I struggle, and I mean I struggled with this one at around 2am in the morning really tired.
Depending on which leg you look at first, it could be going forward or backwards @Roblox Fix your stuff, this shouldn’t be in the Captcha’s.
It is perfectly logical. The only reason I think Roblox hasn’t done this in the past was because it is risky. But Roblox is at a point where they have to. People use bots to go into games and do bad stuff. IP banning is helpful but it can be blocked by a VPN. So now you have to contact the host of the VPN to ban the person. So just banning someone using a VPN is the easiest way.
I’m not sure if you know that the current bot issue on Roblox is made possible by humans.
There are tons of captcha solving services around which are used by botters to solve captchas.
What my point is, throwing impossible captchas to VPN users isn’t fair at all.
I’m a VPN user myself and I use it to secure my connection and to bypass network blockages. As you can see on my profile, I’m doing nothing bad at all. But, because I use a VPN I should be locked out of my account with an impossible captcha? No way!
Captcha typically adjusts itself based on your network or computers “reputation” ie is there a history of your IP address or account spamming features or doing suspicious things.
In terms of posting to group walls and such, it makes more sense to just not use a captcha unless there is suspicion something is going on. Ie a lot of people are posting to the wall, or a lot of accounts from your network are.
There is no reason someone in good standing should still get ridiculous Captchas. My best guess is that Roblox didn’t want to take any risks of people getting around this but it’s definitely possible to adjust it.
Something Roblox could possibly do to stop this is create API keys. You basically fill out an application, and if you pass you will be emailed an API key, if you fail, you will not receive one. It can be whitelisted by IPs and for services like Glitch, you can whitelist AWS containers. It may solve a lot of issues. The problem with cookies are, they can be found and exploited, Roblox hasn’t changed it so people learn more things they can do to exploit the game, they last for WAY too long (like 1w is enough). Noblox now has a refresh cookie which could give you access to a cookie that works forevery. Roblox moderation is lacking so a lot of in-game bots are not noticed by Roblox. There is no IP protection what so ever, so if someone DOES grab your cookie, they can use it as they please, it is a bypass for verification.
From looking through an HTML, I was able to identify something. There are parameters for what type captcha send. I’m not going to send a picture to protect Roblox. But it is something to think about. There are different captchas for different actions. Something a will point out is, Roblox has a whole API for captchas on their end and Arkose’s end
Maybe this is how roblox changes the age demographic, by making it super difficult for children to sign up and complete captchas, well played.
There is not even an upside to these insane captchas since I have seen barely any decrease in bots if any so it obviously isn’t working in that area at all.
A test you could do is try making accounts, with different ages, and IPs (make sure they have a low rating on AbuseIPDB) and see if the captcha’s are different. Because, safe chat is based on age, not settings. So, they may give different captcha’s to lower ages and harder ones to higher ages.
This is not even close to how bots work. Bots are using APIs. They don’t even need a browser. All they need is an IP, a RBXSecurity cookie, and a good internet connection. Infact, they don’t even touch on the domain (not including subdomains) roblox.com at all. And here is a quote to a post that goes into detail: