Ask HN: Are others seeing Google's reCAPTCHA rejecting Firefox users?
Infinite Google ReCAPCHA loop trying to access archive.is using current Firefox from Linux. Just started today. Firefox is in "strict" mode. Disabled Privacy Badger for that site, and it didn't help. Tried private browsing, and it didn't help.
Is this part of Google's war against ad-blocking and non-Chrome browsers?
I've used vultr.com for years with no problems. Recently it wouldn't let me login without solving a Google captcha. I tried private windows, etc and ended up having to cancel my Vultr account and ask for a refund. Fortunately I only used them to spin up test VMs and didn't have any production stuff running there.
I refuse to pay a company for service and then be required to identify motorcycles and traffic lights every time I sign in. I went a few rounds with Vultr customer service and they said (paraphrasing) "It's not something we can fix, you have to talk to Google about it". Right... Google forced you to put their captcha on your web site.
>CAPTCHAs don't work anymore, at this point. AI can trivially solve them.
The point is to raise the cost, not to create some impenetrable barrier. A $5 vps can make hundreds of requests per second. IP bans and rate limiting forces people to use residential proxies, which are like $5/GB. That's much more expensive, but still cheap. Not sure about the token cost of AI is like, but captcha solving service used to charge around $0.002 per solve, which increases costs even more.
You can also randomly generate a password for the user on the form they'd normally type one in on registration. Add a "Regen" button to give users more visceral control over it before they submit the form.
Attacks have been distributed for quite some time if your service has any loot worth attacking. You have to handle the case where every request comes from a unique IP address.
A few years ago a service for which we had just implemented a scraper for (they had no API, and the customer needed info from 1000s of accounts) added a captcha right after we had implemented the scraper.
We quickly figured out that the server didn't validate the captcha challenge code with Google. It worked for 3 years until they changed the system to send a code via email to validate your login, and limiting you to 1 session at-a-time. Now we have different problems to deal with...
Ok, debian forky, 155.0.1, successfully logged into vultr.com after a year inactive, added a credit card and a little credit. I do, however, still stupidly use google authenticator for 2FA. The captcha was just a checkbox.
That said I have run into a number of unsolvable captchas lately on firefox. Had to use chromium on a healthcorp insurer site.
Captchas are often used as tarpits. They've already decided you're a bot based on other factors so you aren't getting in until you change those factors. I've seen this happen where I'm stuck in the loop and then change the VPN endpoint and get right in after one try.
I'm sure there exist examples where people maliciously give tasks (captchas) out that have no chance of getting the person anywhere, but it's definitely not common
Consider yourself lucky. I routinely run into tarpit Google reCAPTCHAs and I don't even use a VPN. I think it's because I run Linux and the site admins treat anything besides Windows, Mac, iOS, or Android Chrome as suspicious enough to blacklist. It has gotten to a point that I literally never even _try_ to do image-based CAPTCHAs anymore. If I can't access the site, oh well.
We were getting about few hundred spam registrations per day on one of our sites. With CF's captcha number drops to tens per day. I have no idea who and why make these registrations.
Constantly. It's made me stop using Google entirely because I can't run a single search without hitting reCAPTCHA. It's becoming problematic because some services I pay for, such as Bandcamp, also end up pestering me with boatloads of reCAPTCHAs. I enjoy Bandcamp, but I'm going to have to axe it if it keeps up.
reCAPTCHA actually works for me. The one that asks if it's a sidewalk or a motorcycle or whatever right?
cloudflare bot detection has convinced itself I am a bot however (I do a lot of automated web related stuff on my home IP) and that's been an eye opener for sure... I can't enjoy a good 20% of the internet it seems like now.
Doesn't matter how many times I click that cloudflare button, they don't believe me.
And I've been signed in to my cloudflare account (which I've held in good standing with a live credit card for years) the entire time :/
It doesn't work in Chrome either (please complete CAPTCHA/yes you're valid/repeat), it might be a config issue on archive.is (Firefox latest windows, Chrome 151 windows - guest/null profile on both) rather than a war move.
Dunno, but is anyone else continuing to seem to get what feels like 3-4 minute reCaptcha challenges? I’m getting mentally exhausted having to try to solve the super blurry pick-the-streetlights they keep throwing at me in loops.
It feels like I have to go slowly through it only for it to eventually end in a “please try again” as I sit and wait ten seconds for each square to slowly fade in a new stupid bus for me to click.
This is a tarpit. They've decided you're almost certainly a bot. If you're willing to solve the captchas for three minutes straight, they eventually might relent and let you in, or maybe not.
I doubt any human would solve them for 3 minutes straight, but a bot might. So closing and reloading the page (something a human would do) might work. Of course bots that don't do this will quickly figure out that they should - just like every other attempt to figure out if this is a bot or not...
