<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: eatbots</title><link>https://news.ycombinator.com/user?id=eatbots</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 06 Apr 2026 03:11:18 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=eatbots" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Browser agents have virtually no guardrails]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.hcaptcha.com/post/report-browser-agent-safety-is-an-afterthought-for-vendors">https://www.hcaptcha.com/post/report-browser-agent-safety-is-an-afterthought-for-vendors</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45735597">https://news.ycombinator.com/item?id=45735597</a></p>
<p>Points: 13</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 28 Oct 2025 17:06:53 +0000</pubDate><link>https://www.hcaptcha.com/post/report-browser-agent-safety-is-an-afterthought-for-vendors</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=45735597</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45735597</guid></item><item><title><![CDATA[how hCaptcha stayed up when Cloudflare and Google went down]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.hcaptcha.com/post/how-hcaptcha-stayed-up">https://www.hcaptcha.com/post/how-hcaptcha-stayed-up</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44270624">https://news.ycombinator.com/item?id=44270624</a></p>
<p>Points: 28</p>
<p># Comments: 4</p>
]]></description><pubDate>Fri, 13 Jun 2025 17:53:01 +0000</pubDate><link>https://www.hcaptcha.com/post/how-hcaptcha-stayed-up</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=44270624</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44270624</guid></item><item><title><![CDATA[New comment by eatbots in "1 bug, $50k in bounties, a Zendesk backdoor"]]></title><description><![CDATA[
<p>Reported this exact bug to Zendesk, Apple, and Slack in June 2024, both through HackerOne and by escalating directly to engs or PMs at each company.<p>I doubt we were the first. That is presumably the reason they failed to pay out.<p>The real issue is that non-directory SSO options like Sign in with Apple (SIWA) have been incorrectly implemented almost everywhere, including by Slack and other large companies we alerted in June.<p>Non-directory SSO should not have equal trust vs. directory SSO. If you have a Google account and use Google SSO, Google can attest that you control that account. Same with Okta and Okta SSO.<p>SIWA, GitHub Auth, etc are not doing this. They rely on a weaker proof, usually just control of email at a single point in time.<p>SSO providers are not fungible, even if the email address is the same. You need to take this into account when designing your trust model. Most services do not.</p>
]]></description><pubDate>Sat, 12 Oct 2024 15:09:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=41819655</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=41819655</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41819655</guid></item><item><title><![CDATA[New comment by eatbots in "An Empirical Study and Evaluation of Modern CAPTCHAs"]]></title><description><![CDATA[
<p>If you report the website/sitekey to hCaptcha support it'll get banned pretty quickly.</p>
]]></description><pubDate>Sun, 17 Dec 2023 21:45:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=38676755</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=38676755</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38676755</guid></item><item><title><![CDATA[New comment by eatbots in "How Well Do AI Text Detectors Work? (Benchmarks)"]]></title><description><![CDATA[
<p>hCaptcha tested popular detectors on confirmed LLM and human output. No public AI text detector scored better than random chance.</p>
]]></description><pubDate>Wed, 07 Jun 2023 18:13:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=36230911</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=36230911</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36230911</guid></item><item><title><![CDATA[How Well Do AI Text Detectors Work? (Benchmarks)]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.hcaptcha.com/post/ai-text-detectors-fail-to-spot-llm-output">https://www.hcaptcha.com/post/ai-text-detectors-fail-to-spot-llm-output</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=36230910">https://news.ycombinator.com/item?id=36230910</a></p>
<p>Points: 16</p>
<p># Comments: 2</p>
]]></description><pubDate>Wed, 07 Jun 2023 18:13:02 +0000</pubDate><link>https://www.hcaptcha.com/post/ai-text-detectors-fail-to-spot-llm-output</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=36230910</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36230910</guid></item><item><title><![CDATA[New comment by eatbots in "Ask HN: Did HN just start using Google recaptcha for logins?"]]></title><description><![CDATA[
<p>hCaptcha has completely passive score-only modes. When to challenge and how hard is up to the site.</p>
]]></description><pubDate>Mon, 09 Jan 2023 19:55:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=34315129</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=34315129</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34315129</guid></item><item><title><![CDATA[New comment by eatbots in "Ask HN: Did HN just start using Google recaptcha for logins?"]]></title><description><![CDATA[
