recaptcha icon indicating copy to clipboard operation
recaptcha copied to clipboard

⚠️⚠️ FCC VIOLATION ⚠️⚠️ Recaptcha is being abused by clients to thwart downloading.

Open Lexxos opened this issue 3 years ago • 1 comments

I've raised this issue many times with Envato. They use Google Recaptcha to limit the amount you're able to download. It isn't time based or how fast you download. It's based on the amount downloaded. For instance. If I download over 50 items in one day, they start to require a recaptcha every 15 items, and then it's reduced to 10, and then 5, and then every download requires a recaptcha.

I asked them about this, and they asked "why are you downloading so much?" What are you talking about? You have stock photos, videos, and fonts. They don't offer a way to download a preview, and they have no way of viewing fonts before you try them. Google Fonts would be ideal for them. So I am forced to download things that MIGHT work, only to be blocked by a recaptcha.

And it would be fine if it was a regular recaptcha but it isn't. It will start to slow down to the point that it takes on average 3 minutes to complete one recaptcha.

Envato lists "UNLIMITED DOWNLOADS" and that in itself doesn't matter in the fact that websites cannot throttle your data usage if your activities are legitimate. Which they are. I also use Google DNS, and since Google is an ISP, they aiding in an effort to throttle data which is extremely against FCC regulations.

Clear motive:

  1. you are not utilizing any means other than traffic to determine your recaptcha.
  2. you are selling a false product as it does not actually detect bots.
  3. you are selling a product, and using the customers of clients to train your own neural network.
  4. you are extorting both clients and their customers as well as allowing clients to throttle data usage.

The FCC's open internet rules protect and maintain open, uninhibited access to lawful online content. The rules specifically prohibit: • Blocking: Broadband providers may not block access to lawful content, applications, services or non-harmful devices. • Throttling: Broadband providers may not deliberately target some lawful internet traffic to be delivered to users more slowly than other traffic. • Paid prioritization: Broadband providers may not favor some internet traffic in exchange for consideration of any kind. ISPs are also banned from prioritizing content and services of their affiliates.

Since Google, Amazon, and some other ISP offer the broadband availability of these websites from their data center servers, they are in fact INDIRECTLY violating the rules set forth by the FCC.

Issue description

Environment

  • OS name and version:
  • PHP version:
  • Web server name and version:
  • google/recaptcha version:
  • Browser name and version:

Reproducing the issue

  • URL (optional):
  • Code (optional):

User steps

1. Visit page...

Lexxos avatar Nov 05 '21 22:11 Lexxos

FCC Ticket: 5126910

Lexxos avatar Nov 05 '21 22:11 Lexxos

Repo is just for PHP client issues. This is about the reCAPTCHA service.

rowan-m avatar Feb 18 '23 19:02 rowan-m