There is no good automated answer. Things bots do to abuse web pages should be made illegal and then jail (fine...) the people who set the abusive bots loose - but I suspect most abusive bots are foreign and so we can't do anything without sending in an army (obviously unacceptable)
> I doubt any human would solve them for 3 minutes straight
Cognitive overload. There's days I'm just straight up tired and don't realize it until I'm at least one "please try again", page refresh, and endless traffic light game later that I'm probably in the tarpit and wonder why.
The weird thing is that I don't KNOW why. I use good ol' consumer Chrome, good ol' consumer MacOS, a consumer ISP, and my IP isn't in any kind of reputational blacklists that I'm aware of.
Note I posted the comment only once a day ago. Thread ID seems the same, but old timestamp is visible in my profile. Important issue for information freedom, HN relevant, so it’s back new on the front page?
I also have the same issue in Firefox, Chromium and Vivaldi on Linux.
I tried searching the interweb for a cause/fix, but couldn't find anything sensible in the flood of low-quality SEO hijacking webcrap returned by multiple search engines. So I asked AI.
The claim is that it could be caused by the blocking of some DNS providers (NextDNS, Quad9, ..), and it suggested using a VPN or phone tethering.
And lo and behold, both suggestions worked, without any browser setting changes.
Archive.today / Archive.is / Archive.ph issues the past few days. Safari Private w/iCloud Private Relay. See the enterprise free tier exceeded messaging:
This site is exceeding reCAPTCHA Enterprise free quota.
I do not think that this is Firefox specific, more likely is is something Linux specific.
For me, hCaptcha has stopped working immediately before last weekend, regardless of the site that uses it.
It goes in an infinite loop, despite solving correctly all challenges.
On Linux, I have tested with 2 browsers, Firefox and Vivaldi, and the browser did not make any difference. I do not use any ad blockers, nor any non-standard extension.
So I think that they deployed a version update last Friday, which for some reason is broken on Linux.
It would not be surprising if both hCaptcha and Google ReCAPCHA have made some similar changes, so now they are both broken on Linux.
Meanwhile, some other "Captcha" applications from other vendors, which are used on other sites, still work like before.
I get reCaptchaed-to-death all the time in iOS and MacOS using both Firefox and Brave. I use a big name VPN which probably makes it worse, since I'm routinely blocked outright by Cloudfare services, assuming cluelessly that I'm a bot.
Since last month I've been CAPTCHAed in many Google searchs in Firefox. I assumed either a local device was spamming them or maybe Codex/Claude web search was flagging me as a bot.
So is this CAPTCHAing because I refuse to navigate the ad-infested way? How can I rule out a problem on my end if my router is ISP provided with limited functionality ?
Yes. And even after solving the recaptcha it just wont accept and after multiple attemots even if it accepts it just goes on to display it all over again
archive.today doesn't use a real recaptcha, the cloudflare page isn't real either. it serves that as a punishment for using 1.1.1.1 DNS because the owner doesn't like that 1.1.1.1 doesn't send EDNS client subnets.
I recall that the 1.1.1.1 block page doesn't serve the real one,, but the challenge page that they serve normally does. Maybe I'm misremembering? or maybe they changed it.
I just tested and it's the "real" recaptcha, with requests to google and everything. It still might be "fake" in the sense that the server rejects any response, even valid ones, which is probably what's actually happening.
What do you mean by "a real recaptcha"? I just went to an archive.is page, and it's trying to load a script from www.google.com. Doesn't Google still own reCAPTCHA?
> On 14 January 2026, it emerged that archive.today had silently modified its CAPTCHA page to send repeated requests to Gyrovague, thereby causing visitors to unwittingly contribute to a DDOS attack against the blog.
It tells us that the moderators of HN support copyright infringement and DDOS attacks. They are actively moderating this forum and choosing to do nothing.
They also choose to do nothing about uncharitable interpretations of their inactions. Should they act there too? Or do you prefer the hands-off approach when it suits you?
Better to just ignore the anti-Russian and hasbara spam. It's being posted opportunistically. The chance to attack archive.is in an organically posted thread is probably the only reason an intermittent outage (common) of archive.is was upvoted enough to make it to the front page. Look at the top comment.
because of my privacy settings google search outright blocks me as a bot. the only way to search is through an intermediary like startpage. related because if it does give me the time of day i tend to then get endless captchas.
Not sure about Firefox but lately, if I access Google from Safari on my Mac with Apple's private relay on and private mode Safari, I get an endless captcha loop.
One interesting thing I found recently was after enforcing geo-fencing, recaptcha intermittently started failing. They might be using global edge servers or something
I have been seeing this, but it depends on my originating IP. I switched my house from Spectrum to T-mobile and then started getting ReCAPTCHAs on Firefox. Going out through another Spectrum connection on the same machine doesn't trigger the ReCAPTCHAs. It happens far, far less with chrome but it does still happen.
Strict mode has always been broken for me. Firefox replaces some of Google's tracking scripts with no-ops but that usually breaks Google's reCAPTCHA on my end. I have to disable tracking protection to make reCAPTCHA sites work.
I think it's fair for Google not to fix Firefox's shims, so I don't know who to blame for this. I doubt it's part of some big conspiracy against Firefox, though. I don't think Google cares enough about Firefox to bother annoying Firefox users.
Archive.is has had downtime this weekend when I tried to use it. They also regularly pull shady stuff, so I wouldn't be surprised if they did something stupid again and got themselves banned from reCAPTCHA.
> Advertisers on Google should be paying a lot less than they were a year ago.
I wonder how the Google Search page traffic has been affected by the recent AI surge.
Very anecdotally, of course, but in my social circle (middle-class urban Romanians in their late 30s and early 40s) almost everyone I know has replaced a phrase like "I googled it and I found this and this and this" to "I chatGPT-ed and I found this and this and this" (where "chatGPT" can also be sometimes replaced by Claude and, not that often, by Gemini).
The open secret: the CAPTCHA wasn’t actually being checked against Google’s servers; any answer was accepted as correct – until yesterday, when someone armed with this knowledge launched an AI crawler. Now it’s being checked, so you’ll have to solve it.
I'm not sure why this is downvoted. It approximately checks out. An "assessment" only counts if your server tries to verify it, so you could conceivably use recaptcha for "free" if you don't bother validating the results. It also explains why other people have started seeing "This site is exceeding reCAPTCHA Enterprise free quota" message.
Can we just get rid of reCaptcha? It was fun when it was new, but now it's just pointless busywork to let Google know who we are. Does it do anything other than that? I don't for a minute believe bots can't solve that anymore.
It still works, bots can solve it but it probably increases the cost of that web call by 10x or 100x for that bot, so it won't bother. Had a recent bad experience with removing recaptcha.
Interesting, saw reCAPTCHA infinite loop for the first time in a long time just yesterday, on Firefox, and it was when I tried to access an article on PMC. Disabling uBlock and Enhanced Tracking Protection did not help. It looked like several automatic reloads, then one real reCAPTCHA showed, and infinite reload loop after I solved it.
Does not reproduce today though, and I never had issues with PMC/NIH before that.
If you're seeing an infinite CAPTCHA loop on archive.is, it's more likely that you're on the operator's shitlist than any technical issue. All Finnish IP addresses are on that shitlist already.
Yup. Before they just blackholed Finnish IP ranges instead, accessing the site from one would serve a fake Cloudflare page with a reCAPTCHA challenge and the DDoS script. (The tell of it being fake is y'know, that Cloudflare doesn't use reCAPTCHA)
I can only guess the goal was to keep users on that page longer to keep sending off more spam requests.
I don't think it has anything to do with google, it's an intermittent issue on the archive sites that usually clears out within an hour or two. You're being successful, then being bounced back out again.
Also firefox from linux. Just leave the pages open and refresh them every 20 minutes or so.
I refuse to pay a company for service and then be required to identify motorcycles and traffic lights every time I sign in. I went a few rounds with Vultr customer service and they said (paraphrasing) "It's not something we can fix, you have to talk to Google about it". Right... Google forced you to put their captcha on your web site.
How do you prevent credential stuffing attacks?
>especially if it blocks important functionality like closing your account.
That just falls under standard tort law, not to mention recent "click to cancel" legislation some states have been introducing.
CAPTCHAs don't work anymore, at this point. AI can trivially solve them.
Rate-limit the number of attempts, test accounts against known-password lists like HIBP, and support 2FA.
The point is to raise the cost, not to create some impenetrable barrier. A $5 vps can make hundreds of requests per second. IP bans and rate limiting forces people to use residential proxies, which are like $5/GB. That's much more expensive, but still cheap. Not sure about the token cost of AI is like, but captcha solving service used to charge around $0.002 per solve, which increases costs even more.
Passkeys or magic links seem like the way forward here.
We quickly figured out that the server didn't validate the captcha challenge code with Google. It worked for 3 years until they changed the system to send a code via email to validate your login, and limiting you to 1 session at-a-time. Now we have different problems to deal with...
It does it for me if I use a VPN (Mullvad) - if I don't use a VPN then I haven't noticed I get them.
But yeah, very annoying.
That said I have run into a number of unsolvable captchas lately on firefox. Had to use chromium on a healthcorp insurer site.
https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...
At this point captchas need to be completely removed everywhere. They aren't effective and just waste time.
If you can reliably use it, you are not at the "deepest" bot detection level.
cloudflare bot detection has convinced itself I am a bot however (I do a lot of automated web related stuff on my home IP) and that's been an eye opener for sure... I can't enjoy a good 20% of the internet it seems like now.
