Live data from Hacker News

Worst CAPTCHA Ever

svedic.org

141–150 of 169 posts

Re: Worst CAPTCHA Ever

#141
post #44

Earlier quoted context omitted.

I still loathe reCAPTCHA more than any other captcha out there. I've given up hopes of logging in on many occasions simply because of it. Looks like it's designed for not to be deciphered either by humans or computers.

I totally agree, see this recaptcha which is upside down, how are we supposed to read it http://postimg.org/image/7xgovvhij/

NSFW ads on this link...

Re: Worst CAPTCHA Ever

#142

One of my buddies worked in the accounting department at our state government. He needed to get a bunch of documents from another agency (like hundreds every month) to process claims. Well this other agency requires everyone to go through their website and download each document one at a time. They said it was to prevent abuse. For some reason they couldn't just send a batch of them to us, even a fellow state agency.…

Isn't that one ambitious DA away from being a felony these days?

no, as I understand, that part alone would be a misdemeanor (and therefore, unlikely to be worth pursuing) under the CFAA. the alleged intent to sell/defraud is what made it a potential felony.

Re: Worst CAPTCHA Ever

#143

One of my buddies worked in the accounting department at our state government. He needed to get a bunch of documents from another agency (like hundreds every month) to process claims. Well this other agency requires everyone to go through their website and download each document one at a time. They said it was to prevent abuse. For some reason they couldn't just send a batch of them to us, even a fellow state agency.…

Isn't that one ambitious DA away from being a felony these days?

[deleted]

Re: Worst CAPTCHA Ever

#144
My company got a couple of emails from a "credit advisor" Stacy at D&B with no subject. Then in the third email, from the same person... the email was typed out in the subject and there was no body. facepalm

Re: Worst CAPTCHA Ever

#145
post #78
post #22

Earlier quoted context omitted.

It's not an uncommon strategy (eg: fill up a comment form with hidden but obviously named form fields) and since people won't be filling in those hidden fields then bots will have revealed themselves. This isn't by any means a complete solution however it does catch 90% of drive-by spam.

That's an interesting approach, but I guess as soon as it would become mainstream, the bots would adapt without many problems.

Depending on how the fields were hidden, they may need to render and reflow html, css and dom changes by javascript.

None of which is all that difficult for a full size browser, but it may be prohibitively resource intensive for a high-volume spam bot.

Re: Worst CAPTCHA Ever

#146
post #13

Earlier quoted context omitted.

It doesn't matter though. This isn't just a 'stupid mistake' made by a dev rushed for time, this is literally 'not a captcha.' It's not. Not even a poorly designed and incompetently executed captcha... it just isn't even one at all. It doesn't take long to find out that best practices exist for captchas, what they are, what the typical vulnerabilities are, and then pick one from the top shelf of existing solutions on…

With hindsight, sure. But that's not looking at the whole picture. The problem is not how much effort to stop this one mistake, the problem is how much effort to stop every potential mistake of similar importance to this . Or worse, perhaps they did get this from a shelf of existing solutions.

>Or worse, perhaps they did get this from a shelf of existing solutions.

I'd like to believe that was impossible but of course given how irrational it would be to go through the trouble of making this, it's probably likely. Though I don't know why you'd necessarily skip over recaptcha and securimage and how far down the list you'd have to go to get to this sort of thing... but ZeljkoS has a couple more examples like it on his site. So apparently it's a captcha anti-pattern.

Re: Worst CAPTCHA Ever

#147
post #138

This should give you a really good idea what it's like trying to get a DUNS number (a requirement for doing contract work with the government as a business). Their entire business is basically the front-end to a scam. Somebody pulled a network contact to wedge their company in between businesses and the federal government. You are guaranteed to get scammy-sounding emails and phone calls from D&B after signing up. Ema…

They have the same slimy up sell tactics as every other credit reporting agency, but the core business is far from a scam.

The startup crowd doesn't see it much, but D&B is a critical component of how non-technical medium to large businesses vet each other and prevent fraud. They are effectively the Better Business Bureau for B2B.

Re: Worst CAPTCHA Ever

#148
post #138

This should give you a really good idea what it's like trying to get a DUNS number (a requirement for doing contract work with the government as a business). Their entire business is basically the front-end to a scam. Somebody pulled a network contact to wedge their company in between businesses and the federal government. You are guaranteed to get scammy-sounding emails and phone calls from D&B after signing up. Ema…

It's not just contract work with the government. Once you are a business of sufficient size it's almost inevitable that you'll run into some random thing where you're required to have a DUNS number before proceeding (and it's always unclear why this is a requirement). So dumb.

Re: Worst CAPTCHA Ever

#150
D&B is in the business of selling your corporate data to marketing companies. They claim that they never share their data base in an automated way, and to protect this information, so that it is only human readable but it is in their best interest to let companies have access. Likely this is there to allow miners, not specifically because they are incompetent, but because they are dishonest.
Post reply on HN