Live data from Hacker News

Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

bitbucket.org

71–80 of 128 posts

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#71
post #15
post #3

Step 1: Use Captcha to get free AI training data. Step 2: Sell improved AI. Step 3: Add edge cases to the Captcha that your AI can't handle yet. Go to step 1.

Can someone please explain to me why smart people keep saying that we’ll just build software to detect deepfakes? When AlphaZero plays against itself it just gets better. Once that spread is so narrow, every deviation is in the range of possible error. And it can’t explain WHY a certain move is better or why the picture is a squirrel. And sometimes it can be wrong, but only on hilarious edge cases, in the rest we jus…

It's just a different world. Somehow we live with text being like that. Maybe we'll even learn to verify signatures from trusted sources one day.

With deepfakes, in general I agree but it is a bit like computer security. It may be no different from reality but it may still have marks of the network that generated it. Ways to detect it may come out slowly, like computer bugs, with some entities having incentives to research them heavily and not release them.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#72
post #65

Earlier quoted context omitted.

If I were Google, I would let it pass (at least where it's not in my own services, not in crucial places), and use that obviously simple heuristic for machine learning so that distinction between human and robot can be taught using many other available variables. Well, I wouldn't really do that if I were Google. But I think it could be happening.

Google doesn't pass or fail, it gives a score and leaves it up to the site operator.

s/let it pass/give lower score

Although I admit my idea looks less probable this way. It's still less ridiculous to me that not using keyboard or mouse data.

But on the other hand they may be afraid of people screaming "Google is sending your keystrokes to their servers" etc.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#74
post #50
post #19

Earlier quoted context omitted.

We do have methods to detect deepfakes and it often works very well (at least for any given generator, perhaps not multiple generators), but you're right, at some point deepfakes will be indistinguishable from real media. At that point I think the problem is largely outside the domain of computer science and we will need to start redefining "trust" looks like.

Anyone else find it mildly(/extremely) distressing that a large part of our industry is dedicated to creating technology that provides little-to-no value to society, but creates enormous opportunities for great societal damage? We then release the tech to the wild without any proposed way to address the problems, instead saying “the problems this causes are outside the domain of CS, so I won’t bother considering them…

I hope I didn't make it seem like I was pushing the solution onto others when I said that it will move outside the domain of computer science. My research is in the area of detecting deep fakes.

You're definitely right about how little we attend to the consequences of our advancements, especially in the field of AI/ML. This area is fraught with ethical and moral issues that have taken a backseat to the ideal of progress and I think we are making a mistake there.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#75
post #65

Earlier quoted context omitted.

If I were Google, I would let it pass (at least where it's not in my own services, not in crucial places), and use that obviously simple heuristic for machine learning so that distinction between human and robot can be taught using many other available variables. Well, I wouldn't really do that if I were Google. But I think it could be happening.

Google doesn't pass or fail, it gives a score and leaves it up to the site operator.

They only did that so they could shift the blame/responsibility of making the classification to website operators instead of themselves.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#76

Earlier quoted context omitted.

Audio and video evidence isn't admissible because it's audio or video (and may be inadmissible nonetheless). It's admissible because someone testifies under oath that they have personal knowledge of its provenance. The burden is on the party introducing the evidence to show that it's reliable, and the question of whether or not it is indeed reliable is a factual one for a judge or jury to answer. It's not assumed to…

It will be inadmissable because of the psychological effects. Imagine having someone claim you murdered someone. Also you happened to drive by that park where the person was murdered at the same time. Now someone wants to frame you, perhaps because you are a celebrity or a person with money to extort from. So they claim that they saw you murder this person. Normally, this wouldn't hold any water and no jury would con…

[deleted]

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#77

Earlier quoted context omitted.

What's needed is more cryptography. Build keys into sensors to sign media and use something like blockchain to broadcast the signature at time of capture / time when the device returns to the internet. Won't be perfect, but it would be a hurdle. Also, for things like audio and video if you know the location on the planet then there are certain artifacts that are hard to fake with mere AI. The way sound bounces off wa…

> Build keys into sensors to sign media and use something like blockchain to broadcast the signature at time of capture / time when the device returns to the internet. That literally accomplishes nothing. It would be a matter of time before someone just removes the light sensor (CCD? or something) and has a custom made encoder that can write the input data as though the device actually records it live.

Yes, like I said, it's not perfect. There will still be deepfakes, but they won't be around every single nook and cranny. And once you ever invalidate a video, all other works by the same key are now suspect.

Imagine two court cases. In one, there is a video signed with a key from a phone that shows no signs of compromise. In the other, there is a video with no signatures at all. Which is more trustworthy? It's a continuum, not a binary.

Edit:

And also, we can scale trust. There should be more webs-of-trust in the world. I should be able to tap my phone next to my buddies and it should create a link between us. We should have the concept of trust online when we need it.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#78

Earlier quoted context omitted.

Audio and video evidence isn't admissible because it's audio or video (and may be inadmissible nonetheless). It's admissible because someone testifies under oath that they have personal knowledge of its provenance. The burden is on the party introducing the evidence to show that it's reliable, and the question of whether or not it is indeed reliable is a factual one for a judge or jury to answer. It's not assumed to…

It will be inadmissable because of the psychological effects. Imagine having someone claim you murdered someone. Also you happened to drive by that park where the person was murdered at the same time. Now someone wants to frame you, perhaps because you are a celebrity or a person with money to extort from. So they claim that they saw you murder this person. Normally, this wouldn't hold any water and no jury would con…

In your examples, it would most likely be a Mistrial scenario, the jury would be dismissed, and the prosecuting team would have to start over again from scratch later, assuming they aren't themselves in trouble for introducing faulty evidence.

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#79
post #32

Earlier quoted context omitted.

google is already trying to retire them. v3 has no challenges, they just generate a score completely transparent to the end user

"Transparent" until Google doesn't trust you for some insane reason. Now I can be denied access because of an opaque score, with no way to get around it. Yay, progress!

yup. Setting some tor privacy extensions in Firefox already locks you out of Google login. Yay!

Re: Beating Google ReCaptcha and the funCaptcha using AWS Rekognition

#80

while neat, it's a boon to spammers and other nefarious actors who can use these techniques to further get around captcha... concerning to say the least. if we want to defeat time-wasting and privacy-invading captcha and the murky ethics aren't a concern, then we should go to every e-commerce site that employs them, with full crap-blocking privacy mode on, load up on products/services, and then abandon our carts at t…

>abandon our carts at the captcha.

I thought the credit card number was the answer to the captcha on an e-commerce site.

Post reply on HN