Is this part of Google's war against ad-blocking and non-Chrome browsers?
Ask HN: Are others seeing Google's reCAPTCHA rejecting Firefox users? (self)
prirun 5 days ago
I refuse to pay a company for service and then be required to identify motorcycles and traffic lights every time I sign in. I went a few rounds with Vultr customer service and they said (paraphrasing) "It's not something we can fix, you have to talk to Google about it". Right... Google forced you to put their captcha on your web site.
pixelesque 21 hours ago
It does it for me if I use a VPN (Mullvad) - if I don't use a VPN then I haven't noticed I get them.
But yeah, very annoying.
basilikum 20 hours ago
account42 20 hours ago
PaoloBarbolini 20 hours ago
We quickly figured out that the server didn't validate the captcha challenge code with Google. It worked for 3 years until they changed the system to send a code via email to validate your login, and limiting you to 1 session at-a-time. Now we have different problems to deal with...
econ 20 hours ago
gruez 19 hours ago
How do you prevent credential stuffing attacks?
>especially if it blocks important functionality like closing your account.
That just falls under standard tort law, not to mention recent "click to cancel" legislation some states have been introducing.
JoshTriplett 18 hours ago
CAPTCHAs don't work anymore, at this point. AI can trivially solve them.
Rate-limit the number of attempts, test accounts against known-password lists like HIBP, and support 2FA.
gruez 18 hours ago
The point is to raise the cost, not to create some impenetrable barrier. A $5 vps can make hundreds of requests per second. IP bans and rate limiting forces people to use residential proxies, which are like $5/GB. That's much more expensive, but still cheap. Not sure about the token cost of AI is like, but captcha solving service used to charge around $0.002 per solve, which increases costs even more.
GoblinSlayer 17 hours ago
gruez 17 hours ago
GoblinSlayer 17 hours ago
olyjohn 14 hours ago
bellowsgulch 17 hours ago
OS, browser, fingerprinting, networked bytes, residential address spaces.
All of it is done.
nisegami 17 hours ago
Passkeys or magic links seem like the way forward here.
hombre_fatal 17 hours ago
account42 2 hours ago
JoshTriplett 12 hours ago
vablings 16 hours ago
olyjohn 14 hours ago
Plont 13 hours ago
If a website/app goes passkey only (or, even worse, if it starts relying only on one-time email codes), I won't use it.
I know plenty of others who feel the same, though I don't know if we're numerous enough to put a dent in a company's bottom line or not. I imagine it depends on the company and its target audience.
iambenm 18 hours ago
hombre_fatal 17 hours ago
toomuchtodo 14 hours ago
Plont 13 hours ago
Email services don't even support true 2FA; many claim to, and ask for a 2FA code for web login, but connecting an email account to a client via POP or IMAP bypasses that.
toomuchtodo 13 hours ago
> Email services don't even support true 2FA; many claim to, and ask for a 2FA code for web login, but connecting an email account to a client via POP or IMAP bypasses that.
"In less than a year, passkeys have been used to authenticate people more than 1 billion times across over 400 million Google Accounts. Passkeys are easy to use and phishing resistant, only relying on a fingerprint, face scan or a pin making them 50% faster than passwords. In fact, on a daily basis passkeys are already used for authentication on Google Accounts more often than legacy forms of 2SV, such as SMS one-time passwords (OTPs) and app based OTPs (such as Authenticator apps) combined."
https://blog.google/innovation-and-ai/technology/safety-secu... (April 2024)
Don't forget: Microsoft is killing passwords. How to set up a Microsoft passkey before August deadline. - https://mashable.com/article/microsoft-passkey-how-to-passwo... - June 20th, 2025
(All major email providers support either passkeys, or in the case of Microsoft, passwordless ["strong authentication"]; we can consider the user creating an app specific secret for an external mail client minimal risk if performed after strong authentication has occurred, as the odds are low of that secret being phished or exfiltrated once configured in their mail client of choice, for the few folks interested in such a user experience with web based email services)
dpifke 12 hours ago
"Neither a sender nor any person acting on behalf of a sender may require that any recipient pay any fee, provide any information other than the recipient's electronic mail address and opt-out preferences, or take any other steps except sending a reply electronic mail message or visiting a single Internet Web page"
https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C...
A simple reading says, no. But I guess they don't want to put that in writing.
downut 19 hours ago
That said I have run into a number of unsolvable captchas lately on firefox. Had to use chromium on a healthcorp insurer site.
GoblinSlayer 17 hours ago
prirun 16 hours ago
I do use Firefox. And I couldn't cancel my account myself: had to request it via email since I couldn't login. They were good about doing it right away and said they issued a refund for the balance.
selcuka 5 days ago
https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...
pessimizer 20 hours ago
gruez 19 hours ago
emsign 16 hours ago
emsign 20 hours ago
VCFundedGenYer 5 days ago
At this point captchas need to be completely removed everywhere. They aren't effective and just waste time.
deltoidmaximus 5 days ago
Aachen 20 hours ago
bityard 18 hours ago
radiorental 20 hours ago
anticrymactic 18 hours ago
If you can reliably use it, you are not at the "deepest" bot detection level.
steelframe 16 hours ago
mac-attack 18 hours ago
xenator 18 hours ago
elric 20 hours ago
kotaKat 5 days ago
It feels like I have to go slowly through it only for it to eventually end in a “please try again” as I sit and wait ten seconds for each square to slowly fade in a new stupid bus for me to click.
How is this fair to the humans?
