Live data from Hacker News

An Empirical Study and Evaluation of Modern CAPTCHAs

arxiv.org

301–310 of 338 posts

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#301

Bot operators can already pay human captcha solvers as the paper mentions. So all this does is potentially replace those humans with AI, driving down prices for bot operators. As prices for bot operators decrease, website operators will increase the challenge and drive up effort for the intended website audience (humans) who are solving captchas instead of paying bots. In the end, the website operators will have to s…

Micropayments is not possible when stripe/visa/paypal charge a 30 cents minimum fee

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#302
Submitted title was "AI bots are now outperforming humans in solving CAPTCHAs", which broke HN's title rule: "Please use the original title, unless it is misleading or linkbait; don't editorialize."

Submitters: If you want to say what you think is important about an article, that's fine, but do it by adding a comment to the thread. Then your view will be on a level playing field with everyone else's: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#303

Earlier quoted context omitted.

I am pretty confident that, when it comes to browser users, proof of work simply doesn't work. The disparity in speed between GPUs and javascript is so high that either you are a non-issue to a sane attacker or you make your users sit for a minute with their fans on full waiting to be able to sign in.

Would it be possible to conceive a proof-of-work that is difficult to parallelize, making it harder for GPU computing?

There are PoW systems which are designed to be difficult to run on ASICs, but modern GPUs can generally run them. Even if you find one that has to run on CPU, these kind of functions will still be much faster running in native code than in js/wasm.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#304

Earlier quoted context omitted.

They go down somewhat frequently. I think it’s like four 9’s? I’m not sure why they insist on running just a few machines though. They have more than enough money and probably make up the difference by the advertising for YC that they get.

I mean, it works well enough the way it is. Does it need to be more reliable? It’s just a simple forum, there isn’t anything critical on the platform. We all like to see lots of 9s, but they don’t matter that much for something like HN.

That’s fair. To clarify my frustration comes from a place of “love”. When a partial or complete outage happens I get severe HN withdrawals.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#305
post #282

Earlier quoted context omitted.

The real world does allow it. People have been able to write anonymous letters and send them through the mail for a long time. Still can. No one checks my id before I stick an envelope in the mail box.

In the US that we know about. I would not be surprised if there is some country that has a facial recognition camera network faced at mailboxes these days.

Yes, the UK has a lot of CCTs. But that's relatively new, and certainly after the idea that the Internet should allow anonymous or pseudonymous use.

Even then, here is literally the first post box I found looking in the UK, in a small town: https://www.google.com/maps/@52.0936599,0.0761217,3a,75y,165... . No CCT in sight, no power, good solid iron.

Plus, think of how difficult it is to match a person to the physical envelope.

At best there could be a distinctive envelope.

Otherwise, yes, you can get a list of people who use the box. But for that to be useful, the mail from different boxes can't simply be jumbled together into the same pickup bag as that would broaden the number of suspects.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#307

Earlier quoted context omitted.

Amusingly the infotainment system in our Model Y actually crashed on the way home tonight, and when it rebooted it decided to install the update then, while driving. Sent me a notification on my phone immediately afterwards. To be fair, the updates don't usually go that way.

Wow, that never happened to me and is unacceptable. Was that for the infotainment only or the drive train? Just for others, they are separate systems, you can even safely reboot the infotainment (main display with maps, music etc) if you need to while driving, as it doesn't affect the drive train. I'm guessing it was not the drive train which would be incredibly dangerous.

Yeah, it didn't affect the drive train, and it was also quite quick - less than a minute between when the screen went dark and when it had finished rebooting and sent notifications that an update had been installed. So presumably just an infotainment update as you said; I didn't try to dig into exactly what the update included though.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#308

Earlier quoted context omitted.

But you can't send in 1000 people per second into most establishments you visit either. It's not an apt comparison.

What does the number/second have to do with 'It’s hard to remain anonymous in the real world. The real world largely runs on identity and (identity) trust.'? There are very few places in the real world which can handl 1,000 people per second. In the real world I rarely need to identify myself. I can see a movie, visit the library, buy groceries, go to a restaurant, and more.

> What does the number/second have to do with 'It’s hard to remain anonymous in the real world. The real world largely runs on identity and (identity) trust.'?

Hobest question, are you being serious here? The sxale of fraud and automated traffic is disproportionately large, and has a significantly lower barrier to entry than other forms of abuse. That's the entire reason.

> There are very few places in the real world which can handl 1,000 people per second.

Exactly, and if someone started sending thousands of people per second there, they would make it significantly more difficult to do so.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#309
post #306

My pet theory is that our whole simulated world is actually a huge captcha. Captchas keep evolving until you have to live an entire lifetime as a human to prove that you're a human. When you die you wake up and get access to a website.

So that's what 42 was for!

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#310
post #268

Coincidentally Worldcoin is up 30% today. Maybe cryptographic/biometric proof of being a human will be useful after all?

No thanks, I'd rather not live in a dystopian nightmare where Sam Altman is in control of assigning proof of humanity. Worldcoin will undoubtedly end up assigning identities to AIs for profit anyway, and/or there will be swaths of identities being sold on the black market.

Well - there doesn't have to be a Sam + Worldcoin monopoly on these things. Anyone else could launch a similar proof / ID system and websites and the like could accept any they feel like accepting.
Post reply on HN