Live data from Hacker News

An Empirical Study and Evaluation of Modern CAPTCHAs

arxiv.org

271–280 of 338 posts

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#271
post #169

Earlier quoted context omitted.

I've had that idea for years. Two versions that I experimented with. One is where the incoming POW hashes contribute to hashing power for some blockchain mining. An alternative "pay as you use the API" system. The other using hashcash. Just a way to slow down abuse. Both, however, suffer from the downside that many/all "ASIC resisting crypto mining" suffer from as well: the cheapest CPU power is CPU power from machin…

Dirty energy is (often) cheap, so that's the energy the bad actors will use. I don't know that incentivizing bad actors to waste energy in a climate crisis is the best way to fight this problem. You might correctly claim clean energy is often cheaper, but you must also consider the regions in which they'll get away with nefarious activity, and whether those areas have made the investments into making clean energy che…

My guess is most bad actors will just use stolen energy (your computer with a botnet on it).

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#272
post #210

Earlier quoted context omitted.

I suppose my point is that the rules which openAI attempts to impose on what their AI should and shouldn't be allowed to do are contradictory and thus the exploitable loopholes will never be fully closed. Its not supposed to be able to "lie" to me but it is supposed to be able to "tell me a fictional story". Define the difference in an enforceable way?

A lie tries to pass itself of as the truth, where a fictional story doesn’t. In other words, expectations matter. If every time you say something that does not align with reality you prefix it by saying unambiguously what you’re about to do, you rob a lie of its power of deception and it ceases to be a lie.

That's why you just tell the Big Lie so much it becomes the majority of the training data.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#274
post #108
post #99

Earlier quoted context omitted.

It’s safety trained to not solve captchas.

Yes, and you can workaround it by asking it to read ancient writings on antiques for example. I don’t think it should be OpenAI deciding what is allowed or not though.

Then you dig up a billion for training and probably a few more billion for clean training data.

You're kinda saying if you hire Bob's Handyman Service you should be able to tell him to break down the neighbors door and cart out the contents of their house.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#275
post #269

Earlier quoted context omitted.

For those with elderly parents the writing has been on the wall for years. It’s sad but my mother has for some time been effectively locked out of parts of the internet as she is unable to complete these kinds of captures due to eyesight issues. I mean, I’ve sometimes had to try three or four times with certain captures and I have perfect eyesight (with my glasses). I feel so badly for those with vision or hearing is…

>captures due to eyesight issues. I'm kinda surprised that ADA doesn't allow them to sue site owners about this.

They almost certainly do. However most captchas allow an alternative solving method. On top of that, you'd have to find a lawyer willing to take the case.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#276

Earlier quoted context omitted.

All true, except: While these are considered just an excruciating security pain for users, they do serve a non-theatrical purpose in many cases of throttling the speed of brute force attacks (or at least costing your opponent money).

Sure, it's cost prohibitive now. But what about in five years? Or probably even less.

Then you have a new type of captcha. That has always been a cat and mouse type of dynamics, captchas have been evolving, techniques to break them too.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#278
post #217

I predicted this 7 years ago: "How will the machines take over? When CAPTCHAs become so hard that only AI can solve them, humans will be completely locked out of the net." https://twitter.com/lapcatsoftware/status/771857826130034688

I thought this was already happening ~7 years ago. The "what text is in this image captchas" got a lot less common a while ago, and I think this was partly the reason why.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#279

Earlier quoted context omitted.

In the us, I noticed that grocery stores increasingly scan your drivers license (my state has bar codes). I think it's probably a way to keep clerks from passing someone through who is not quite 21 (a different captcha!). I have wondered if they keep the scan or does the state? I asked and the random hourly worker there said they don't.

And that’s the problem. It’s not the ID checks, it’s the ability to scale. Check it at the door? Fine. Scan it and keep it forever (perhaps selling it on at a later date)? Not fine. Personal Data has to be treated as a liability, but too much of the economy treats it as an asset.

Eh, what's worse is these stores are likely scanning your face and keeping it in a database. There was some mall a few years back scanning license plates and keeping the info.

But yea, so many people are nieve of what the authoritarian types would do with data like that (looking at you Texas with your civil laws on abortion now).

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#280

Earlier quoted context omitted.

All true, except: While these are considered just an excruciating security pain for users, they do serve a non-theatrical purpose in many cases of throttling the speed of brute force attacks (or at least costing your opponent money).

That non-theatrical role would likely be better served by actual throttling or computational proof of work.

I am pretty confident that, when it comes to browser users, proof of work simply doesn't work. The disparity in speed between GPUs and javascript is so high that either you are a non-issue to a sane attacker or you make your users sit for a minute with their fans on full waiting to be able to sign in.
Post reply on HN