Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

An interesting thing is that for Arkose to be effective against bad actors, they can't just make CAPTCHAs that are hard for bots. They also have to be not-easy or at least expensive for a subset of humans who aren't legitimate users, namely 'CAPTCHA Farms' like https://anti-captcha.com/.

Most CAPTCHAs, including ones made by Arkose, have site keys that are unique to that CAPTCHA and public/visible in the browser -- so companies like Anti Captcha can then automate sending challenging CAPTCHAs directly to a human solver in a 'CAPTCHA farm' who can solve it (in a different browser) and have the CAPTCHA return that it was successfully passed, usually all within ~a minute.

So to get around this and -- as Arkose's site says -- make fraud expensive for hackers, Arkose Labs has to make their CAPTCHAs hard/slow to solve. If they do that, then it becomes expensive for bad actors to rely on labor to solve them (anti-captcha.com cites 58 seconds/$3 per CAPTCHA).

As long as the site key is publicly exposed, this basically isn't going to change; you either need to also couple it with other anti-fraud tactics like device fingerprinting, or use a CAPTCHA that doesn't expose the site key at all.

Disclaimer - I work for a company (Stytch) that has a competing CAPTCHA product.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: