Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Heh, I know people who are working on breaking reCaptcha. Maybe they should get together and learn from each other.

If you're saying that it's possible to prevent manual, outsourced captcha solving, I would have to strongly disagree. It's similar to the futility of DRM as an antipiracy measure. As long as I can see the captcha, I can pay someone in another country to solve it for me.

I will agree that it's rare- but the most sophisticated and high-volume spammers do it, and they're the ones you have to worry about.

In case people start giving me sideways glances I want to make it clear that I haven't done any blackhat stuff in a very long time, but I'm still interested in the blackhat community from a security researcher's perspective.



I'm not saying that its possible to do it in an automated way. I'm just saying that tools exist to create red flags that would make thing easily verified by a human. They have ways in which they deal with these things. All I'm saying is so far, its been working for them.


You're probably not going to tell me more about these tools, although I would be very curious to learn how they work.

All I have is anecdotal evidence- I know several people who are making their living spamming Craigslist and outsourcing their ReCaptcha solving. Since they can make $XX per post, paying pennies for captcha is a tiny expense. I don't condone this behavior, but be aware- it happens more than you think.

Anyway, probably best to take the discussion to email if you want more...perspective from the other side.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: