Live data from Hacker News

The CAPTCHA arms race: from distorted text to browser identity

browserbase.com

11–20 of 60 posts

Re: The CAPTCHA arms race: from distorted text to browser identity

#13
post #2

They have been around that long ? Does not seem so but the timing could be correct probably because the sites I went to had no need for CAPTCHAs until AI came around.

The name wasn't invented until 2003, but yes.

Guestbooks, contact forms, signup pages, and the like started receiving automated abuse approximately five minutes after they were invented. It didn't take long after that for people to start including a question they expected to be easy for a person and hard to automate with a script.

What's relatively new is CAPTCHAs merely to browse a site. There are few faster ways to get me to close your site, and maybe send you an unfriendly email.

Re: The CAPTCHA arms race: from distorted text to browser identity

#14
post #8

Oh my good I hate AI articles. Why do we have to make an interactive visualization for every single sentence? Thanks for showing me how distorted text is made in steps. And being a cat and mouse game doesn’t mean the defenders failed.

> And being a cat and mouse game doesn’t mean the defenders failed. It does though, in the end attackers always win. If something is a "cat and mouse game" then it's unwinnable by design from the defender side. Sure, you can keep playing it if you feel like it, but at some point the attacker will be indistinguishable from a legitimate user and you will lose that fight.

By that logic, every security task is doomed to fail. Spam detection and antivirus are cat and mouse games too. I wouldn’t say they fail just because they have to adapt over time.

Re: The CAPTCHA arms race: from distorted text to browser identity

#15
TLDR: They're promoting a product they're working on with Cloudfare under the guise of it being an "open standard" [1]. Of course, in the docs, Step 1 is "Sign in with your Cloudfare account". Comes across a bit land-grabby.

[1] https://www.browserbase.com/blog/cloudflare-browserbase-pion...

Re: The CAPTCHA arms race: from distorted text to browser identity

#16
Omg. I am on various VPN’s and now and again Google Auth (for youtube) throws me a captcha. They are mostly unreadable, but there is an audio option… which is just insane and does not make any sense, anyone had that? It sounds like a recording of 300 people speaking at the same time in a call center while on various dosages of LSD

Re: The CAPTCHA arms race: from distorted text to browser identity

#18

Omg. I am on various VPN’s and now and again Google Auth (for youtube) throws me a captcha. They are mostly unreadable, but there is an audio option… which is just insane and does not make any sense, anyone had that? It sounds like a recording of 300 people speaking at the same time in a call center while on various dosages of LSD

They give you that (or hieroglyphics) if you are using certain VPNs and don't leave a specific browser fingerprint.

Re: The CAPTCHA arms race: from distorted text to browser identity

#19

Omg. I am on various VPN’s and now and again Google Auth (for youtube) throws me a captcha. They are mostly unreadable, but there is an audio option… which is just insane and does not make any sense, anyone had that? It sounds like a recording of 300 people speaking at the same time in a call center while on various dosages of LSD

I've got captchas that made me play a small game and I score like 3 points to go ahead, lol. For real.
Post reply on HN