Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So to bypass captcha all a user has to do is block the script from loading? I can see that working but only for attacks that aren’t targeted?


Only if they are able to block the siteverify check performed by our backend server. That's not the kind of attack we are trying to mitigate with Turnstile.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: