kiwix / web

Bugs, enhancements, ideas for our Web presence
https://kiwix.org
7 stars 6 forks source link

Replace kiwix.org reCaptcha #151

Open kelson42 opened 2 years ago

kelson42 commented 2 years ago

reCaptcha is not only a tool to secure the contact page and secure that the user is not a bot. It is as well a solution which spies on visitors.

It seems as well that reCaptcha is not available in countries where Google is not accessible, such as China https://webmarketing.academy/en/hcaptcha/

Read here the CNIL assessment about the tool: https://twitter.com/DavidLibeau/status/1516041376542208012

For all these reasons we should think IMO to replace it by a solution which does not leak user private information.

kelson42 commented 2 years ago

https://www.hcaptcha.com seems a promising alternative, but I have no definitive opinion on this. Maybe a local only alternative would be even better.

martin8032 commented 2 years ago

I'm aware of hCAPTCHA, but I don't know enough about it to tell if they have simply the better marketing. I see the following options:

  1. If someone does the research and comes to the conclusion that hCAPTCHA is significantly better in terms of privacy protection, I'm happy to implement hCAPTCHA instead of reCAPTCHA.
  2. I can simply deactivate reCAPTCHA and give the built-in honeypot feature of Ninja Forms a shot. (Background: https://ninjaforms.com/blog/google-recaptcha/)
kelson42 commented 2 years ago

@martin8032 Sounds good, I will give me a bit of time to mature my opinions and have a look to your proposals.

stale[bot] commented 2 years ago

This issue has been automatically marked as stale because it has not had recent activity. It will be now be reviewed manually. Thank you for your contributions.