Live data from Hacker News

An Empirical Study and Evaluation of Modern CAPTCHAs

arxiv.org

311–320 of 338 posts

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#311

Earlier quoted context omitted.

It will be a business or personal expense, depending. Businesses that can't afford the expense will close or adapt, depending. Maybe fewer hobby projects will be launched.

Indeed. Which is why my hobby projects will continue to use bot detection and CAPTCHA recognition. Especially since I'm routing through Cloudflare, so that's invisible for 99% of my users and the remaining 1% can just get off Tor if they're tired of solving the captions.

You are welcome to do so, but if spammers can break the captchas, then you only annoy your normal visitors.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#312
post #246

Earlier quoted context omitted.

If I remember correctly, Google’s CAPCHA’s test isn’t in correctly identifying images, but the behavior of the runtime system (mouse jitter, for example) while the capcha is presented to the user. The image identification was not the real test and serves as training data. It has been like that for years. (But with agent-based behaviors from say, Q*, mouse jitter alone won’t help; there are probably other signals like…

I have occasionally wondered if they were fingerprinting users based on that mouse jitter. Most likely certain aspects of the mouse motion and timing would be unique.

No doubt they are. Google CAPTCHA isn't really about whether or not the user is a human but about which human they are. Enabling Firefox's fingerprinting resistance turns Google's CAPTCHA into the Allied Mastercomputer.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#313
post #150

Earlier quoted context omitted.

> they do serve a non-theatrical purpose in many cases of throttling the speed of brute force attacks Might do that unobtrusively for the average person, by using projects like mCaptcha [0] for instance. [0] https://mcaptcha.org/

Oh what a perfect find. I have on my todolist to add POW to some of my api endpoints

I'm not sure whether that's genius or horrifying. On the one hand, that could form the micropayments network the web always needed. On the other hand, it would enable quite a bit of abuse on its own.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#314

Earlier quoted context omitted.

These sites like 2captcha and deathbycaptcha let anyone sign up to be a worker and start solving captchas for $$. If you can run AI that solves captcha just as well, you can literally print money.

2captcha gives you $0.50 per "1-2 hours". Is that really worth all the work? deathbycaptcha does not let anyone simply sign up to work.

> 2captcha gives you $0.50 per "1-2 hours". Is that really worth all the work?

That's rough, but you could scale it up I guess. Didn't know that about dbc, thank you.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#315

Earlier quoted context omitted.

They almost certainly do. However most captchas allow an alternative solving method. On top of that, you'd have to find a lawyer willing to take the case.

Oh ADA lawyers are a dime a dozen. There’s entire cottage industries of finding ADA violations to sue over. The issue is more finding companies to sue that can’t afford to fight back.

I don’t know about that. When I was 18, I was diagnosed with multiple sclerosis, and received a sudden and unexpected demotion from a job with a small regional restaurant franchise that was previously flourishing, and then found myself unemployed a few weeks later, just days before my benefits package was due to be activated.

I contacted several attorneys, none of whom would consider taking the case, or even bother to discuss the details with me. One of them told me that, at least in North Carolina, an employer would effectively have to get on the stand and explicitly confess taking adverse actions against me specifically because I had been diagnosed with MS. Any other remotely plausible excuse would provide them with all the cover necessary.

It was only much later that I learned that I would have had to have filed a complaint with the EEOC and NLRB within 180-days, and allow them to investigate my claims fully before authorizing such a lawsuit to begin with, as without such a determination I could not file the suit anyway. None of the attorneys I consulted even mentioned this absolutely critical first step, which suggests that they had even less faith in a successful outcome.

Maybe it’s different for facilities and regulatory enforcement, but in my experience, at least for labor, the protections are incredibly weak.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#316
post #76

Earlier quoted context omitted.

The next step is device attestation. IIRC Safari already does this, so you should not see captcha on places that support it. Something that can work on any browser can be like this: Scan the QR code in your iPhone or Android device that supports attestation. Will ask you if you approve login, then will attest for you. If you turn out to be a bad actor, the website can ban this device - so no flooding with a single de…

There are over a billion Idevices out there. Malware on just 1% of them can make and control 10 million spam accounts on every site using device attestation, and they're indistinguishable from real users.

