• ono@lemmy.ca
    link
    fedilink
    English
    arrow-up
    34
    ·
    9 months ago

    Other than making the web tedious to use, my biggest CAPTCHA complaint is that it puts the main providers in a position to monitor everyone’s web use. The blog post doesn’t address that, but it does say this:

    No third-party services

    Perhaps they mean self-hosting? That would be very welcome. It might require open source code to catch on, since many site owners are uncomfortable running mystery code on their servers. That would be very welcome, too.

    Here’s hoping it’s good.

    • activ8r@sh.itjust.works
      link
      fedilink
      arrow-up
      12
      arrow-down
      3
      ·
      9 months ago

      since many site owners are uncomfortable running mystery code on our servers

      And yet Node.js exists and flourishes.

        • ono@lemmy.ca
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          2
          ·
          edit-2
          9 months ago

          The Node package manager is used in some web applications and has a very trusting distribution model, but it’s not particularly relevant to what I wrote (red herring fallacy), and GP’s phrasing alone is enough to identify them as a heckler. Please don’t feed the trolls.

    • Dark Arc@social.packetloss.gg
      link
      fedilink
      English
      arrow-up
      9
      ·
      9 months ago

      That just means they’re using other servers to route traffic. It doesn’t mean those servers are third party services.

  • Zerush@lemmy.ml
    link
    fedilink
    arrow-up
    8
    ·
    9 months ago

    Nice, but captchas are never a good measure to avoid bots, only to annoying users, apart from spying them, if it is from Google. Long before AI, bots could solve captchas better than humans. It is a clearly obsolete method. Apart the system used by Proton is impossible for blind users, Google captcha at least had an auditive captcha too.

    • xuniL@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      7
      ·
      9 months ago

      It does stop bots, but only extremely simple bots that for instance scrape data. That’s mostly it though, more sophisticated bots can easily beat Captchas

      • Zerush@lemmy.ml
        link
        fedilink
        arrow-up
        8
        ·
        9 months ago

        This is the problem. I remember a very simple method to avoid spambots on a forum with great success. It is based on the following idea: A spambot or even a spammer necessarily uses a disposable email to register. These emails are usually not valid for more than 10-30 minutes, just to be able to receive the confirmation link. In this forum, the sending of the confirmation email has been delayed for half an hour due to this and with this the spam problems have ended. A normal user, if they really want to sign up, waits this time without problems. Then the usual 50 messages before being able to put a link as an additional measure. Simple and without third party apps.

  • squid@feddit.uk
    link
    fedilink
    arrow-up
    9
    arrow-down
    1
    ·
    9 months ago

    I often won’t touch websites with captcha as its used to train ai for google so if I see open source captcha solutions of which I doubt I will see as often as id like as googles strong hold

    But proton keep up the good work

  • FREE_TO_SAIL@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    9 months ago

    FUCK ALL CAPTCHA i want to develop a program not to solve captcha but to actually break them then when they go down bypass them some how some way one day i swear i will

  • Sha'ul@lemmy.ca
    link
    fedilink
    arrow-up
    14
    arrow-down
    18
    ·
    9 months ago

    Proton is trying to do too many things and can’t excel at doing one thing. It’s getting too big beyond its capabilities which means services are going to suffer at a lower quality.

    If the want blanket trust from users, remove the VPN login to make it anonymous and change the VPN code to remove all anti-features and comply with native F-Droid, other RiseUpVPN is the only choice for everybody to use.

      • ReversalHatchery@beehaw.org
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        9 months ago

        What’s the problem with riseup? I’ve also read some other comments below, but their confusing wording does not help…

    • 1chemistdown@kbin.social
      link
      fedilink
      arrow-up
      16
      arrow-down
      2
      ·
      9 months ago

      Sure, push a known malware free vpn service while bashing a service that is very well known and respected.

      • speck@kbin.social
        link
        fedilink
        arrow-up
        10
        arrow-down
        1
        ·
        9 months ago

        I have to admit that I don’t know enough about any of this to be sure I’m reading in the right way. Is it “known malware, free VPN” or “known malware-free VPN”?

      • Sha'ul@lemmy.ca
        link
        fedilink
        arrow-up
        7
        arrow-down
        1
        ·
        9 months ago

        You found malware in the source code for RiseUpVPN? The source code is publicly accessible, what kind of malware is in it?

      • QuazarOmega@lemy.lol
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        9 months ago

        It’s one of the most transparent services, there’s this neat video examining the available free VPNs by Techlore that was coincidentally made very recently: peertube/piped

      • Sha'ul@lemmy.ca
        link
        fedilink
        arrow-up
        4
        arrow-down
        1
        ·
        9 months ago

        Accoding to F-Droid build service, it says ProtonVPN depends entirely on non-free network services, which means:

        “This Anti-Feature is applied to apps that promote or depend entirely on a Non-Free network service which is impossible, or not easy to replace. Replacement requires changes to the app or service. This antifeature would not apply, if there is a simple configuration option that allows pointing the app to a running instance of an alternative, publicly available, self-hostable, free software server solution.”

        Compared to RiseUpVPN source code which has zero anti-features