Live data from Hacker News

Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

bitbucket.org

51–60 of 128 posts

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#51
post #15

Earlier quoted context omitted.

Can someone please explain to me why smart people keep saying that we’ll just build software to detect deepfakes? When AlphaZero plays against itself it just gets better. Once that spread is so narrow, every deviation is in the range of possible error. And it can’t explain WHY a certain move is better or why the picture is a squirrel. And sometimes it can be wrong, but only on hilarious edge cases, in the rest we jus…

Audio and video evidence isn't admissible because it's audio or video (and may be inadmissible nonetheless). It's admissible because someone testifies under oath that they have personal knowledge of its provenance. The burden is on the party introducing the evidence to show that it's reliable, and the question of whether or not it is indeed reliable is a factual one for a judge or jury to answer. It's not assumed to…

It will be inadmissable because of the psychological effects. Imagine having someone claim you murdered someone. Also you happened to drive by that park where the person was murdered at the same time.

Now someone wants to frame you, perhaps because you are a celebrity or a person with money to extort from. So they claim that they saw you murder this person.

Normally, this wouldn't hold any water and no jury would convict you, we are not in the medieval ages anymore. There would be no evidence of you around the crime scene, because of course, you weren't there.

Now imagine that they are able to produce audio recordings of a conversation you had with the victim, screaming at them and saying "you are gonna pay for this". And then they also happen to have video evidence of a smart phone camera that happened to capture you stabbing the victim.

Now tell me, if the jury sees all this and then it gets dismissed, because of "deepfake" claims or whatever, how will it affect the outcome of this trial?

If you are truly innocent, this might still work out alright, unless you are not white. But imagine there is even the SLIGHTEST connection to the real world. It doesn't have to be completely fake. Maybe you had some fight with that victim earlier, or there are witnesses who testify under oath that you had several heated arguments with them, etc.

Deepfakes can change the entire outcome of trials, by biasing the jury and proceedings against you. That's why any audio and video evidence essentially needs to be rejected without a very very thorough forensic analysis of its authenticity. And even then you would still not know for sure.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#52

Earlier quoted context omitted.

I am perfectly fine with rendering CAPTCHAs absolutely useless for bot prevention if it expedites websites finally getting rid of the absolute pox that is reCAPTCHA.

Yeah. Text captcha/Recaptcha can be solved by spammers. The more advanced the more cpu time it burns up but it still does little to stop them. It just makes it super inconvenient for me to solve. Sometimes they aren't even human readable.

In the worst case, there are people in poor countries solving those chaptas for relatively little money. Probably not worth for everyone, but when operating a botnet on a large scale, thats probably a pretty attractive option as well.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#53
Interesting. Two things that I found interesting:

1) ip addresses he uses have probably really good reputation, because even with rather bad image recognition ability it still lets him in.

2) surprisingly enough google's captcha apparently doesn't consider mouse movements at all - the bot selects images rapidly one immediately after another and always clicks in the same place of image.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#55
post #15

Earlier quoted context omitted.

Can someone please explain to me why smart people keep saying that we’ll just build software to detect deepfakes? When AlphaZero plays against itself it just gets better. Once that spread is so narrow, every deviation is in the range of possible error. And it can’t explain WHY a certain move is better or why the picture is a squirrel. And sometimes it can be wrong, but only on hilarious edge cases, in the rest we jus…

Sci-fi author John Varley covered this in one of his novels. In a society where anything digital can be manipulated, the veracity of a speech or event depends on a network of trust and people who witnessed the event in real life . If someone made a speech in front of hundreds of live, physically present spectators, these spectators can then verify the authenticity of any recording, and as long as there people in that…

What happens when there's a global pandemic and everyone is forced to stay home and not attend witness any of these speeches, but instead has to watch the broadcast over the internet and/or TV?

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#56
post #50
post #19

Earlier quoted context omitted.

We do have methods to detect deepfakes and it often works very well (at least for any given generator, perhaps not multiple generators), but you're right, at some point deepfakes will be indistinguishable from real media. At that point I think the problem is largely outside the domain of computer science and we will need to start redefining "trust" looks like.

Anyone else find it mildly(/extremely) distressing that a large part of our industry is dedicated to creating technology that provides little-to-no value to society, but creates enormous opportunities for great societal damage? We then release the tech to the wild without any proposed way to address the problems, instead saying “the problems this causes are outside the domain of CS, so I won’t bother considering them…

“Too sweet”

https://economicsbyfilm.net/blog/2015/11/25/is-ai-progress

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#58

Earlier quoted context omitted.

That's not my problem. As a user I should not be inconvenienced for a problem caused by someone else. The offending party should pay the price.

That's not the server's problem. As the server, they should not be inconvenienced for a problem caused by someone else. The users (which includes the bots) should pay the price.

No, the users do not include the bots. You have this backwards.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#60

Earlier quoted context omitted.

Sci-fi author John Varley covered this in one of his novels. In a society where anything digital can be manipulated, the veracity of a speech or event depends on a network of trust and people who witnessed the event in real life . If someone made a speech in front of hundreds of live, physically present spectators, these spectators can then verify the authenticity of any recording, and as long as there people in that…

What happens when there's a global pandemic and everyone is forced to stay home and not attend witness any of these speeches, but instead has to watch the broadcast over the internet and/or TV?

Heh
Post reply on HN