Live data from Hacker News

Chess CAPTCHA

en.lichess.org

161–170 of 171 posts

Re: Chess CAPTCHA

#161
post #153

Earlier quoted context omitted.

Yes, an afternoon of coding to be able to post spam on exactly one website. Until they change the captcha.

So you are, literally, arguing for security by obscurity. "Oh, my captcha is unique, therefore nobody will bother". There are easier to implement unique captchas, than chess.

I'd agree partially, but I'd comment that it's also security by diversity. If every site had a unique captcha solution requiring custom software for a defeat, the force multiplier effect of "write once, run everywhere" would be hugely diminished, and it would be much less cost effective to implement various types of spam. So, the particular security strategy here is indeed weak, but I would say that it might actually strike closer to the root of the problem than just making a really hard, but still universally applied, captcha technology.

Re: Chess CAPTCHA

#162
post #43

Brilliant building of software. Less than brilliant copy. I would change Black plays; checkmate in one! This is a chess CAPTCHA. Click on the board to make your move, and prove you are human. to This is a chess CAPTCHA... To prove that you are human, click on a black piece, then click on the only destination square that will checkmate. I really don't mean to nitpick, but took me a minute to figure out what to do. Som…

"checkmate in one!" seems fairly clear to me.

Re: Chess CAPTCHA

#163
post #44
post #43

Brilliant building of software. Less than brilliant copy. I would change Black plays; checkmate in one! This is a chess CAPTCHA. Click on the board to make your move, and prove you are human. to This is a chess CAPTCHA... To prove that you are human, click on a black piece, then click on the only destination square that will checkmate. I really don't mean to nitpick, but took me a minute to figure out what to do. Som…

thanks for the feedback, I will apply the suggested change soon.

Are you lichess creator? Just wanted to congratulate you for the great peace of software you got there. IMHO is one of the best multi-player chess platforms out there. It is so straightforward and UX is amazing. The "analyze game" link after the end of the game is also very good.

Even though I am only a ~1200 ELO player, I play almost daily and enjoy your platform a lot :)

Re: Chess CAPTCHA

#164
post #153

Earlier quoted context omitted.

So you are, literally, arguing for security by obscurity. "Oh, my captcha is unique, therefore nobody will bother". There are easier to implement unique captchas, than chess.

I'd agree partially, but I'd comment that it's also security by diversity . If every site had a unique captcha solution requiring custom software for a defeat, the force multiplier effect of "write once, run everywhere" would be hugely diminished, and it would be much less cost effective to implement various types of spam. So, the particular security strategy here is indeed weak, but I would say that it might actuall…

You are not making any sense.

Re: Chess CAPTCHA

#165
post #134
post #104

Earlier quoted context omitted.

Out of curiosity: are there any known blind chess players? I guess it would be quite hardcore.

There are blind go players, so I assume blind chess players also exist.

I think blind chess is a lot easier than blind go. Apparently there are master-level blind chess players, while Sensei's Wiki mentions only a 26-kyu blind go player (i.e., around the level of somebody who has been playing for about a month).

Re: Chess CAPTCHA

#166
post #104
post #90

Earlier quoted context omitted.

I would change "a real user" with "a real user who doesn’t use a screen-reader". That’s less funny, but more accurate.

Out of curiosity: are there any known blind chess players? I guess it would be quite hardcore.

One of my friends spent his 2 years of military service in Israel playing chess -- up to 2 dozen chess games simultaneously, blind folded, against soldiers in the Israeli army. After his army service, he eventually ended up in grad school and later on became a professor. But more than his research papers, it is his chess playing that I remember.

Re: Chess CAPTCHA

#167
Though I like this a lot, as has been said, there are some obvious ways to crack it. There would be ways around this though, so as a proof of concept for one specific site it is pretty cool.

In order to contribute to the ways in which this can be 'broken', I present you with a brute force, not on the server, but on the chess game itself:

http://bookmarkify.it/114 (this is a bookmarklet, but you can also just copy-paste the code from the editor (scroll down) and paste it in your console).

Re: Chess CAPTCHA

#168
On a sunday, after a hung over weekend, I had a look at it for about a minute, tried a wrong move and gave up..

If that had been on the pizza delivery site then someone else would have got my order.

Re: Chess CAPTCHA

#169
post #153

Earlier quoted context omitted.

Yes, an afternoon of coding to be able to post spam on exactly one website. Until they change the captcha.

So you are, literally, arguing for security by obscurity. "Oh, my captcha is unique, therefore nobody will bother". There are easier to implement unique captchas, than chess.

Obscurity can be a great tool for security. But you have to understand its limitations, and expect at some point it will fail.

Custom captchas are probably a great use of this.

Re: Chess CAPTCHA

#170
I play a little chess, but I had lots of trouble distinguishing the king from the queen in this graphics. I've tried all the moves with no luck until I've understood that I've mistaken the king for the queen.
Post reply on HN