banner



How To Check Recaptcha V3 Score

With Firefox fingerprint resisting turned on and with Ublock Origin/UMatrix, I get a score of 0.1. And I'm non fifty-fifty on a VPN; I'one thousand certain on my home network I'd accept an even lower score.

To me, it feels similar Google's unabridged strategy behind reCaptcha is to brand information technology harder to protect your privacy. Nosotros've basically given up on the idea that at that place are tasks only humans tin do, and to me V3 feels like Google openly saying, "You know how we tin can show you're non a robot? Because we literally know exactly who you are." I don't even know if it should be chosen a captcha -- it feels like it's just identity verification.

I don't recollect this is an acceptable tradeoff. I know that when reCaptcha shows up on HN there'southward frequently a oversupply that says, "but how else can nosotros block bots?" I'k gonna draw a personal line in the sand and say that I think protecting privacy is more of import than stopping bots. If your website tin can't stop bots without violating my privacy, and so I'm starting to feel like I might exist on the bots' side.

> information technology feels like Google'southward entire strategy behind reCaptcha is to make it harder to protect your privacy

For the irony, I'm still logged into GMail and it nevertheless works perfectly, equally basic HTML, fifty-fifty with google.com forbidden to run scripts. But information technology's the flippin' reCaptchas all over the place that make me temp-allow google.com, and then a reload later, temp-let gstatic.com and reload again. Just and then I go to use someone else's site normally, and I tin disallow over again... it'due south irritating. And then, this.

BTW that page manifestly says the scores are samples and non related to reality. Refresh a few times and spotter it alter. 0.iii, 0.7, and 0.9 seem to be my lucky numbers. I see everyone else getting those and 0.1.

Please stop reading things into information technology oh it'southward too late. Maybe they suddenly started seeing this page hundreds of times in the referrer and added that bit afterwards, I don't know.

Dunno if it'southward changed recently or if I just didn't refresh plenty before, only I'm now seeing basically random numbers as well.

If anyone wants a fun weekend project, I would love for there to exist a few public sites I tin can reliably check my product score on.

I'm non certain it matters though, since I'm but ignoring most sites that use reCaptcha now. For sites I can't ignore, I've taken to emailing them with my requests instead -- recently I tried to use Spotify's internal data consign tool and it wouldn't let me past. If you're not going to permit me use a website to manage my existing account, then your back up squad can do it for me.


I get the exact same score no thing what browser I use, despite uBlock Origin & Privacy Badger & Decentraleyes, even in private mode and with a VPN connectedness from a country I normally don't utilize. Hmmmmm...

When I just continue reloading, I get either 0.9 or 0.1. I get 0.1 more often. Interesting.

Maybe some browser extension can monitor the score and tell me what it currently is on each folio load, when reCaptcha is used on some website. I'd just keep reloading, until it's good, and then try the captcha.

Same. FF dev, uBlock, Decentraleyes

Changing the FF content policy from Standard to Strict appears to accept no touch on on the score.

Opening in a Private window drops information technology to 0.7 for me. I have a bunch of add ons allowed in Private Browsing, so not surprised information technology only dropped a piddling.

Of course, if you have 3rd party frames and scripts disabled globally via uBlock, information technology doesn't even load.

Ublock Origin + NoScript on FF threescore.7.2esr and got 0.9 as well.

[edit] tried in a private window and got the same score.

FF private window + UBlock + Resist Fingerprinting = 0.1 for me

In my chief FF window with UBlock + Resist Fingerprinting, logged into a ton of Google accounts, I too got 0.1

Going to approximate that without fingerprinting data they are probably going to give you a 0.1.


Practice you need to restart FF with that? After setting it to true and using a private window, FF nonetheless registers a score of 0.ix.


First endeavor in Vivaldi's individual fashion got me still a 0.three . Then I tested information technology while being logged into Google and it went to 0.9 . However, when I tried information technology over again in private mode, I got 0.9 there besides. Temporary fingerprints evidence quite the event.

I also get 0.1 with the same config as you, except that I had uMatrix disabled (which if anything, should better the score in Google'south eyes)...

so why are they having you solve image puzzles if they know that they are going to fail yous? fifty-fifty if they know that yous are human being...

It seems totally reasonable that Google knows yous're non a bot if you have a Google account. This isn't the problem, although information technology hides the problem.

The problem is that they aren't trying harder for users who aren't logged in.


I'one thousand but waiting for the AI-generates imitation people and any style they will come up to monetize that!

Your privacy isn't almost equally of import as you retrieve, and every bit long every bit you keep to overvalue it, you'll proceed to be unwilling to trade it for convenience.

That'southward on yous, not Google.

Using Firefox with uBlock and Cookie-Autodelete I get 0.one

Using Chrome, even incognito and with uBlock I get 0.7

(╯°□°)╯︵ ┻━┻. F y'all, Google, this is blatant bullying, technically unjustifyable abuse of your stranglehold over the whole web platform.

To offer a dissimilar datapoint:

On FireFox with uBlock on and logged into my corporate gmail I go 0.nine, switching to a individual tab I get 0.7. This is with every privacy setting turned on in the FF options.


I besides have a like result (0.vii) using my browser at piece of work. I am using containers, uBlock, privacy badger and auto-delete cookies.


> NOTE:This is a sample implementation, the score returned here is not a reflection on your Google account or type of traffic.

Using chrome on my telephone I get 0.9, but if I switch to Firefox I get 0.ane.

This is essentially going to let Google gatekeep the web if you aren't using their services.


Really? I don't think so. I get a 0.nine on Google Chrome, and a 0.7 on Firefox. I heavily utilise Chrome and I take not used Firefox apart from mayhap testing some local websites. Despite this I still got 0.7 on there. I expected lower since I don't employ the browser.


On a flip side: you really should bank check privacy settings in your Firefox, it seems Google tin track yous hands in that location. ;)

I utilize Firefox with Google container and uBlock Origin and Privacy Badger and also get a score of 0.7

How tin can I get better privacy settings?


I was being sarcastic - high score on captcha probably means G knows too much about yous. That said, I don't think the scores are reliable. Information technology is possible (probable even) that G is still running experiments.


I become 0.i continuously, maybe because I take resist fingerprinting enabled in Firefox. I'chiliad not irresolute anything to compensate that score; it shows I must be doing something correct. If I encounter a reCAPTCHA I will go on to (ordinarily) simply leave the site it'southward on.

Opposite to the results here, using Firefox + uBlock with DNT and tracking protection enabled, I get a score of 0.9. In private browsing mode information technology's 0.7.

I wonder how many people hither are using a VPN or accessing from a non-western land -- I'd bet those are much bigger factors

FF logged into Google account: 0.ix

FF incognito window not logged into Google business relationship: 0.vii

FF incognito window not logged into Google account through VPN: 0.3

FYI I have uBlock, pi-pigsty and a bunch of privacy widgets enabled


This looks like a RNG: I got 0.seven, 0.ix, and 0.i successively. It tin't make up its mind whether I'm almost certainly not a bot (0.9) or almost certainly a bot (0.1)?


Perhaps the rapid, repeated identical requests outweighed the initial factors which gave you a positive response


Might very well be. I also become errors on hacker news about "tin can't process requests that fast". When request nearly it (initially because I idea votes didn't piece of work randomly), the limit is a few requests per second. Turns out I click faster than that, either past reading a whole comment thread and making upwardly my mind whose comments were most helpful (to upvote all at once) or past navigating too fast.

from the link

>the score returned here is not a reflection on your Google account or type of traffic

I got random scores also. It looks like this is merely a sample of the data structure that the service returns, not the actual score.


That would exist a useless site, but that's not how I read it. I empathise information technology as "this is non that Google thinks your business relationship is a bot, information technology's that this request might exist made by a bot. And since you didn't use this site as a normal website, it too doesn't score your blazon of traffic, just this one request". Yous might be right, but information technology actually does seem to be doing a request to their API.

>That would be a useless site

looks like information technology is a demo of the API for people wanting to swallow it. knowing what the payload looks like is not useless at all in this example.


Documenting requests' format and their return values is documentation and doesn't require an interactive site that looks totally real and makes yous expect a real (rather than a dummy) answer. Which is not to say it's impossible, but it would be weird/unlikely. Usually when there is an example api request in documentation, it's a real (live) request, too, and this isn't even a documentation folio.

> This looks like a RNG

Come on, how is everyone in this chain so blind. Information technology's literally in bold and the single largest block of content on the folio:

Notation:This is a sample implementation, the score returned here is non a reflection on your Google account or type of traffic. In product, refer to the distribution of scores shown in your admin interface and adapt your own threshold accordingly. Do not raise issues regarding the score yous see here.

> Come on, how is anybody in this chain so bullheaded

Please see the sibling comments (that were in that location before yours) where this is already being discussed, before being insulting.

I also got 0.ane even though I'm not on a VPN, and have a stock FF installation with just uBlock addon. I remember my Isp may take some office in it but notwithstanding 0.1 score is 100% bot right?

I'm also logged into google and fb which also doesn't affect my score. Only shows how cleaved their algorithm is :(

edit: just tried it with chrome and my score jumped to 0.9! So definitely non my ISP. It'southward simply my browser that Recaptcha doesn't like. If you put 2 and two together that'due south really evil shit, even for Google!


