Cloudflare is probably the most effective tool for this. It also looks like it might be archive.org in the screenshot, and they've been dealing with a lot of DDoS attacks lately. I don't think Google advertises "we force you to scan a QR code" as a feature of reCAPTCHA either, so it feels a little weird to me to blame the site for using a DDoS protection tool that in turn uses reCAPTCHA for human verification when Google randomly decides to add a new stupid challenge type. permalink fedilink source parent hideshow 2 child comments replies: [–] VonReposti@feddit.dk 5 points 2 months ago As far as I know, Cloudflare doesn't use reCaptcha. I think they use a version of hCaptcha running on their own workers. permalink fedilink source parent
[–] fizzle@quokk.au 20 points 2 months ago (1 child) Isn't the site choosing to use recaptcha? permalink fedilink source parent hideshow 2 child comments replies: [–] wander1236@sh.itjust.works 7 points 2 months ago (1 child) The site is using Cloudflare for DDoS protection, and unfortunately Cloudflare is probably the most effective tool for this. It also looks like it might be archive.org in the screenshot, and they've been dealing with a lot of DDoS attacks lately. I don't think Google advertises "we force you to scan a QR code" as a feature of reCAPTCHA either, so it feels a little weird to me to blame the site for using a DDoS protection tool that in turn uses reCAPTCHA for human verification when Google randomly decides to add a new stupid challenge type. permalink fedilink source parent hideshow 2 child comments replies: [–] VonReposti@feddit.dk 5 points 2 months ago As far as I know, Cloudflare doesn't use reCaptcha. I think they use a version of hCaptcha running on their own workers. permalink fedilink source parent
[–] wander1236@sh.itjust.works 7 points 2 months ago (1 child) The site is using Cloudflare for DDoS protection, and unfortunately Cloudflare is probably the most effective tool for this. It also looks like it might be archive.org in the screenshot, and they've been dealing with a lot of DDoS attacks lately. I don't think Google advertises "we force you to scan a QR code" as a feature of reCAPTCHA either, so it feels a little weird to me to blame the site for using a DDoS protection tool that in turn uses reCAPTCHA for human verification when Google randomly decides to add a new stupid challenge type. permalink fedilink source parent hideshow 2 child comments replies: [–] VonReposti@feddit.dk 5 points 2 months ago As far as I know, Cloudflare doesn't use reCaptcha. I think they use a version of hCaptcha running on their own workers. permalink fedilink source parent
[–] VonReposti@feddit.dk 5 points 2 months ago As far as I know, Cloudflare doesn't use reCaptcha. I think they use a version of hCaptcha running on their own workers. permalink fedilink source parent