Live data from Hacker News

Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

bitbucket.org

31–40 of 128 posts

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#31
post #5

Does it beat ReCaptcha v3?

Apparently yes.V3 is just the system used by V2 to give puzzle difficulty. I scored 0.7 for 40 hours on Vision API videos. https://www.youtube.com/watch?v=7tPcs06fgbg

Go to the channel for the other 3.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#32
post #7

At some point Captcha's will be easier to solve with software than by people. Hopefully by then we can retire them completely. The onus for proving that a visitor is not a bot should be on the server side, not on the humans.

google is already trying to retire them. v3 has no challenges, they just generate a score completely transparent to the end user

"Transparent" until Google doesn't trust you for some insane reason.

Now I can be denied access because of an opaque score, with no way to get around it.

Yay, progress!

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#33
post #15
post #3

Step 1: Use Captcha to get free AI training data. Step 2: Sell improved AI. Step 3: Add edge cases to the Captcha that your AI can't handle yet. Go to step 1.

Can someone please explain to me why smart people keep saying that we’ll just build software to detect deepfakes? When AlphaZero plays against itself it just gets better. Once that spread is so narrow, every deviation is in the range of possible error. And it can’t explain WHY a certain move is better or why the picture is a squirrel. And sometimes it can be wrong, but only on hilarious edge cases, in the rest we jus…

Sci-fi author John Varley covered this in one of his novels.

In a society where anything digital can be manipulated, the veracity of a speech or event depends on a network of trust and people who witnessed the event in real life. If someone made a speech in front of hundreds of live, physically present spectators, these spectators can then verify the authenticity of any recording, and as long as there people in that group that you trust (directly, through your trusted network, or perhaps as journalists of good standing) you can trust that the recorded speech is what was said.

Conversely, a recording of a world leader saying they recommend Coca-Cola to prevent tooth decay wouldn't have any credibility at all if no one credible was actually there to witness it.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#34

while neat, it's a boon to spammers and other nefarious actors who can use these techniques to further get around captcha... concerning to say the least. if we want to defeat time-wasting and privacy-invading captcha and the murky ethics aren't a concern, then we should go to every e-commerce site that employs them, with full crap-blocking privacy mode on, load up on products/services, and then abandon our carts at t…

I am perfectly fine with rendering CAPTCHAs absolutely useless for bot prevention if it expedites websites finally getting rid of the absolute pox that is reCAPTCHA.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#35
post #15
post #3

Step 1: Use Captcha to get free AI training data. Step 2: Sell improved AI. Step 3: Add edge cases to the Captcha that your AI can't handle yet. Go to step 1.

Can someone please explain to me why smart people keep saying that we’ll just build software to detect deepfakes? When AlphaZero plays against itself it just gets better. Once that spread is so narrow, every deviation is in the range of possible error. And it can’t explain WHY a certain move is better or why the picture is a squirrel. And sometimes it can be wrong, but only on hilarious edge cases, in the rest we jus…

What's needed is more cryptography. Build keys into sensors to sign media and use something like blockchain to broadcast the signature at time of capture / time when the device returns to the internet.

Won't be perfect, but it would be a hurdle. Also, for things like audio and video if you know the location on the planet then there are certain artifacts that are hard to fake with mere AI. The way sound bounces off walls in a room or shared environmental noise that other devices in the area would detect, like a plane flying by.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#36

Woah, I never seen something like this done with bash and command line utilities. Thanks for sharing, made me find xdotool which is exactly what I neede to replace SikuliX. I can't comment on the project since I didn't test it but wow, only this example https://bitbucket.org/Pirates-of-Silicon-Hills/voightkampff/... made me think why didn't OP use a scripting language and went with Bash? (Python?) Don't get me wrong,…

It was my first time working with Bash. My focus is algorithms and I use C++.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#37

while neat, it's a boon to spammers and other nefarious actors who can use these techniques to further get around captcha... concerning to say the least. if we want to defeat time-wasting and privacy-invading captcha and the murky ethics aren't a concern, then we should go to every e-commerce site that employs them, with full crap-blocking privacy mode on, load up on products/services, and then abandon our carts at t…

I am perfectly fine with rendering CAPTCHAs absolutely useless for bot prevention if it expedites websites finally getting rid of the absolute pox that is reCAPTCHA.

Yeah. Text captcha/Recaptcha can be solved by spammers. The more advanced the more cpu time it burns up but it still does little to stop them. It just makes it super inconvenient for me to solve. Sometimes they aren't even human readable.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#39
post #15

Earlier quoted context omitted.

Can someone please explain to me why smart people keep saying that we’ll just build software to detect deepfakes? When AlphaZero plays against itself it just gets better. Once that spread is so narrow, every deviation is in the range of possible error. And it can’t explain WHY a certain move is better or why the picture is a squirrel. And sometimes it can be wrong, but only on hilarious edge cases, in the rest we jus…

Sci-fi author John Varley covered this in one of his novels. In a society where anything digital can be manipulated, the veracity of a speech or event depends on a network of trust and people who witnessed the event in real life . If someone made a speech in front of hundreds of live, physically present spectators, these spectators can then verify the authenticity of any recording, and as long as there people in that…

So you'd need a bunch of GPT-3+ stuff to corroborate the deepfake, exciting! Where do you determine the "troll-line" in a trust network? You can build it over time I suppose? Though that kind of leads to similar echo-chamber stuff, right?

As an anecdote, I know real humans who do truly believe deepfaked political videos. They were genuinely surprised to know that Pelosi can talk like a normal human.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#40
post #15

Earlier quoted context omitted.

Can someone please explain to me why smart people keep saying that we’ll just build software to detect deepfakes? When AlphaZero plays against itself it just gets better. Once that spread is so narrow, every deviation is in the range of possible error. And it can’t explain WHY a certain move is better or why the picture is a squirrel. And sometimes it can be wrong, but only on hilarious edge cases, in the rest we jus…

Sci-fi author John Varley covered this in one of his novels. In a society where anything digital can be manipulated, the veracity of a speech or event depends on a network of trust and people who witnessed the event in real life . If someone made a speech in front of hundreds of live, physically present spectators, these spectators can then verify the authenticity of any recording, and as long as there people in that…

This doesn't work that well in practice:

- Humans can lie

- Human memory is too fallible to serve as this verification, particularly for every detail

- Small details with big impact can be changed in a verified speech without some people noticing

Of course if someone reliable records the actual speech, any copy can be checked against that. I'm not sure why human memory would be considered superior, as humans have poor memories and can lie.

Post reply on HN