Live data from Hacker News

Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

mediamemo.allthingsd.com

31–40 of 81 posts

Re: Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

#31
post #15

I spent a minute trying but no, I cannot think of anything that would make me go 'well fuck you' and go elsewhere faster then being expected to type out ad copy like a school child.

and yet you will gladly type randomized and difficult to read letters or words?

This is actually attempting to solve two problems at once, and in some ways it could be more interesting to the user if the ads are well targetted.

Why not help the site owner make a bit of $$??? are you really afraid that typing in a bit of ad copy is going to turn you into a mindless drone

Re: Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

#32
post #17
post #3

So you replace the hard to read CAPTCHAs with easy to read ads. Of which presumably there will be a limited number in circulation at any one time. Sounds kinda easy to circumvent...

You know, most modern capchas are not solved by bots, but by people in third world countries solving them for pennies. The current going rate is about $1/1000 and there are easy to use captcha solving APIs for any platform. capcha has long provided an illusion of security, nothing more. Any and all captchas will be broken.

Before adding captchas to my stupid personal blog, Akismet was catching ~300 attempted spams a day, and I was manually flagging ~2 a day.

Then I installed reCaptcha, and now Akismet catches ~10 a month, and I've had to manually flag zero.

I'll take that illusion, thanks.

Re: Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

#33
post #15

I spent a minute trying but no, I cannot think of anything that would make me go 'well fuck you' and go elsewhere faster then being expected to type out ad copy like a school child.

and yet you will gladly type randomized and difficult to read letters or words? This is actually attempting to solve two problems at once, and in some ways it could be more interesting to the user if the ads are well targetted. Why not help the site owner make a bit of $$??? are you really afraid that typing in a bit of ad copy is going to turn you into a mindless drone

I'd rather type random characters than "Safer Browsing" for an IE ad. You have to consider the emotional reaction to these ads.

Re: Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

#35
post #20

Earlier quoted context omitted.

A longtime standing solution to hard-to-read captchas are easy to read (but hard to process) captchas. E.g. show a picture of an animal or a shape and ask what it is, or even just ask a simple math problem or riddle in writing. Problem with those are that they need to be constantly updated from a reliable source, or else, once the solution becomes popular, the spammer can bruteforce it in linear time (no matter how h…

You have no idea what you're talking about. > show a picture of an animal or a shape and ask what it is, Ok, so let's say you come up with pictures of 20 different animals. A spam script that picks the same answer every time will have a 5% success rate. > or even just ask a simple math problem or riddle in writing. Computers are way better at solving most math problems than people.

Please read my post. Specifically the second paragraph where exactly this issue is addressed.

Re: Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

#36
post #17

Earlier quoted context omitted.

You know, most modern capchas are not solved by bots, but by people in third world countries solving them for pennies. The current going rate is about $1/1000 and there are easy to use captcha solving APIs for any platform. capcha has long provided an illusion of security, nothing more. Any and all captchas will be broken.

I know the founders of reCaptcha. This is easier to prevent than you think. Its also quite rare.

Heh, I know people who are working on breaking reCaptcha. Maybe they should get together and learn from each other.

If you're saying that it's possible to prevent manual, outsourced captcha solving, I would have to strongly disagree. It's similar to the futility of DRM as an antipiracy measure. As long as I can see the captcha, I can pay someone in another country to solve it for me.

I will agree that it's rare- but the most sophisticated and high-volume spammers do it, and they're the ones you have to worry about.

In case people start giving me sideways glances I want to make it clear that I haven't done any blackhat stuff in a very long time, but I'm still interested in the blackhat community from a security researcher's perspective.

Re: Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

#37
post #16

Yeah, this is exactly what I want - remind the user about some other brand in the exact same signup page where I should actually try hard to win him over. Not to mention how ridiculously easy it will be to break these limited edition captchas.

Works just fine for a blogger that doesn't care too much whether you complete the captcha or not but likes the few extra bucks he makes on a well-commented blog entry.

Re: Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

#38
post #20

Earlier quoted context omitted.

A longtime standing solution to hard-to-read captchas are easy to read (but hard to process) captchas. E.g. show a picture of an animal or a shape and ask what it is, or even just ask a simple math problem or riddle in writing. Problem with those are that they need to be constantly updated from a reliable source, or else, once the solution becomes popular, the spammer can bruteforce it in linear time (no matter how h…

You have no idea what you're talking about. > show a picture of an animal or a shape and ask what it is, Ok, so let's say you come up with pictures of 20 different animals. A spam script that picks the same answer every time will have a 5% success rate. > or even just ask a simple math problem or riddle in writing. Computers are way better at solving most math problems than people.

You have no idea what you're talking about.

Please be careful. It could be that his thoughts are excellent but his communication is flawed. It could also be that he has a great deal of general expertise in the subject but is mistaken in this specific statement.

Thus, a general statement about him could be false is also aggressively ad hominem. You might want to consider focusing on the statement itself rather than the speaker, such as:

"Your suggestion is entirely wrong."

JM2C of course, and it is possible that I don't know what I'm talking about. I am not a psychologist or a logician.

Re: Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

#39
This sounds a lot like what Vidoop tried to do. Their initial idea was to replace passwords with an authentication mechanism based on selecting a number of pictures that fit into user-chosen categories. A person would select 3-5 images from a grid of 12 with each image belonging to a distinct category. Those who picked the images, in the correct order, corresponding to their chosen categories (selected on sign up to the service) along with their username was deemed authenticated. As far as I know they hoped to make money by selling ads within the categories, so if one of the categories displayed was "pets" you might see ads for petfood for example. They moved into doing captchas at some point too.

Anyway, it seemed like a promising idea, but they folded last year. Good write up from a former employee here: http://factoryjoe.com/blog/2009/06/05/the-fall-of-vidoop/

Re: Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?

#40
post #15

I spent a minute trying but no, I cannot think of anything that would make me go 'well fuck you' and go elsewhere faster then being expected to type out ad copy like a school child.

Did you go to their signup page? They had one that said "watch this ad clip to reveal the security code" and you had to watch the video to get the code to enter.

Interesting idea, but I would never watch an ad clip to signup for something nor would I want my users to have to.

Post reply on HN