My question pertains to the general security of using a captcha solving provider.
First to explain using a captcha provider the required steps are:
GET https://2captcha.com/in.php?key=YOUR_API_KEY&method=userrecaptcha&googlekey=6LeIxboZAAAAAFQy7d8GPzgRZu2bV0GwKS8ue_cH&pageurl=http://2captcha.com/demo/recaptcha-v2
GET https://2captcha.com/res.php?key=YOUR_API_KEY&action=get&id=2122988149
OK|03AHJ_Vuve5Asa4koK3KSMyUkCq0vUFCR5Im4CwB7PzO3dCxIo11i53epEraq-uBO5mVm2XRikL8iKOWr0aG50sCuej9bXx5qcviUGSm4iK4NC_Q88flavWhaTXSh0VxoihBwBjXxwXuJZ-WGN5Sy4dtUl2wbpMqAj8Zwup1vyCaQJWFvRjYGWJ_TQBKTXNB5CCOgncqLetmJ6B6Cos7qoQyaB8ZzBOTGf5KSP6e-K9niYs772f53Oof6aJeSUDNjiKG9gN3FTrdwKwdnAwEYX-F37sI_vLB1Zs8NQo0PObHYy0b0sf7WSLkzzcIgW9GR0FwcCCm1P8lB-50GQHPEBJUHNnhJyDzwRoRAkVzrf7UkV8wKCdTwrrWqiYDgbrzURfHc2ESsp020MicJTasSiXmNRgryt-gf50q5BMkiRH7osm4DoUgsjc_XyQiEmQmxl5sqZP7aKsaE-EM00x59XsPzD3m3YI6SRCFRUevSyumBd7KmXE8VuzIO9lgnnbka4-eZynZa6vbB9cO3QjLH0xSG3-egcplD1uLGh79wC34RF49Ui3eHwua4S9XHpH6YBe7gXzz6_mv-o-fxrOuphwfrtwvvi2FGfpTexWvxhqWICMFTTjFBCEGEgj7_IFWEKirXW2RTZCVF0Gid7EtIsoEeZkPbrcUISGmgtiJkJ_KojuKwImF0G0CsTlxYTOU2sPsd5o1JDt65wGniQR2IZufnPbbK76Yh_KI2DY4cUxMfcb2fAXcFMc9dcpHg6f9wBXhUtFYTu6pi5LhhGuhpkiGcv6vWYNxMrpWJW_pV7q8mPilwkAP-zw5MJxkgijl2wDMpM-UUQ_k37FVtf-ndbQAIPG7S469doZMmb5IZYgvcB4ojqCW3Vz6Q
function injectToken() { document.getElementsByName("g-recaptcha-response").innerHTML=token}
injectToken()
My question is rather broad, and I apologize in advance for that, but there is no searchs or information I could find that could address this.
What is the security risks in sending out such requests to Captcha Solving Service Provider? None of their websites have any information pertaining to the security of their service? Tickets I have opened with them are still pending.
Would this allow for people to steal data, get access in anyway, execute code, or track the user?
How would you convince someone it is a secure service? None of the providers seem to care about providing the basic information on why there service does not introduction any security risks.
Also does it make a difference that some services use human workers that could also potentially have access to the site-key and url information from the request?
Excuse my ignorance. Hopefully your answers will bring me into the know. Thank you.
I have opened support tickets with various vendors. Searched on many forums and search engines with no avail.