Bot operators can already pay human captcha solvers as the paper mentions. So all this does is potentially replace those humans with AI, driving down prices for bot operators. As prices for bot operators decrease, website operators will increase the challenge and drive up effort for the intended website audience (humans) who are solving captchas instead of paying bots. In the end, the website operators will have to s…
An Empirical Study and Evaluation of Modern CAPTCHAs
301–310 of 338 posts
Re: An Empirical Study and Evaluation of Modern CAPTCHAs
#302Submitters: If you want to say what you think is important about an article, that's fine, but do it by adding a comment to the thread. Then your view will be on a level playing field with everyone else's: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
Re: An Empirical Study and Evaluation of Modern CAPTCHAs
#303Earlier quoted context omitted.
I am pretty confident that, when it comes to browser users, proof of work simply doesn't work. The disparity in speed between GPUs and javascript is so high that either you are a non-issue to a sane attacker or you make your users sit for a minute with their fans on full waiting to be able to sign in.
Would it be possible to conceive a proof-of-work that is difficult to parallelize, making it harder for GPU computing?
Re: An Empirical Study and Evaluation of Modern CAPTCHAs
#304Earlier quoted context omitted.
They go down somewhat frequently. I think it’s like four 9’s? I’m not sure why they insist on running just a few machines though. They have more than enough money and probably make up the difference by the advertising for YC that they get.
I mean, it works well enough the way it is. Does it need to be more reliable? It’s just a simple forum, there isn’t anything critical on the platform. We all like to see lots of 9s, but they don’t matter that much for something like HN.
Re: An Empirical Study and Evaluation of Modern CAPTCHAs
#305Earlier quoted context omitted.
The real world does allow it. People have been able to write anonymous letters and send them through the mail for a long time. Still can. No one checks my id before I stick an envelope in the mail box.
In the US that we know about. I would not be surprised if there is some country that has a facial recognition camera network faced at mailboxes these days.
Even then, here is literally the first post box I found looking in the UK, in a small town: https://www.google.com/maps/@52.0936599,0.0761217,3a,75y,165... . No CCT in sight, no power, good solid iron.
Plus, think of how difficult it is to match a person to the physical envelope.
At best there could be a distinctive envelope.
Otherwise, yes, you can get a list of people who use the box. But for that to be useful, the mail from different boxes can't simply be jumbled together into the same pickup bag as that would broaden the number of suspects.
Re: An Empirical Study and Evaluation of Modern CAPTCHAs
#306Re: An Empirical Study and Evaluation of Modern CAPTCHAs
#307Earlier quoted context omitted.
Amusingly the infotainment system in our Model Y actually crashed on the way home tonight, and when it rebooted it decided to install the update then, while driving. Sent me a notification on my phone immediately afterwards. To be fair, the updates don't usually go that way.
Wow, that never happened to me and is unacceptable. Was that for the infotainment only or the drive train? Just for others, they are separate systems, you can even safely reboot the infotainment (main display with maps, music etc) if you need to while driving, as it doesn't affect the drive train. I'm guessing it was not the drive train which would be incredibly dangerous.
Re: An Empirical Study and Evaluation of Modern CAPTCHAs
#308Earlier quoted context omitted.
But you can't send in 1000 people per second into most establishments you visit either. It's not an apt comparison.
What does the number/second have to do with 'It’s hard to remain anonymous in the real world. The real world largely runs on identity and (identity) trust.'? There are very few places in the real world which can handl 1,000 people per second. In the real world I rarely need to identify myself. I can see a movie, visit the library, buy groceries, go to a restaurant, and more.
Hobest question, are you being serious here? The sxale of fraud and automated traffic is disproportionately large, and has a significantly lower barrier to entry than other forms of abuse. That's the entire reason.
> There are very few places in the real world which can handl 1,000 people per second.
Exactly, and if someone started sending thousands of people per second there, they would make it significantly more difficult to do so.
Re: An Empirical Study and Evaluation of Modern CAPTCHAs
#309My pet theory is that our whole simulated world is actually a huge captcha. Captchas keep evolving until you have to live an entire lifetime as a human to prove that you're a human. When you die you wake up and get access to a website.
Re: An Empirical Study and Evaluation of Modern CAPTCHAs
#310Coincidentally Worldcoin is up 30% today. Maybe cryptographic/biometric proof of being a human will be useful after all?
No thanks, I'd rather not live in a dystopian nightmare where Sam Altman is in control of assigning proof of humanity. Worldcoin will undoubtedly end up assigning identities to AIs for profit anyway, and/or there will be swaths of identities being sold on the black market.