Infinite Google ReCAPCHA loop trying to access archive.is using current Firefox from Linux. Just started today. Firefox is in "strict" mode. Disabled Privacy Badger for that site, and it didn't help. Tried private browsing, and it didn't help.
Is this part of Google's war against ad-blocking and non-Chrome browsers?
archive.today doesn't use a real recaptcha, the cloudflare page isn't real either. it serves that as a punishment for using 1.1.1.1 DNS because the owner doesn't like that 1.1.1.1 doesn't send EDNS client subnets.
What do you mean by "a real recaptcha"? I just went to an archive.is page, and it's trying to load a script from www.google.com. Doesn't Google still own reCAPTCHA?
> On 14 January 2026, it emerged that archive.today had silently modified its CAPTCHA page to send repeated requests to Gyrovague, thereby causing visitors to unwittingly contribute to a DDOS attack against the blog.
Better to just ignore the anti-Russian and hasbara spam. It's being posted opportunistically. The chance to attack archive.is in an organically posted thread is probably the only reason an intermittent outage (common) of archive.is was upvoted enough to make it to the front page. Look at the top comment.
That whole debacle is even specifically relevant to this thread because the operator of archive.today (aka archive.is) was caught using a script on its captcha page to make visitors' browsers connect to the blog they were mad at. That's how their DDOS attack worked. They used their own visitors, who naturally trusted the captcha page, to commit a crime.
For whatever reason, with the exception of Wikipedia (bless the editors), they seem to have gotten away with this, as well as with deliberately falsifying the content of "archived" pages (as described in the arstechnica article), without consequences.
So, call me crazy or a Russian bot if you want, but I think it's reasonable to be suspicious of any weird captcha behavior from this website in particular.
It tells us that the moderators of HN support copyright infringement and DDOS attacks. They are actively moderating this forum and choosing to do nothing.
They also choose to do nothing about uncharitable interpretations of their inactions. Should they act there too? Or do you prefer the hands-off approach when it suits you?
I don't think it's very interesting even if true. I'm not that fussed about copyright infringement myself and I don't consider using archive.is (infrequently) to be condoning their DDOS.
I recall that the 1.1.1.1 block page doesn't serve the real one,, but the challenge page that they serve normally does. Maybe I'm misremembering? or maybe they changed it.
I just tested and it's the "real" recaptcha, with requests to google and everything. It still might be "fake" in the sense that the server rejects any response, even valid ones, which is probably what's actually happening.
It doesn't work in Chrome either (please complete CAPTCHA/yes you're valid/repeat), it might be a config issue on archive.is (Firefox latest windows, Chrome 151 windows - guest/null profile on both) rather than a war move.
They have nothing to do with Cloudflare. Their challenge page is only made to look like the one from Cloudflare. It's entirely their own page. Only the reCaptcha challenge is not theirs. And the reason why nobody gets redirected is because the have used up their free enterprise quota with reCaptcha, as you can read in the widget itself.
Not sure about Firefox but lately, if I access Google from Safari on my Mac with Apple's private relay on and private mode Safari, I get an endless captcha loop.
because of my privacy settings google search outright blocks me as a bot. the only way to search is through an intermediary like startpage. related because if it does give me the time of day i tend to then get endless captchas.
Dunno, but is anyone else continuing to seem to get what feels like 3-4 minute reCaptcha challenges? I’m getting mentally exhausted having to try to solve the super blurry pick-the-streetlights they keep throwing at me in loops.
It feels like I have to go slowly through it only for it to eventually end in a “please try again” as I sit and wait ten seconds for each square to slowly fade in a new stupid bus for me to click.
This is a tarpit. They've decided you're almost certainly a bot. If you're willing to solve the captchas for three minutes straight, they eventually might relent and let you in, or maybe not.
I doubt any human would solve them for 3 minutes straight, but a bot might. So closing and reloading the page (something a human would do) might work. Of course bots that don't do this will quickly figure out that they should - just like every other attempt to figure out if this is a bot or not...
There is no good automated answer. Things bots do to abuse web pages should be made illegal and then jail (fine...) the people who set the abusive bots loose - but I suspect most abusive bots are foreign and so we can't do anything without sending in an army (obviously unacceptable)
> I doubt any human would solve them for 3 minutes straight
Cognitive overload. There's days I'm just straight up tired and don't realize it until I'm at least one "please try again", page refresh, and endless traffic light game later that I'm probably in the tarpit and wonder why.
The weird thing is that I don't KNOW why. I use good ol' consumer Chrome, good ol' consumer MacOS, a consumer ISP, and my IP isn't in any kind of reputational blacklists that I'm aware of.
Captchas are often used as tarpits. They've already decided you're a bot based on other factors so you aren't getting in until you change those factors. I've seen this happen where I'm stuck in the loop and then change the VPN endpoint and get right in after one try.
I'm sure there exist examples where people maliciously give tasks (captchas) out that have no chance of getting the person anywhere, but it's definitely not common
Consider yourself lucky. I routinely run into tarpit Google reCAPTCHAs and I don't even use a VPN. I think it's because I run Linux and the site admins treat anything besides Windows, Mac, iOS, or Android Chrome as suspicious enough to blacklist. It has gotten to a point that I literally never even _try_ to do image-based CAPTCHAs anymore. If I can't access the site, oh well.
I also get infinite captchas but it's imo not a tarpit if it's not intentional but a bug
Edit: looked up the term, DDG shows a Wikipedia card saying "A tarpit is a service on a computer system that purposely delays incoming connections." (purposeful)
It may seem purposeful on Google's part but I bet that if we could get through to the developers for answers, it's probably not designed that way but we're running into a case where the system isn't designed to handle it
Which could be said to be intentional (excluding people with our FOSS setup), I guess
We were getting about few hundred spam registrations per day on one of our sites. With CF's captcha number drops to tens per day. I have no idea who and why make these registrations.
I've used vultr.com for years with no problems. Recently it wouldn't let me login without solving a Google captcha. I tried private windows, etc and ended up having to cancel my Vultr account and ask for a refund. Fortunately I only used them to spin up test VMs and didn't have any production stuff running there.
I refuse to pay a company for service and then be required to identify motorcycles and traffic lights every time I sign in. I went a few rounds with Vultr customer service and they said (paraphrasing) "It's not something we can fix, you have to talk to Google about it". Right... Google forced you to put their captcha on your web site.
>CAPTCHAs don't work anymore, at this point. AI can trivially solve them.
The point is to raise the cost, not to create some impenetrable barrier. A $5 vps can make hundreds of requests per second. IP bans and rate limiting forces people to use residential proxies, which are like $5/GB. That's much more expensive, but still cheap. Not sure about the token cost of AI is like, but captcha solving service used to charge around $0.002 per solve, which increases costs even more.
No, it's a numbers game on both sides. Attackers are after hundreds or thousands of accounts, not just one. Defenders knows that exactly 0 hacks are impossible to achieve, and they're just trying to limit losses from fraud, but also costs from anti-fraud.
You can also randomly generate a password for the user on the form they'd normally type one in on registration. Add a "Regen" button to give users more visceral control over it before they submit the form.
That's essentially the same as magic links because most users won't remember/save that password and will have to rely on the usually email-based reset flow.
Please don't. I find such services obnoxious, especially when they aggressively log you back out. Chasing down a link in your email is much slower than having your password manager fill in the long unique random password and hitting "log in".
I'm not giving up recovery codes, nor my ability to default to locking out people who physically have my device. I usually don't allow auto-login or biometrics login either.
If a website/app goes passkey only (or, even worse, if it starts relying only on one-time email codes), I won't use it.
I know plenty of others who feel the same, though I don't know if we're numerous enough to put a dent in a company's bottom line or not. I imagine it depends on the company and its target audience.
Attacks have been distributed for quite some time if your service has any loot worth attacking. You have to handle the case where every request comes from a unique IP address.
Email OTP is garbage without the option to also add a password. That just outsources the problem to the user's email service, and assures that compromising the email inbox alone is enough to immediately also compromise every service that uses passwordless, 2FA-less "magic link" or OTP login.
Email services don't even support true 2FA; many claim to, and ask for a 2FA code for web login, but connecting an email account to a client via POP or IMAP bypasses that.
I never got a response when I wrote to the FTC, requesting formal guidance as to whether having to disable NoScript (a browser security measure) to complete a CAPTCHA to unsubscribe from email spam satisfies 16 CFR § 316:
"Neither a sender nor any person acting on behalf of a sender may require that any recipient pay any fee, provide any information other than the recipient's electronic mail address and opt-out preferences, or take any other steps except sending a reply electronic mail message or visiting a single Internet Web page"
Ok, debian forky, 155.0.1, successfully logged into vultr.com after a year inactive, added a credit card and a little credit. I do, however, still stupidly use google authenticator for 2FA. The captcha was just a checkbox.
That said I have run into a number of unsolvable captchas lately on firefox. Had to use chromium on a healthcorp insurer site.