I got 0.7 on FF, 0.3 on Opera and Chrome, all in incognito mode. Peradventure they have just a few values and return information technology based on AND OR logic of two-4 variable. Or maybe they are simply playing around trying to get together some stats, for some "Don't be Evil" purpose!


Google is putting a number on us, is honestly some Minority Report level dystopia. Google is already using this to make life hell for anyone who cares near their privacy, we need to practice something well-nigh this before they terminate putting upwards their iron curtain over the web. Would it be possible to sue website owners for requiring such invasive measures? I'd love to see this ruled equally monopoly power and Google broken up but that'south probably non very realistic and then nosotros would probably practice better to make using Google captchas more expensive in court costs alone than only edifice their ain solutions to fight bots.

Work Firefox which I utilize all the fourth dimension, no addons (including any adblockers): 0.1

Almost unused Chrome installation, also without addons: 0.7


Seeing what everyone else has posted I'm very suprised that I've received a 0.3 using Chrome on Android. I'm logged in to Google and most of my browsing is via Chrome or Chrome based webview. At least on my phone I've never cleared my cookies or done anything special.


This is full bullshit. My score of 0.1 in firefox shoots up to 0.9 if I alter my user agent to ChromeOS. No other changes - same ready of ghostery/advertising blocker/fingerprinting prevention, etc. What a scam.


Ding ding ding ding, Google'south way of killing the other browsers in the market for expert, kill off the adblockers manifest, literally become the entity which monitors the internet as much as the NSA...

Oscillates between 0.1 and 0.7 for me, and I'm changing aught on my end (just striking "Try once more"). Does it have to practice with refresh speed, I wonder?

Privacy Badger and ABP on my piece of work (less-locked-down) Mac.


Hitting the same URL over and over over again is bot-like behaviour. When working with reCaptcha on forms I ordinarily start getting hit after 4-5 exam submissions.


I get .9 in Firefox on my MBP with UBlock Origin installed. I wondered if it was because I was logged in to Google, so I tried Incognito and got .vii. In a never-earlier-used container I also get .vii.


I get a 0.seven on my estimator on Firefox. If I use the same website in Chrome (which is signed into a Google account) I become a 0.9. I guess information technology'south a [0,1] scale?

I'm guessing their a-listers came upwardly with something like this:

                                                                  // TODO: add together impressive-looking math     if (signedin && trackedEverywhere) {          render 0.9     } else {          return 0.7     }                                                              
I think nosotros give Google fashion too much credit for their talent. This is the same company that didn't feel like finishing their website for two decades and subsequently stole $75 one thousand thousand from their users even when Google knew [1].

The same company that somehow notwithstanding doesn't reconcile amounts owed and only keeps the money when they randomly-ban users and hide behind fake support emails, only they did feel like paying $11 meg to go along that away from scrutiny [two].

[i] https://world wide web.businessinsider.com/google-emails-adtrader-lawsu...

[2] https://www.searchenginejournal.com/adsense-lawsuit/248135/


Google consistently gives me the impression of a company that (I suppose) has tons of smart people in it, simply has desperately cleaved management & incentive structures leading them to constantly practise bafflingly stupid stuff at both large and small scales, even by the standards of a bigcorp, to the point that they survive simply because they've got one hell of a golden goose.

Good info. Give thanks yous.

And in keeping with recent revelations on Google's manipulation of search results, I call up they have really gone beyond the pale. I un-archived my old iPhone two days ago and went dorsum to iOS subsequently the James O'Keefe/Project Veritas revelations. I at present cannot, in expert censor, use annihilation Google. I always knew about the tracking and all that because, after all, they are an ad company. I'm at present in the process of moving all of my domains over to Fastmail, which I've used since 2002. I'm using Qwant, Startpage, and DDG for search. FF for browser with many about:config tweaks and several add-ons.

Please explain. Fifty-fifty without the revelations from PV, it's plainly obvious Google, et al are biased. Anyone tin can see it. Silicon Valley is a bloody echo chamber. If the videos past PV were not damning in the least, why did 4 different companies take them down and remove the accounts of PV?

Sunlight is the very best disinfectant. People have a right to know if searches are being manipulated to one side.

If I sign out of my google business relationship in Chrome it drops from 0.9 to 0.vii.

I could accept sworn I'd never signed in to Chrome using my google business relationship, merely I approximate I must have mistakenly signed in to gmail or something.

I use FF as my main browser, only always drop back to Chrome sporadically, or when I really want tabs to be completely isolated (at that place are some annoyingly CPU/ability intensive stuff I do from time to fourth dimension, and I can just renice Chrome while I get on with other stuff.)

> I could have sworn I'd never signed in to Chrome using my google account, but I gauge I must have mistakenly signed in to gmail or something.

Chrome 69 tricked users into signing into the browser, myself included - https://lifehacker.com/how-to-disable-chromes-automatic-sign...

