Live data from Hacker News

The CAPTCHA arms race: from distorted text to browser identity

browserbase.com

1–10 of 60 posts

Re: The CAPTCHA arms race: from distorted text to browser identity

#4
post #2

They have been around that long ? Does not seem so but the timing could be correct probably because the sites I went to had no need for CAPTCHAs until AI came around.

They were introduced in 1997, although I personally didn't start seeing them until a couple of years later.

Re: The CAPTCHA arms race: from distorted text to browser identity

#7
post #2

They have been around that long ? Does not seem so but the timing could be correct probably because the sites I went to had no need for CAPTCHAs until AI came around.

So in the past few years? Oh dear, no. Captchas have been in common use for much longer than that. reCAPTCHA has been around almost 20 years.

Re: The CAPTCHA arms race: from distorted text to browser identity

#8

Oh my good I hate AI articles. Why do we have to make an interactive visualization for every single sentence? Thanks for showing me how distorted text is made in steps. And being a cat and mouse game doesn’t mean the defenders failed.

> And being a cat and mouse game doesn’t mean the defenders failed.

It does though, in the end attackers always win. If something is a "cat and mouse game" then it's unwinnable by design from the defender side.

Sure, you can keep playing it if you feel like it, but at some point the attacker will be indistinguishable from a legitimate user and you will lose that fight.

Re: The CAPTCHA arms race: from distorted text to browser identity

#10
post #5

Question that I've been wondering, can't attackers record human sessions and use it to attack a website to bypass cloudflare ?

They can. They have already figured out a lot of what cloudflare is looking for and have figured out how to bypass it. (according to the article) Which is why protection is trying something else. I suppose this is why every website wants me to login with my google account (which I never use)
Post reply on HN