Login to Google Account w/o passing CAPTCHA

Bill Mac [PersonRank 9]

Wednesday, July 2, 2008
Just now I mistakenly entered bad username/password when trying to sign-in to a Google Account and naturally I was presented with a CAPTCHA. I did not enter any text for the CAPCHA field, but lo and behold, I was able to sign-in without solving the CAPTCHA.

Does anybody else notice this? I have tested it a few times and it always seems to work, whether the service is GMail or something else, like Google Reader.

James Xuan [PersonRank 10]

14 years ago #

Yeah, it's always been like that...

heebie sudoku [PersonRank 5]

14 years ago #

Why don't they fix it? Surely it's a massive security risk?

DPic [PersonRank 10]

14 years ago #

i'm not sure but i think it only happens what you mistype the username. if you fix the username there's no need for the captcha anymore. do you know if the same thing happens if you only mess up on the password?

Kernel Sanders [PersonRank 0]

14 years ago #

A more important question is: Why doesn't Phillip employ captcha use here, in his blog?
Friggin frustrating not being able to comment an "old" item (2 weeks is OLD?!?) just because the un-captcha'ed blog pages are bot-spammable and need to be "locked"?

I implore you to visit and to consider using it to protect pages, instead of "time locking" the entries.

Keith Chan [PersonRank 10]

14 years ago #

I remember if you have typed most part of your password correct say 9 out of 10 characters, then Google will still not prompt you to enter the CAPTCHA.