Doesn't matter how many times I click that cloudflare button, they don't believe me.
And I've been signed in to my cloudflare account (which I've held in good standing with a live credit card for years) the entire time :/
It feels like I have to go slowly through it only for it to eventually end in a “please try again” as I sit and wait ten seconds for each square to slowly fade in a new stupid bus for me to click.
How is this fair to the humans?
There is no good automated answer. Things bots do to abuse web pages should be made illegal and then jail (fine...) the people who set the abusive bots loose - but I suspect most abusive bots are foreign and so we can't do anything without sending in an army (obviously unacceptable)
Cognitive overload. There's days I'm just straight up tired and don't realize it until I'm at least one "please try again", page refresh, and endless traffic light game later that I'm probably in the tarpit and wonder why.
The weird thing is that I don't KNOW why. I use good ol' consumer Chrome, good ol' consumer MacOS, a consumer ISP, and my IP isn't in any kind of reputational blacklists that I'm aware of.
https://i.ibb.co/Q7qTtK16/Image.jpg
Note I posted the comment only once a day ago. Thread ID seems the same, but old timestamp is visible in my profile. Important issue for information freedom, HN relevant, so it’s back new on the front page?
Edit: good job Social-Protocols, its graph accommodates this unexpected (to me) scenario: https://news.social-protocols.org/stats?id=49555592
[0] https://news.ycombinator.com/item?id=26998308
I tried searching the interweb for a cause/fix, but couldn't find anything sensible in the flood of low-quality SEO hijacking webcrap returned by multiple search engines. So I asked AI.
The claim is that it could be caused by the blocking of some DNS providers (NextDNS, Quad9, ..), and it suggested using a VPN or phone tethering.
And lo and behold, both suggestions worked, without any browser setting changes.
It's very annoying and inconvenient.
For me, hCaptcha has stopped working immediately before last weekend, regardless of the site that uses it.
It goes in an infinite loop, despite solving correctly all challenges.
On Linux, I have tested with 2 browsers, Firefox and Vivaldi, and the browser did not make any difference. I do not use any ad blockers, nor any non-standard extension.
So I think that they deployed a version update last Friday, which for some reason is broken on Linux.
It would not be surprising if both hCaptcha and Google ReCAPCHA have made some similar changes, so now they are both broken on Linux.
Meanwhile, some other "Captcha" applications from other vendors, which are used on other sites, still work like before.
So is this CAPTCHAing because I refuse to navigate the ad-infested way? How can I rule out a problem on my end if my router is ISP provided with limited functionality ?
Sometimes the audio recaptcha works. But, most of the time I can't understand the garbled audio.
Closing the tab always resolves the problem.
>archive.today doesn't use a real recaptcha
How? It's loading the script from google, and the images/responses are from google to.
https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...
either change the user-agent to the newest version for WINDOWS
and/or use cloudflare warp which is technically a free non-privatizing VPN
on linux you can use warp via wireguard + WGCF
* reddit.com/r/CloudFlare/comments/ty9hke
The worst trigger is searching Google from the address bar.
Loading the homepage first makes the problem notably less common. Or getting a couple wrong.
Ich bin kein Roboter. Diese Website überschreitet das kostenlose reCAPTCHA Enterprise-Kontingent.
I am not a robot. This website has exceeded the free reCAPTCHA Enterprise quota.
I think it's fair for Google not to fix Firefox's shims, so I don't know who to blame for this. I doubt it's part of some big conspiracy against Firefox, though. I don't think Google cares enough about Firefox to bother annoying Firefox users.
Archive.is has had downtime this weekend when I tried to use it. They also regularly pull shady stuff, so I wouldn't be surprised if they did something stupid again and got themselves banned from reCAPTCHA.
but .... my user agent is way more finger printable then it should (e.g. has the Linux x86_64 part) so that might make the difference.
Advertisers on Google should be paying a lot less than they were a year ago.
I wonder how the Google Search page traffic has been affected by the recent AI surge.
Very anecdotally, of course, but in my social circle (middle-class urban Romanians in their late 30s and early 40s) almost everyone I know has replaced a phrase like "I googled it and I found this and this and this" to "I chatGPT-ed and I found this and this and this" (where "chatGPT" can also be sometimes replaced by Claude and, not that often, by Gemini).
NIH support staff is even worse as they refuse to acknowledge the issue and reply with a scripted useless response.
If I remember correctly, Recaptcha doesn't work on GrapheneOS either which is a separate issue.
Does not reproduce today though, and I never had issues with PMC/NIH before that.
“Um, I know this may be a very personal question, but is it possible that you…could we say…may be…a Robot?”
I can only guess the goal was to keep users on that page longer to keep sending off more spam requests.
Also firefox from linux. Just leave the pages open and refresh them every 20 minutes or so.