Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It seems like they're using cursor tracking to validate human-ness. Assuming thats the case: Since the cursor is outside of javascript's control, it would force the attacker one level higher (to the browser/os, instead of the dom). Not impossible, but still a significant barrier.


Not really, you would just need to reverse the js code, look at what data they actually send to google and randomly generate appropriate data like mouse movements.


Ah, good point




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: