Live data from Hacker News

An Empirical Study and Evaluation of Modern CAPTCHAs

arxiv.org

221–230 of 338 posts

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#221
post #108
post #99

Earlier quoted context omitted.

It’s safety trained to not solve captchas.

Yes, and you can workaround it by asking it to read ancient writings on antiques for example. I don’t think it should be OpenAI deciding what is allowed or not though.

> I don’t think it should be OpenAI deciding what is allowed or not though.

Avoiding lawsuits is what they are trying to do. They don't actually care about what you use their products for.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#222
post #169

Earlier quoted context omitted.

I've had that idea for years. Two versions that I experimented with. One is where the incoming POW hashes contribute to hashing power for some blockchain mining. An alternative "pay as you use the API" system. The other using hashcash. Just a way to slow down abuse. Both, however, suffer from the downside that many/all "ASIC resisting crypto mining" suffer from as well: the cheapest CPU power is CPU power from machin…

Dirty energy is (often) cheap, so that's the energy the bad actors will use. I don't know that incentivizing bad actors to waste energy in a climate crisis is the best way to fight this problem. You might correctly claim clean energy is often cheaper, but you must also consider the regions in which they'll get away with nefarious activity, and whether those areas have made the investments into making clean energy che…

I was specifically talking about "ASIC resistant crypto mining".

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#223

Earlier quoted context omitted.

Tesla recalled two million vehicles after federal officials said it had not done enough to make sure that drivers remained attentive when using the system. Not because their self-driving system sucks, or whatever you were trying to imply.

If the self driving system were worth it's salt, it wouldn't matter if the drivers weren't paying attention. Ergo, the system sucks, or is at the very least not nearly as good as Tesla likes to tout.

It can be "worth it's salt" but the government still doesn't see it as such (for many possible reasons).

I don't know if it is or isn't, I never drove one, but those are two completely different standards

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#224

Earlier quoted context omitted.

Who pays for the bandwidth and download resources then?

The website or service owners. If they can't afford it they should be out of business and do something else. The web is big enough for both humans and bots.

No thank you. I prefer to live by the code "Every request is a two way conversation. The client may accept, and the server may choose to emit."

Just because I emit to other clients does not obligate me to emit to yours, any more than my emission of ads obligates you to accept and render them (but if you don't, or if you choose to ignore my CAPTCHAs, I may choose not to emit to you).

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#225

Earlier quoted context omitted.

And when you do show ID, to buy booze for example, it’s checked and immediate forgotten by a human. Computers don’t forget, and any attempts to make companies do so (GDPR) are met with massive pushback from the players in the industry I have no problem with Joan over the road curtain twitching. It doesn’t scale. I have a massive problem with the 24/7 surveillance from ring though.

In the us, I noticed that grocery stores increasingly scan your drivers license (my state has bar codes). I think it's probably a way to keep clerks from passing someone through who is not quite 21 (a different captcha!). I have wondered if they keep the scan or does the state? I asked and the random hourly worker there said they don't.

And that’s the problem. It’s not the ID checks, it’s the ability to scale. Check it at the door? Fine. Scan it and keep it forever (perhaps selling it on at a later date)? Not fine.

Personal Data has to be treated as a liability, but too much of the economy treats it as an asset.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#226

Google CAPTCHAs were designed and deployed as a mechanism to train AIs. That's why they are the way they are. Any security theater surrounding them is entirely incidental. So it's no surprise that the AIs are now good at solving them. We've trained them for years.

I always thought they used more timing & mouse movement instead of correct answer to verify if your a human.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#227

You see where this is heading: after superintelligence is achieved, CAPTCHAs will be designed to be questions that humans get wrong but AI has no problem with.

At least that would still be a proper CAPTCHA, in that it tells computers and humans apart…

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#229

Earlier quoted context omitted.

> Website operators can use alternatives, like asking for micro-payments Similarly to how dApps work in ethereum-like blockchains?

I don't know anything about ethereum

I also don't know much, but my limited understanding is that every transaction/mutation in a dApp has a cost, so this might be useful to reduce bot incentives.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#230

Earlier quoted context omitted.

I don't have to show my ID in most establishments I visit. Doing this on a huge scale and automatically is a thousand times worse.

But you can't send in 1000 people per second into most establishments you visit either. It's not an apt comparison.

No comparison can be made if everything has to be equal
Post reply on HN