Live data from Hacker News

An Empirical Study and Evaluation of Modern CAPTCHAs

arxiv.org

101–110 of 338 posts

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#103

Earlier quoted context omitted.

With a token, you probably get a higher efficiency. Similar to how a heatpump is more efficient than a heater. If you only consume resources on the client side, then you hope that an attacker thinks "I won't invest $0.01 of resources just to log in here". If you also transfer the consumed resources to the server, you get an additional benefit: The server thinks "$0.01 is enough to cover the costs of a fake signup". A…

I think a fairer solution will be some form of proof of personhood that isn't PoW-based. Your idea isn't bad but it gives more power to those who can afford a lot of devices. You know those Chinese mobile phone click farms they use to game app stores? It will be like that, PoW can prevent spam only to a certain degree and with all the social media and networks we have today there is a lot of money in influencing the…

Depends on the use case.

If the captcha is to prevent overuse of a free trial, then nobody will operate a lot of devices just to get more free trials if the paid version is cheaper than those devices.

If the use case is to improve democracy, then it gets more complicated.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#104
post #17
post #7

I think captchas disappear next year or so. Already was soft human determination.

That’s excessively optimistic. The most likely scenario is that we’ll have captchas for the next 30 years but only humans will be bothered by them.

Sounds like DRM - pirates do not care, legitimate users are bothered.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#105
post #99

Earlier quoted context omitted.

GPT-4 (in)famously tricked a human to do a captcha for it. The current GPT-4 with vision would probably have been able to do it without the human, but maybe it has been “gaslit” by all the content online saying that only humans can solve captchas, that it doesn’t consider it?

It’s safety trained to not solve captchas.

I’ve seen screenshots of people tricking it into solving captchas.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#106
post #66

Does HN ever require CAPTCHAs? It seems to do pretty well with its basic but battle-tested moderation/antispam tools, and rate-limiting that seems to repel all but the most concerted DDoS attacks. I don't think HN has any unreasonable restrictions on scraping or third-party clients, either. And it manages to serve 5M unique visitors a month and 10M views a day[0]. [0] https://news.ycombinator.com/item?id=33454140

I cant tell if the audience of HN are more likely to script something untoward against HN, be that DDOS or just "check out my product" spam, because its a bunch of hackers - or less likely to do it because (maybe) we like having nice things, or figure the audience is too in the know to fall for boring crypto spam.

HN audience is rich enough to just pay $10 for 1000 solved CAPTCHAs of any complexity since those services are human powered.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#107
post #66

Does HN ever require CAPTCHAs? It seems to do pretty well with its basic but battle-tested moderation/antispam tools, and rate-limiting that seems to repel all but the most concerted DDoS attacks. I don't think HN has any unreasonable restrictions on scraping or third-party clients, either. And it manages to serve 5M unique visitors a month and 10M views a day[0]. [0] https://news.ycombinator.com/item?id=33454140

They go down somewhat frequently. I think it’s like four 9’s? I’m not sure why they insist on running just a few machines though. They have more than enough money and probably make up the difference by the advertising for YC that they get.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#108
post #99

Earlier quoted context omitted.

GPT-4 (in)famously tricked a human to do a captcha for it. The current GPT-4 with vision would probably have been able to do it without the human, but maybe it has been “gaslit” by all the content online saying that only humans can solve captchas, that it doesn’t consider it?

It’s safety trained to not solve captchas.

Yes, and you can workaround it by asking it to read ancient writings on antiques for example.

I don’t think it should be OpenAI deciding what is allowed or not though.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#109
post #66

Does HN ever require CAPTCHAs? It seems to do pretty well with its basic but battle-tested moderation/antispam tools, and rate-limiting that seems to repel all but the most concerted DDoS attacks. I don't think HN has any unreasonable restrictions on scraping or third-party clients, either. And it manages to serve 5M unique visitors a month and 10M views a day[0]. [0] https://news.ycombinator.com/item?id=33454140

They go down somewhat frequently. I think it’s like four 9’s? I’m not sure why they insist on running just a few machines though. They have more than enough money and probably make up the difference by the advertising for YC that they get.

Unless something changed, it's just the one server.
Post reply on HN