That was the terminal straw to uninstall Chrome from all my devices and I've been a happy Firefox user always since. Well, except now reCAPTCHA inappreciably ever works.


I believe that'south a "feature" they added a while back, car-signing you into chrome every bit soon as you was logged into gmail.

The GP post's IP address or other fingerprint may be validated from other Google properties they might have visited, so I wouldn't put so much stock in the 0.vii.

Honestly... if information technology's the same team that did ReCaptcha 2.0, this is a team that pulls out all the stops. Per https://github.com/neuroradiology/InsideReCaptcha ... they implemented a freaking VM in Javascript to obfuscate the code that combines diverse signals. There's a lot going on here that'south likely highly obfuscated and quantized before it'due south displayed to united states of america.

EDIT: non-paywall link for [one] in the parent post: https://outline.com/aA7HS5


So, I nevertheless accept to whitelist Google in uMatrix and allow cookies for this to work. Even after doing so, I get a 0.1. I reloaded the page to check for variation equally some other users mentioned simply get the aforementioned score each fourth dimension. I approximate Google is saying I shouldn't exist allowed to use the internet.

0.3 with Brave on Android, no extensions. 0.9 with Chrome on the aforementioned device, same connectedness.

Brave isn't particularly "unusual", and is even based on Chromium - surely this is Google blatantly punishing non-Chrome users?

Interesting.

I become a 0.7 on Chrome with no business relationship logged in and uBlock Origin installed.

Same browser, aforementioned plugin but incognito information technology's 0.1.

Papa google needs my data to trust me. Makes consummate sense but nevertheless interesting that you can affect your score past giving in.


What is most odd is I get 0.vii on iOS Safari which I utilise for 100% of my purposeful mobile browsing, just I get .9 on iOS Chrome, which is only used when I accidentally click on links from gmail (then very, very rarely).


Not really odd at all - if you're using the gmail app, there's a shared hallmark cookie in all Google apps - including Chrome, so Google knows who yous are in Chrome.

A consistent 0.iii.

> fault-codes": ["score-threshold-not-met"]

Not sure if happy or not happy with that. I volition conclude happy plenty.

Linux, on VPN, Firefox. Not logged into any Google services. Cleared caches (nevertheless same IP), no difference.


Stock Qutebrowser 0.7, FF w/ all the usual extensions (ublock origin) 0.7. Don't know if information technology matters simply I'm rolling Curvation. Just adding another point of data for those curious.

From my calculator, where I browse fairly as with all three of Chrome, Safari, and Firefox (admitting unlike sites), I become the post-obit scores:

Chrome: .nine

Safari: .7

Firefox: .one

I have adblock running on all 3, and I apply containers on Firefox.


interesting my score is 0.9 if I allowed google to track me using cookies, if I block the cookies information technology goes to 0.7 and if I enable content blocking in Firefox it drops to 0.ane


With desktop Chrome I get a 0.3. My browser sends Practise Not Track, has PrivacyBadger extension, and has that useless google-contour-in-the-browser feature disabled.

I got 0.ix on Chrome, logged into google. I also got 0.9 on Firefox, not logged into google.

In incognito mode in chrome, I sometimes get 0.9 and sometimes 0.7 when I reload.


Using desktop Safari incognito without a Google account and Ghostery enabled, I get 0.seven as well. Interestingly, disabling CSS drops me to 0.i...


Interestingly enough I got .nine on Edge with Ublock origin installed. Mayhap this has something to do with how Edge is using webkit now?


I got 0.9 in my Android telephone running chrome. When I opened it in incognito style, my score was reduced to 0.7


It gives me 0.7 on Safari (uBlock Origin) while 0.3 on Chrome (uBlock Origin) - both macOS Mojave.

>Please upgrade to a supported browser to get a reCAPTCHA challenge

I guess this is a 0 for me then

iPhone with a good (not amazing) adblocker: 0.seven

Safari macOS with the same adblocker: 0.7

Firefox macOS with a lot of adblockers: 0.i


Information technology didn't load for me and I couldn't figure out why.

Then I remembered that I put this in my /etc/hosts a few weeks ago and forgot about it.

                                                                      127.0.0.1       google.com     127.0.0.1       world wide web.google.com                                                                  
[Edit] So if nothing shows up for you on that folio, bank check for that. As well I just generally recommend it. Google has some unethical practices and duckduckgo.com is pretty skilful.

I got "reCAPTCHA script loading".

You need non to use hosts to block it, uMatrix could practise information technology past itself.

Source: https://news.ycombinator.com/item?id=20295040

0 Response to "How To Check Recaptcha V3 Score"

Post a Comment

Iklan Atas Artikel

Iklan Tengah Artikel 1

Iklan Tengah Artikel 2

Iklan Bawah Artikel