logoalt Hacker News

chatmastayesterday at 10:42 PM0 repliesview on HN

You don’t need to MITM it, this was a common pattern for a long time (not sure it still works though). There was no origin verification so you could just use a different site ID and have people respond to captchas you encountered on that site.