StilesCrisis 21 hours ago
bluGill 20 hours ago
There is no good automated answer. Things bots do to abuse web pages should be made illegal and then jail (fine...) the people who set the abusive bots loose - but I suspect most abusive bots are foreign and so we can't do anything without sending in an army (obviously unacceptable)
kotaKat 19 hours ago
Cognitive overload. There's days I'm just straight up tired and don't realize it until I'm at least one "please try again", page refresh, and endless traffic light game later that I'm probably in the tarpit and wonder why.
The weird thing is that I don't KNOW why. I use good ol' consumer Chrome, good ol' consumer MacOS, a consumer ISP, and my IP isn't in any kind of reputational blacklists that I'm aware of.
bluGill 19 hours ago
nullc 2 minutes ago
johnnyApplePRNG 19 hours ago
cloudflare bot detection has convinced itself I am a bot however (I do a lot of automated web related stuff on my home IP) and that's been an eye opener for sure... I can't enjoy a good 20% of the internet it seems like now.
Doesn't matter how many times I click that cloudflare button, they don't believe me.
And I've been signed in to my cloudflare account (which I've held in good standing with a live credit card for years) the entire time :/
sourweasel 15 hours ago
One method that does seem to help is being sloppy when clicking the "I am a human" checkbox. I suspected that bots were more likely to perfectly click the center of the checkbox every time and decided to try clicking the padding around the checkbox instead (which still registers as a click). It seems to be more successful, but it could be my imagination.
johnnyApplePRNG 14 hours ago
adrian_b 5 days ago
For me, hCaptcha has stopped working immediately before last weekend, regardless of the site that uses it.
It goes in an infinite loop, despite solving correctly all challenges.
On Linux, I have tested with 2 browsers, Firefox and Vivaldi, and the browser did not make any difference. I do not use any ad blockers, nor any non-standard extension.
So I think that they deployed a version update last Friday, which for some reason is broken on Linux.
It would not be surprising if both hCaptcha and Google ReCAPCHA have made some similar changes, so now they are both broken on Linux.
Meanwhile, some other "Captcha" applications from other vendors, which are used on other sites, still work like before.
oh_no 20 hours ago
randcraw 18 hours ago
fransje26 20 hours ago
I tried searching the interweb for a cause/fix, but couldn't find anything sensible in the flood of low-quality SEO hijacking webcrap returned by multiple search engines. So I asked AI.
The claim is that it could be caused by the blocking of some DNS providers (NextDNS, Quad9, ..), and it suggested using a VPN or phone tethering.
And lo and behold, both suggestions worked, without any browser setting changes.
It's very annoying and inconvenient.
Barbing 2 days ago
This site is exceeding reCAPTCHA Enterprise free quota.
That’s new, but problems/loops aren’t.gnabgib 5 days ago
Barbing 20 hours ago
https://i.ibb.co/Q7qTtK16/Image.jpg
Note I posted the comment only once a day ago. Thread ID seems the same, but old timestamp is visible in my profile. Important issue for information freedom, HN relevant, so it’s back new on the front page?
Edit: good job Social-Protocols, its graph accommodates this unexpected (to me) scenario: https://news.social-protocols.org/stats?id=49555592
PyWoody 19 hours ago
BoxOfRain 18 hours ago
Barbing 7 hours ago
Barbing 7 hours ago
weedfroglozenge 6 hours ago
nosioptar 6 days ago
Sometimes the audio recaptcha works. But, most of the time I can't understand the garbled audio.
Closing the tab always resolves the problem.
KomoD 5 days ago
foresto 5 days ago
selcuka 5 days ago
https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...
cactusplant7374 5 days ago
dcminter 20 hours ago
pessimizer 20 hours ago
Plont 13 hours ago
https://arstechnica.com/tech-policy/2026/02/wikipedia-bans-a...
That whole debacle is even specifically relevant to this thread because the operator of archive.today (aka archive.is) was caught using a script on its captcha page to make visitors' browsers connect to the blog they were mad at. That's how their DDOS attack worked. They used their own visitors, who naturally trusted the captcha page, to commit a crime.
For whatever reason, with the exception of Wikipedia (bless the editors), they seem to have gotten away with this, as well as with deliberately falsifying the content of "archived" pages (as described in the arstechnica article), without consequences.
So, call me crazy or a Russian bot if you want, but I think it's reasonable to be suspicious of any weird captcha behavior from this website in particular.
cactusplant7374 10 hours ago
cactusplant7374 19 hours ago
dcminter 18 hours ago
cactusplant7374 16 hours ago
dcminter 12 hours ago
Presumably you are and do. We differ.
cactusplant7374 10 hours ago
gruez 5 days ago
>archive.today doesn't use a real recaptcha
How? It's loading the script from google, and the images/responses are from google to.
KomoD 5 days ago
gruez 19 hours ago
realslimjd 5 days ago
omoikane 17 hours ago
Separately, if I were seeing a captcha that I can't get past, my first reaction would be to find a different site to see if it's a site specific issue, because some sites intentionally configure their captcha to work like that (e.g. you can't get in until you have been stuck solving captchas for at least a minute). I would see that more as a signal that the site operator is user hostile and not attribute it to a captcha provider.
ectoloph 20 hours ago
The worst trigger is searching Google from the address bar.
Loading the homepage first makes the problem notably less common. Or getting a couple wrong.
globalnode 5 days ago
n4pw01f 19 hours ago
WaasilaAsif 20 hours ago
busymom0 5 days ago
wastedpotencial 19 hours ago
So is this CAPTCHAing because I refuse to navigate the ad-infested way? How can I rule out a problem on my end if my router is ISP provided with limited functionality ?
unbolted3032 11 hours ago
eMpHaSe 10 hours ago
KinetiNode 5 days ago