Attestation covers much more than the device itself. The whole point is that it establishes there's a chain of trust from the hardware itself to the software being executed. Your average malicious flashlight app might be able to generate valid attestation tokens, but it'll be differentiable from attestation tokens from safari. If you can somehow break this chain of trust, there's way better ways of monetizing this (eg. selling spyware to nation states) than creating a bunch of fake accounts.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#317

I wish captcha providers universally had to provide a way to shut down their use by bad actors. Here in Canada I get tons of scam texts pointing me to a fake banking or postal service website asking me to pay a fake bill. I want to ddos them with fake payment data but they’re all protected by hcaptcha.

If you report the website/sitekey to hCaptcha support it'll get banned pretty quickly.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#318

Earlier quoted context omitted.

What does the number/second have to do with 'It’s hard to remain anonymous in the real world. The real world largely runs on identity and (identity) trust.'? There are very few places in the real world which can handl 1,000 people per second. In the real world I rarely need to identify myself. I can see a movie, visit the library, buy groceries, go to a restaurant, and more.

> What does the number/second have to do with 'It’s hard to remain anonymous in the real world. The real world largely runs on identity and (identity) trust.'? Hobest question, are you being serious here? The sxale of fraud and automated traffic is disproportionately large, and has a significantly lower barrier to entry than other forms of abuse. That's the entire reason. > There are very few places in the real world…

I honestly don't understand how your point is relevant.

Most of the real world does not require identity, so how does "The real world doesn’t allow that" make any sense?

Yes, some parts of the real world require you to identify yourself, and the same for some places on the internet.

Is that really the point? That if you have to use your real identify to log into your bank's web site that you don't have "unconstrained anonymity"?

Because I don't think even the cryptopunks of the 1990s required that sort of anonymity.

> and if someone started sending thousands of people per second

So, 100/second is okay but 1,000/second not okay?

I ask because it looks like 100 people per second enter Manhattan during the peak morning commute time, and I don't see massive calls to make it harder for commuters to enter the borough. (Go to http://manpopex.us/ , go to statistics, "Estimated Pop. for Wednesday, 9 AM: 2,888,116", for "10 AM: 3,284,591" gives 110 people per second.)

And these people aren't all required to identify themselves.

Question for you: does the internet currently have more anonymity than the real world?

Question #2: how much fraud is done on the internet vs. fraud in the real world, measured by dollars?

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#319
post #63
post #44

Earlier quoted context omitted.

I still find it funny that Google, with the advantage of having millions of Internet users train their AI like galley slaves for free, hasn’t yet been able to crack vision driven self driving. Tesla had no such advantage when training their FSD to recognize traffic lights, bicycles, motorcycles, etc.

> hasn’t yet been able to crack vision driven self driving But they have? For years Google Street view has read signs, house numbers, phone numbers of businesses, etc. from the environment. It is safe to assume they have this built into Waymo as well. I assume you might be trying to reference "vision only" self-driving, which is a fantasy made up by Elon Musk because nobody would sell him LiDAR sensors cheaply. https…

This is a meme.

“Sour grape Elon, touting vision because no one will sell him LiDAR sensors. Which are the gold standard sensors that solve self driving.”

How exactly does LiDAR tell you whether the thing in question can move (dog) or not (trash can)? How does it allow a neural net to infer intent?

You’ll actually have to solve vision. Even if you had LiDAR. There’s no way around it. And once you’ve solved it, LiDAR becomes superfluous.

Chesterton’s fence.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#320

Earlier quoted context omitted.

Oh ADA lawyers are a dime a dozen. There’s entire cottage industries of finding ADA violations to sue over. The issue is more finding companies to sue that can’t afford to fight back.

I don’t know about that. When I was 18, I was diagnosed with multiple sclerosis, and received a sudden and unexpected demotion from a job with a small regional restaurant franchise that was previously flourishing, and then found myself unemployed a few weeks later, just days before my benefits package was due to be activated. I contacted several attorneys, none of whom would consider taking the case, or even bother t…

This is more ADA title I. Typically for Title III ADA lawyers troll small businesses looking for accessibility issues like lack of ramp, and have a stable of disabled clients who will file against the businesses. Since the businesses can’t generally afford to context or pay fines they’ll settle quickly and remediate, or a non trivial amount of the time get run out of business (if for instance the remediation costs a non trivial amount to pull off). I’m not judging bad or good, here, it is what it is and perhaps it’s the right outcome to allow for general accessibility.
Post reply on HN