Live data from Hacker News

An Empirical Study and Evaluation of Modern CAPTCHAs

arxiv.org

201–210 of 338 posts

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#201
post #131
post #119

Earlier quoted context omitted.

EU digital ID, asking for mobile number and sending text, so something that is linked to an ID and/or costs money to have. Goodbye anonimity, probably.

This just made me ponder again—where does the assumption that the Internet should allow unconstrained anonymity come from, other than that’s how it used to be for some time? The real world doesn’t allow that. It’s hard to remain anonymous in the real world. The real world largely runs on identity and (identity) trust. Why should the Internet be different?

I believe that the question should be the other way around:

Why is it that you have to lose your anonimity when you are on the internet? The real world always allowed that until it became dependent on surveillance capitalism. Of course you need to prove you're yourself for some things, but that should be the exception. You could always look things up at your local library while being anonymous (for checking out you'd need a card), you could call from a payphone while being anonymous, you could use coins (cash in general) while being anonymous.

Anonimity was the rule and should still be the rule

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#204

Earlier quoted context omitted.

Can't vouch for other Europeans but I got used to them to the point my arm moves automatically where needed before clicking, even accounting for extra modals. I almost don't register them anymore.

Consent-O-Matic (and probably other extensions too) will refuse most cookies automaticaly for you: https://github.com/cavi-au/Consent-O-Matic

Thanks a lot, I totally forgot about this!

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#205
post #76

Earlier quoted context omitted.

The next step is device attestation. IIRC Safari already does this, so you should not see captcha on places that support it. Something that can work on any browser can be like this: Scan the QR code in your iPhone or Android device that supports attestation. Will ask you if you approve login, then will attest for you. If you turn out to be a bad actor, the website can ban this device - so no flooding with a single de…

There are over a billion Idevices out there. Malware on just 1% of them can make and control 10 million spam accounts on every site using device attestation, and they're indistinguishable from real users.

Captcha or Attestation doesn't remove the need of moderation. In case of a botnet, an elevated complaints of user device engaging in fraudulent activity can lead to disabling attestation and trigger an investigation. Every iDevice being a member of your site can happen only if you are Google, other than that what you'll see is that some users will engage in shady stuff and blocking them will be enough to keep them out since they wouldn't be able to just sign in with a new account.

These things are always cat and mouse games.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#206
post #176

I guess validating a payment card is going to be the next step to sign up for whatever. Don’t allow pre paid BINs and let’s go. Gonna be pretty miserable, however someone needs to find something as I currently would rather pay 0.01$ instead of solving a captcha. Especially the select all the bicycles; it’s a waste of life.

At this point the amount of friction added to all these things is pushing things towards just not doing them in the first place (buying less stuff, using social media less). Nature walks and paper books doesn't have captchas.

> just not doing them in the first place

Which is not a bad thing

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#207

You see where this is heading: after superintelligence is achieved, CAPTCHAs will be designed to be questions that humans get wrong but AI has no problem with.

A superintelligent AI would be able to imitate a human, getting the answers incorrect in exactly the way needed.

However, I'm not entirely sure what kind of system a superintelligent AI would need to access which would be protected by a captcha.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#209

Google CAPTCHAs were designed and deployed as a mechanism to train AIs. That's why they are the way they are. Any security theater surrounding them is entirely incidental. So it's no surprise that the AIs are now good at solving them. We've trained them for years.

This doesn't make sense. reCAPTCHA certainly does what it says on the tin. But the way it does it has almost nothing to do with the challenge the human sees. It's all behavioral analytics, including leveraging Google's collected data to determine how likely a user is a bot before they even load the page. I'm not denying reCAPTCHA is a source of training data for Google -- surely there's no particular reason that ever…

> including leveraging Google's collected data to determine how likely a user is a bot before they even load the page.

And also completely incidentally making the web browsing experience a wee bit less pleasant for people who refuse to have google track their every click.

Like users of non-chrome browsers, adblockers etc.

Totally incidental I'm sure.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#210
post #182

Earlier quoted context omitted.

It feels like you left out context, otherwise what’s the problem? Do you get mad at fiction authors for lying to you when you read their books? Or are you OK if someone lies to your detriment then later says “I was just telling a story, bro, but with us as the characters and without explaining it was a story”?

I suppose my point is that the rules which openAI attempts to impose on what their AI should and shouldn't be allowed to do are contradictory and thus the exploitable loopholes will never be fully closed. Its not supposed to be able to "lie" to me but it is supposed to be able to "tell me a fictional story". Define the difference in an enforceable way?

A lie tries to pass itself of as the truth, where a fictional story doesn’t. In other words, expectations matter. If every time you say something that does not align with reality you prefix it by saying unambiguously what you’re about to do, you rob a lie of its power of deception and it ceases to be a lie.
Post reply on HN