Live data from Hacker News

Blocking via an Unsolvable CAPTCHA

google.com

1–10 of 63 posts

Re: Blocking via an Unsolvable CAPTCHA

#3
From the (overly lengthy) Patent Description section:

A challenge-response test may include a type of authentication where one party (e.g., security device 240) presents a question (e.g., a “challenge”) and another party (e.g., attacker device 210) is required to provide a valid solution (e.g., a “response”) to be authenticated. An unsolvable challenge-response test may include a challenge-response test that does not have a correct solution and/or a challenge-response test where attacker device 210 may be incapable of providing the correct solution (e.g., when the correct solution includes a character that may not be typed using a standard keyboard, etc.). In some implementations, security device 240 may generate the unsolvable challenge-response test in the form of an unsolvable CAPTCHA. In some implementations, security device 240 may generate the unsolvable CAPTCHA using one or more construction techniques that are designed to block attacker device 210 from sending a request to server device 230 without making attacker device 210, and/or a user of attacker device 210 (e.g., a hacker), aware that attacker device 210 is being blocked (e.g., by security device 240) from sending the request to server device 230.

Re: Blocking via an Unsolvable CAPTCHA

#4
I hate stuff like this. When I fall into the "this guy looks unusual" bucket, I don't want to have to second-guess whether your system is even going to let me in if I put in the effort to jump through its kafkaesque hoops.

I had trouble with Coinbase account verification which I'm almost certain was akin to the linked patent: it asked me for a picture of my passport, and then a picture of my face, and then told me that the pictures didn't match and I must try again. Every single time. I only managed to regain access to my account by emailing a contact that most people wouldn't have.

Re: Blocking via an Unsolvable CAPTCHA

#6
This makes me think of userbinator's comment from yesterday's Google Memory Loss post.

To add insult to injury, if you do try to make complex and slightly varying queries and exhaust its result pages in an effort to find something you know exists, very often it will think you're a robot and present you with a CAPTCHA, or just ban you completely (solving the CAPTCHA just gives you another, and no matter how many you solve it keeps refusing to search; but they probably benefit from all the AI help you just gave them, what bastards...) for a few hours.

Edit: I wonder if Google is using this as a sort of income source for pages that bring little to no ad revenue.

Re: Blocking via an Unsolvable CAPTCHA

#7
That's literally what it takes to get something patented? For better or worse, maybe by patenting it, we won't see that solution used in many products from other companies.

Hmm, maybe I should start thinking up annoying things that future software might do for profit, and patent them now to stop companies from doing them for a while.

Re: Blocking via an Unsolvable CAPTCHA

#8
post #7

That's literally what it takes to get something patented? For better or worse, maybe by patenting it, we won't see that solution used in many products from other companies. Hmm, maybe I should start thinking up annoying things that future software might do for profit, and patent them now to stop companies from doing them for a while.

> maybe by patenting it, we won't see that solution used in many products from other companies

My favorite in this genre is IBM's patent on patent trolling: https://www.google.com/patents/US20070244837

Re: Blocking via an Unsolvable CAPTCHA

#10
post #6

This makes me think of userbinator's comment from yesterday's Google Memory Loss post. To add insult to injury, if you do try to make complex and slightly varying queries and exhaust its result pages in an effort to find something you know exists, very often it will think you're a robot and present you with a CAPTCHA, or just ban you completely (solving the CAPTCHA just gives you another, and no matter how many you s…

I thought this item would be related to that very popular item... I saw it mentioned in discussion.

At work I just recently managed to trip it three times in one day, which I consider a record since in the past I've encountered it at most a few times a week. What's more infuriating is that my queries were far less complex than the ones that tripped it before (trying to find information about some API constants), basically one quoted term and one site: modifier. I can understand if I was querying 24/7 and hogging their servers (in which case a nice "please slow down" message would be much better), but it tripped within a few minutes of, admittedly intense, Googling.

The security device may notify the attacker device that the solution is incorrect regardless of whether the solution is actually correct.

In Google's case, it doesn't do that at all --- solve one CAPTCHA successfully and all you get is another, immediately. If you actually do deliberately give the wrong answers, it does tell you they were incorrect.

I wonder what can be done to stop it from doing that, besides the old tactic of evading IP bans by changing IP --- it's somewhat creepy to think that it's probably capable of detecting that too and banning the entire subnet. On second thought, it might be worth it... if it means I can get thousands of others blocked from Google for a nontrivial amount of time, all the more mouths to complain and maybe force some reconsideration. I am not a robot. I am not a competitor scraping your pages or doing anything else against your ToS. I am just an intelligent human with over two decades of Internet searching experience enthusiastically using your service for the exact purpose it claims to do: to find something on the Internet.

Post reply on HN