<p>This is entirely configurable by the site owner. hCaptcha has entirely passive score-based detection, 99.9% passive mode, and more aggressive options as needed.<p>(disclosure: work there)</p>
]]></description><pubDate>Mon, 09 Jan 2023 18:25:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=34313939</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=34313939</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34313939</guid></item><item><title><![CDATA[New comment by eatbots in "Audible feedback on just how much your browsing feeds into Google"]]></title><description><![CDATA[
<p>No: enterprise customers like that pay hCaptcha. <a href="https://www.hcaptcha.com/enterprise" rel="nofollow">https://www.hcaptcha.com/enterprise</a></p>
]]></description><pubDate>Mon, 22 Aug 2022 20:57:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=32557134</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=32557134</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32557134</guid></item><item><title><![CDATA[New comment by eatbots in "Captcha Has Gone Too Far"]]></title><description><![CDATA[
<p>This is not what empirical measurements show. It is referring to a minimum internal benchmark, rather than what actually happens. (source: work there)<p>If you're getting shadow banned somewhere, it is typically either the site itself or their CDN or bot management providers that is sending you into a challenge loop; hCaptcha doesn't control the behavior in those scenarios.</p>
]]></description><pubDate>Fri, 12 Aug 2022 12:31:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=32437517</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=32437517</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32437517</guid></item><item><title><![CDATA[New comment by eatbots in "Private Access Tokens: Eliminating CAPTCHAs on iPhones and Macs"]]></title><description><![CDATA[
<p>Like any attestation scheme, it doesn't prove anything about the humanity of the button-presser, only that software, hardware, or flesh triggered an action in iOS.<p>hCaptcha's announcement goes into a bit more detail on the tradeoffs: <a href="https://www.hcaptcha.com/post/announcing-support-for-private-access-tokens" rel="nofollow">https://www.hcaptcha.com/post/announcing-support-for-private...</a><p>The main benefit over traditional hardware attestation is that RSA blinding is used to avoid linkability to a single device.</p>
]]></description><pubDate>Thu, 09 Jun 2022 23:59:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=31688453</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=31688453</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31688453</guid></item><item><title><![CDATA[Humanity Verification: The First 3k Years]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.hcaptcha.com/post/humanity-verification-the-first-3-000-years">https://www.hcaptcha.com/post/humanity-verification-the-first-3-000-years</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=31073953">https://news.ycombinator.com/item?id=31073953</a></p>
<p>Points: 8</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 18 Apr 2022 17:39:47 +0000</pubDate><link>https://www.hcaptcha.com/post/humanity-verification-the-first-3-000-years</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=31073953</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31073953</guid></item><item><title><![CDATA[New comment by eatbots in "The end of the road for Cloudflare CAPTCHAs"]]></title><description><![CDATA[
<p>Reducing challenges to real people is everyone's goal, including the goal of everyone working on modern CAPTCHA / bot mitigation platforms..<p>And no one will ever succeed at bringing them to zero.<p>Perennial favorite explainer on the topic: <a href="https://www.hcaptcha.com/post/why-captchas-will-be-with-us-always" rel="nofollow">https://www.hcaptcha.com/post/why-captchas-will-be-with-us-a...</a> Why CAPTCHAs Will Be With Us Always<p>(disclaimer: work on this stuff)</p>
]]></description><pubDate>Fri, 01 Apr 2022 14:21:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=30878332</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=30878332</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30878332</guid></item><item><title><![CDATA[New comment by eatbots in "Cloudflare have made it impossible for me to unsubscribe from marketing emails"]]></title><description><![CDATA[
<p>Vast majority of traffic from Tor IPs is abuse, which makes it challenging to deliver a good experience for the handful of normal users mixed in there.<p>You might be interested in one approach we've been working on for this: <a href="https://www.hcaptcha.com/privacy-pass" rel="nofollow">https://www.hcaptcha.com/privacy-pass</a><p>(full disclosure: work on hCaptcha)</p>
]]></description><pubDate>Tue, 22 Mar 2022 14:23:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=30766434</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=30766434</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30766434</guid></item><item><title><![CDATA[New comment by eatbots in "ReCAPTCHA (A Google Service) Privacy Concerns"]]></title><description><![CDATA[
<p>hCaptcha really doesn't care who you are, and has no incentive to do so. Pretty different economic model than an ad seller like Google.<p>People who build their own generally end up switching to a service like hCaptcha once they start getting attacked. Not a simple problem, as any solution you put in place needs to constantly evolve if you are protecting anything of value.<p>(disclosure: work there)</p>
]]></description><pubDate>Tue, 15 Feb 2022 22:25:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=30353704</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=30353704</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30353704</guid></item><item><title><![CDATA[New comment by eatbots in "ReCAPTCHA (A Google Service) Privacy Concerns"]]></title><description><![CDATA[
<p>hCaptcha is in fact tested this way, and has pretty consistent accuracy across hundreds of countries:<p><a href="https://www.hcaptcha.com/post/do-captchas-really-discriminate-against-non-americans" rel="nofollow">https://www.hcaptcha.com/post/do-captchas-really-discriminat...</a><p>(disclosure: work there)</p>
]]></description><pubDate>Tue, 15 Feb 2022 22:15:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=30353593</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=30353593</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30353593</guid></item><item><title><![CDATA[New comment by eatbots in "Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services"]]></title><description><![CDATA[
<p>Actually, no. hCaptcha has always been very privacy-focused, so in this case there are technical safeguards available: enterprise customers can pre-blind all data on their end, meaning hCaptcha gets no PII at all.<p>(disclosure: work there)</p>
]]></description><pubDate>Tue, 01 Feb 2022 15:52:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=30164111</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=30164111</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30164111</guid></item><item><title><![CDATA[hCaptcha is not affected by log4shell (Analysis)]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.hcaptcha.com/post/hcaptcha-is-not-affected-by-log4shell-heres-how-we-know">https://www.hcaptcha.com/post/hcaptcha-is-not-affected-by-log4shell-heres-how-we-know</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=29544450">https://news.ycombinator.com/item?id=29544450</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 13 Dec 2021 20:48:46 +0000</pubDate><link>https://www.hcaptcha.com/post/hcaptcha-is-not-affected-by-log4shell-heres-how-we-know</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=29544450</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29544450</guid></item><item><title><![CDATA[New comment by eatbots in "ProtonMail includes Google Recaptcha for login"]]></title><description><![CDATA[
<p>As a fan of ProtonMail, will just add a few points:<p>Every popular online service today is being continuously attacked. Bad actors get a lot of economic value from credential stuffing, account takeovers, and fake registrations, especially on email services.<p>This is why CAPTCHAs exist. They are one of the better tools in the defender's arsenal to increase the cost of attacks.<p>Building and maintaining a good CAPTCHA service is both hard and requires a high level of continuous development, since every day people are waking up and trying to figure out how to break it.<p>This means almost every company that tried building their own in the past has switched to either hCaptcha or Google, since it is not practical for even large companies to maintain their own solution these days.<p>Why was ProtonMail originally using Google? Probably because for many years it was the only plausible option until hCaptcha came around, and they needed to protect their users.<p>We're working with them now to switch over to the enterprise version of hCaptcha, which:<p>1) includes privacy-preserving features that let them decide exactly what user data hCaptcha sees and when, and 
2) guarantees what happens to any data received via a data processing agreement, and
3) isn't run by an ad network.<p>hCaptcha doesn't care who you are and ensures all data is ephemeral, since unlike Google we're not trying to sell ads targeting you.<p>(disclosure: work there)</p>
]]></description><pubDate>Sat, 29 May 2021 19:38:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=27327718</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=27327718</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27327718</guid></item><item><title><![CDATA[New comment by eatbots in "ProtonMail includes Google Recaptcha for login"]]></title><description><![CDATA[
<p>This is not actually true: every relevant aspect is different from a privacy perspective, both technical and legal.<p>Looking only at the technical differences, hCaptcha lets enterprise users like Proton locally scrub any info like IPs prior to sending to hCaptcha. It can be set up so that the user makes no direct connection at all to the service, and the code runs inside of a sandboxed IFRAME.<p>As for false positive vs false negative rates, not sure what you consider too high. We've been able to demonstrate FP rates under 0.005% when measured against known-good/bad signals from customers, which is as good as it gets.<p>(disclosure: work there)</p>
]]></description><pubDate>Sat, 29 May 2021 18:19:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=27327126</link><dc:creator>eatbots</dc:creator><comments>https://news.ycombinator.com/item?id=27327126</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27327126</guid></item></channel></rss>