Live data from Hacker News

An Empirical Study and Evaluation of Modern CAPTCHAs

arxiv.org

281–290 of 338 posts

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#281

Earlier quoted context omitted.

I think a fairer solution will be some form of proof of personhood that isn't PoW-based. Your idea isn't bad but it gives more power to those who can afford a lot of devices. You know those Chinese mobile phone click farms they use to game app stores? It will be like that, PoW can prevent spam only to a certain degree and with all the social media and networks we have today there is a lot of money in influencing the…

But is it worth billions? You just need to increase the cost 1000 fold and pay it back after a holding period to implement that. The drawback is it gets a lot more complex when using a token, because of the additional state, communication, costs and security. A one shot proof of work can be very simple, but probably not effective enough, given that mobile users likely do not want to wait what may have to be many minu…

>Freezing a cent or a dollar for days seems like a better option. Might very well be that VISA/MasterCard figures this out before the crypto bros build anything usable. It will be far easier to do without decentralization and would also be great to spy on and control people.

Fucking A HN.

For any Juniors using this site, this is exactly what you don't post. Especially if it's just to cathart cynicism. I assure you, Poe's law guarantees this will find it's way into some PM's or exec's mind somewhere.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#282
post #131

Earlier quoted context omitted.

This just made me ponder again—where does the assumption that the Internet should allow unconstrained anonymity come from, other than that’s how it used to be for some time? The real world doesn’t allow that. It’s hard to remain anonymous in the real world. The real world largely runs on identity and (identity) trust. Why should the Internet be different?

The real world does allow it. People have been able to write anonymous letters and send them through the mail for a long time. Still can. No one checks my id before I stick an envelope in the mail box.

In the US that we know about.

I would not be surprised if there is some country that has a facial recognition camera network faced at mailboxes these days.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#283
post #44

Earlier quoted context omitted.

I still find it funny that Google, with the advantage of having millions of Internet users train their AI like galley slaves for free, hasn’t yet been able to crack vision driven self driving. Tesla had no such advantage when training their FSD to recognize traffic lights, bicycles, motorcycles, etc.

The tesla system is exciting and dangerous, because it does identify many things in the environment, but it's extremely unsafe because on city driving it will not make the right choice most of the time. On the freeway it does much better, but then that's a more restricted environment. I have an older tesla S with the pre-ai so called autopilot. It has one camera in the front and a radar and the system detects a few t…

Yea, that's the problem with self driving, especially in cities/dense areas. We really need AGI first. There are so many issues that humans react to before there is identifiable danger.

"Good" drivers see questionable situations and slow down or position themselves farther from potential issues before they get to the issue so they don't have to react at the last minute.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#284

Earlier quoted context omitted.

No thank you. I prefer to live by the code "Every request is a two way conversation. The client may accept, and the server may choose to emit." Just because I emit to other clients does not obligate me to emit to yours, any more than my emission of ads obligates you to accept and render them (but if you don't, or if you choose to ignore my CAPTCHAs, I may choose not to emit to you).

That's fighting a losing battle. Clients find their way around any restriction, which by itself risks your service or website losing ground and being overtaken by the alternatives.

Yes, it's all measure countermeasure. But you'll note that the most successful sites out there have bot protection and actively invest in it. I'm not concerned about the being overtaken narrative; My concern is the other scenario, where after the bots are done consuming and exfiltrating my data, I have no bandwidth to serve humans and my data is being vended from other sources now anyway.

It's also not really that much of a losing battle. Cloudflare will fight the battle for me quite well for free, and even better for a pittance.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#285
post #246

Earlier quoted context omitted.

All true, except: While these are considered just an excruciating security pain for users, they do serve a non-theatrical purpose in many cases of throttling the speed of brute force attacks (or at least costing your opponent money).

If I remember correctly, Google’s CAPCHA’s test isn’t in correctly identifying images, but the behavior of the runtime system (mouse jitter, for example) while the capcha is presented to the user. The image identification was not the real test and serves as training data. It has been like that for years. (But with agent-based behaviors from say, Q*, mouse jitter alone won’t help; there are probably other signals like…

I have occasionally wondered if they were fingerprinting users based on that mouse jitter. Most likely certain aspects of the mouse motion and timing would be unique.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#286
post #66

Does HN ever require CAPTCHAs? It seems to do pretty well with its basic but battle-tested moderation/antispam tools, and rate-limiting that seems to repel all but the most concerted DDoS attacks. I don't think HN has any unreasonable restrictions on scraping or third-party clients, either. And it manages to serve 5M unique visitors a month and 10M views a day[0]. [0] https://news.ycombinator.com/item?id=33454140

They go down somewhat frequently. I think it’s like four 9’s? I’m not sure why they insist on running just a few machines though. They have more than enough money and probably make up the difference by the advertising for YC that they get.

I mean, it works well enough the way it is. Does it need to be more reliable? It’s just a simple forum, there isn’t anything critical on the platform. We all like to see lots of 9s, but they don’t matter that much for something like HN.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#287

Earlier quoted context omitted.

Who pays for the bandwidth and download resources then?

It will be a business or personal expense, depending. Businesses that can't afford the expense will close or adapt, depending. Maybe fewer hobby projects will be launched.

Indeed.

Which is why my hobby projects will continue to use bot detection and CAPTCHA recognition. Especially since I'm routing through Cloudflare, so that's invisible for 99% of my users and the remaining 1% can just get off Tor if they're tired of solving the captions.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#288

I find captchas extremely painful, because of ambiguity and not loading all the pictures. I wait for a minute and some never show. When they do load, so manyare pics of bicycles and motorcycles and cross walks. Are you supposed to click on the tiny piece that goes tojust past another tile or not? You can't refresh one that doesn't load, I think most of them start over if you refresh. Like other people reported, if yo…

> Are you supposed to click on the tiny piece that goes tojust past another tile or not? I ask myself this every time.

Pretty sure the hesitation is what makes us humans :)

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#289

Earlier quoted context omitted.

That non-theatrical role would likely be better served by actual throttling or computational proof of work.

I am pretty confident that, when it comes to browser users, proof of work simply doesn't work. The disparity in speed between GPUs and javascript is so high that either you are a non-issue to a sane attacker or you make your users sit for a minute with their fans on full waiting to be able to sign in.

Would it be possible to conceive a proof-of-work that is difficult to parallelize, making it harder for GPU computing?
Post reply on HN