I don't mind a checkbox. I don't even mind the "proof of work" types that take 10 seconds extra. But identifying traffic-y things over and over is way too much for me. I did do one screen, thinking it would let me in, but it just gave me another.
I do use Firefox. And I couldn't cancel my account myself: had to request it via email since I couldn't login. They were good about doing it right away and said they issued a refund for the balance.
The open secret: the CAPTCHA wasn’t actually being checked against Google’s servers; any answer was accepted as correct – until yesterday, when someone armed with this knowledge launched an AI crawler. Now it’s being checked, so you’ll have to solve it.
I'm not sure why this is downvoted. It approximately checks out. An "assessment" only counts if your server tries to verify it, so you could conceivably use recaptcha for "free" if you don't bother validating the results. It also explains why other people have started seeing "This site is exceeding reCAPTCHA Enterprise free quota" message.
I do not think that this is Firefox specific, more likely is is something Linux specific.
For me, hCaptcha has stopped working immediately before last weekend, regardless of the site that uses it.
It goes in an infinite loop, despite solving correctly all challenges.
On Linux, I have tested with 2 browsers, Firefox and Vivaldi, and the browser did not make any difference. I do not use any ad blockers, nor any non-standard extension.
So I think that they deployed a version update last Friday, which for some reason is broken on Linux.
It would not be surprising if both hCaptcha and Google ReCAPCHA have made some similar changes, so now they are both broken on Linux.
Meanwhile, some other "Captcha" applications from other vendors, which are used on other sites, still work like before.
I get reCaptchaed-to-death all the time in iOS and MacOS using both Firefox and Brave. I use a big name VPN which probably makes it worse, since I'm routinely blocked outright by Cloudfare services, assuming cluelessly that I'm a bot.
Interesting, saw reCAPTCHA infinite loop for the first time in a long time just yesterday, on Firefox, and it was when I tried to access an article on PMC. Disabling uBlock and Enhanced Tracking Protection did not help. It looked like several automatic reloads, then one real reCAPTCHA showed, and infinite reload loop after I solved it.
Does not reproduce today though, and I never had issues with PMC/NIH before that.
Archive.today / Archive.is / Archive.ph issues the past few days. Safari Private w/iCloud Private Relay. See the enterprise free tier exceeded messaging:
This site is exceeding reCAPTCHA Enterprise free quota.
Can we just get rid of reCaptcha? It was fun when it was new, but now it's just pointless busywork to let Google know who we are. Does it do anything other than that? I don't for a minute believe bots can't solve that anymore.
It still works, bots can solve it but it probably increases the cost of that web call by 10x or 100x for that bot, so it won't bother. Had a recent bad experience with removing recaptcha.
I don't think it has anything to do with google, it's an intermittent issue on the archive sites that usually clears out within an hour or two. You're being successful, then being bounced back out again.
Also firefox from linux. Just leave the pages open and refresh them every 20 minutes or so.
I have been seeing this, but it depends on my originating IP. I switched my house from Spectrum to T-mobile and then started getting ReCAPTCHAs on Firefox. Going out through another Spectrum connection on the same machine doesn't trigger the ReCAPTCHAs. It happens far, far less with chrome but it does still happen.
133 comments
[ 0.22 ms ] story [ 19.5 ms ] threadIs this part of Google's war against ad-blocking and non-Chrome browsers?
https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...
https://arstechnica.com/tech-policy/2026/02/wikipedia-bans-a...
That whole debacle is even specifically relevant to this thread because the operator of archive.today (aka archive.is) was caught using a script on its captcha page to make visitors' browsers connect to the blog they were mad at. That's how their DDOS attack worked. They used their own visitors, who naturally trusted the captcha page, to commit a crime.
For whatever reason, with the exception of Wikipedia (bless the editors), they seem to have gotten away with this, as well as with deliberately falsifying the content of "archived" pages (as described in the arstechnica article), without consequences.
So, call me crazy or a Russian bot if you want, but I think it's reasonable to be suspicious of any weird captcha behavior from this website in particular.
Presumably you are and do. We differ.
>archive.today doesn't use a real recaptcha
How? It's loading the script from google, and the images/responses are from google to.
Sometimes the audio recaptcha works. But, most of the time I can't understand the garbled audio.
Closing the tab always resolves the problem.
Advertisers on Google should be paying a lot less than they were a year ago.
https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...
It feels like I have to go slowly through it only for it to eventually end in a “please try again” as I sit and wait ten seconds for each square to slowly fade in a new stupid bus for me to click.
How is this fair to the humans?
There is no good automated answer. Things bots do to abuse web pages should be made illegal and then jail (fine...) the people who set the abusive bots loose - but I suspect most abusive bots are foreign and so we can't do anything without sending in an army (obviously unacceptable)
Cognitive overload. There's days I'm just straight up tired and don't realize it until I'm at least one "please try again", page refresh, and endless traffic light game later that I'm probably in the tarpit and wonder why.
The weird thing is that I don't KNOW why. I use good ol' consumer Chrome, good ol' consumer MacOS, a consumer ISP, and my IP isn't in any kind of reputational blacklists that I'm aware of.
At this point captchas need to be completely removed everywhere. They aren't effective and just waste time.
Edit: looked up the term, DDG shows a Wikipedia card saying "A tarpit is a service on a computer system that purposely delays incoming connections." (purposeful)
It may seem purposeful on Google's part but I bet that if we could get through to the developers for answers, it's probably not designed that way but we're running into a case where the system isn't designed to handle it
Which could be said to be intentional (excluding people with our FOSS setup), I guess
If you can reliably use it, you are not at the "deepest" bot detection level.
I refuse to pay a company for service and then be required to identify motorcycles and traffic lights every time I sign in. I went a few rounds with Vultr customer service and they said (paraphrasing) "It's not something we can fix, you have to talk to Google about it". Right... Google forced you to put their captcha on your web site.
It does it for me if I use a VPN (Mullvad) - if I don't use a VPN then I haven't noticed I get them.
But yeah, very annoying.
How do you prevent credential stuffing attacks?
>especially if it blocks important functionality like closing your account.
That just falls under standard tort law, not to mention recent "click to cancel" legislation some states have been introducing.
CAPTCHAs don't work anymore, at this point. AI can trivially solve them.
Rate-limit the number of attempts, test accounts against known-password lists like HIBP, and support 2FA.
The point is to raise the cost, not to create some impenetrable barrier. A $5 vps can make hundreds of requests per second. IP bans and rate limiting forces people to use residential proxies, which are like $5/GB. That's much more expensive, but still cheap. Not sure about the token cost of AI is like, but captcha solving service used to charge around $0.002 per solve, which increases costs even more.
Passkeys or magic links seem like the way forward here.
The point is to stop the attack and prevent users from accidentally hosing themselves.
That's basically a passkey without its special API.
If a website/app goes passkey only (or, even worse, if it starts relying only on one-time email codes), I won't use it.
I know plenty of others who feel the same, though I don't know if we're numerous enough to put a dent in a company's bottom line or not. I imagine it depends on the company and its target audience.
Email services don't even support true 2FA; many claim to, and ask for a 2FA code for web login, but connecting an email account to a client via POP or IMAP bypasses that.
"Neither a sender nor any person acting on behalf of a sender may require that any recipient pay any fee, provide any information other than the recipient's electronic mail address and opt-out preferences, or take any other steps except sending a reply electronic mail message or visiting a single Internet Web page"
https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C...
A simple reading says, no. But I guess they don't want to put that in writing.
That said I have run into a number of unsolvable captchas lately on firefox. Had to use chromium on a healthcorp insurer site.
I do use Firefox. And I couldn't cancel my account myself: had to request it via email since I couldn't login. They were good about doing it right away and said they issued a refund for the balance.
For me, hCaptcha has stopped working immediately before last weekend, regardless of the site that uses it.
It goes in an infinite loop, despite solving correctly all challenges.
On Linux, I have tested with 2 browsers, Firefox and Vivaldi, and the browser did not make any difference. I do not use any ad blockers, nor any non-standard extension.
So I think that they deployed a version update last Friday, which for some reason is broken on Linux.
It would not be surprising if both hCaptcha and Google ReCAPCHA have made some similar changes, so now they are both broken on Linux.
Meanwhile, some other "Captcha" applications from other vendors, which are used on other sites, still work like before.
NIH support staff is even worse as they refuse to acknowledge the issue and reply with a scripted useless response.
If I remember correctly, Recaptcha doesn't work on GrapheneOS either which is a separate issue.
Does not reproduce today though, and I never had issues with PMC/NIH before that.
Ich bin kein Roboter. Diese Website überschreitet das kostenlose reCAPTCHA Enterprise-Kontingent.
I am not a robot. This website has exceeded the free reCAPTCHA Enterprise quota.
The worst trigger is searching Google from the address bar.
Loading the homepage first makes the problem notably less common. Or getting a couple wrong.
Also firefox from linux. Just leave the pages open and refresh them every 20 minutes or so.