Live data from Hacker News

I’m not a human: Breaking the Google reCAPTCHA [pdf]

blackhat.com

11–20 of 70 posts

Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]

#11
post #4

I don't get why, when and how Google uses reCAPTCHA within their own tools. E.g. within the Webmaster Tools, I can submit up to 500 URLs for manual fetch/render and subsequent index submission. So the rate limit is already there and reasonable. However, after 4 submitted URLs, I get a reCAPTCHA. From then on for every URL, I have to complete it with additionaly visual quizzes.

> I don't get why, when and how Google uses reCAPTCHA within their own tools. This may or may not help with your quest. Google triggers recaptcha when i use their search using one of my digitalocean servers as vpn and incognito mode, thus my IP address belongs to a datacentre, there isn't a cookie header and the user-agent is linux.

Thank you - I am using it absolutely genuine. The used account is in fact linked to an AdWords account which has spendings in the five digits...

Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]

#12

I don't get why, when and how Google uses reCAPTCHA within their own tools. E.g. within the Webmaster Tools, I can submit up to 500 URLs for manual fetch/render and subsequent index submission. So the rate limit is already there and reasonable. However, after 4 submitted URLs, I get a reCAPTCHA. From then on for every URL, I have to complete it with additionaly visual quizzes.

Another way they get triggered is when people use browser/desktop based rank checkers. There are also plugins some SEOs use to pull lots of requests. These tools are quite old now and not very useful, but people still use them.

Thanky you. I indeed han a chrome extension doing this. Removed and will check!

Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]

#14

I don't get why, when and how Google uses reCAPTCHA within their own tools. E.g. within the Webmaster Tools, I can submit up to 500 URLs for manual fetch/render and subsequent index submission. So the rate limit is already there and reasonable. However, after 4 submitted URLs, I get a reCAPTCHA. From then on for every URL, I have to complete it with additionaly visual quizzes.

I had the same thing the other day. I figured maybe it was because I was in incognito mode (because logging into half of Google's properties with uBlock and Privacy Badger enabled doesn't work). sigh

Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]

#16

I have a bad feeling CloudFlare is going to break the internet for Tor users with impossible-to-solve CAPTCHAs again after this...

Not that it can become much worse than it already is, though. The current reCAPTCHAS are already "fuck this shit"-inducing on Tor.

Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]

#17
post #2

You could also just pay a service that uses human workers in third world counties. It's a little over a tenth of a cent per captcha.

Or you could set up a pr0n site that shows the material only after the user has completed the captcha. This trick has been done before.

Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]

#18
post #2

You could also just pay a service that uses human workers in third world counties. It's a little over a tenth of a cent per captcha.

The author did compare their performance with captcha-solving services. His accuracy is comparable to the service with no extra cost to the attacker.

From the paper: "We compare our performance to that of Decaptcher, the (self-reported) oldest captcha-solving service. We selected Decaptcher for two reasons. First, it supports the image reCaptcha, charging $2 per 1000 solved captchas. [...] Interestingly, some of our summitted challenges rejected due to the service being overloaded, and had to be resubmitted at a later time, and received a time-out error as the solvers did not provide an answer in the time window allocated by the service. 258 challenges (36.85%) were an exact match. When taking into account the flexibility, 321 (44.3%) of the captchas were solved. The average solving time for the challenges that received a solution was 22.5 seconds. While the accuracy may increase over time as the human solvers become more accustomed to the image reCaptcha, it is evident that our system is a cost-effective alternative. Nonetheless, our completely offline captcha-breaking system is comparable to a professional solving service in both accuracy and attack duration, with the added benefit of not incurring any cost on the attacker."

Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]

#20
Quite interesting how the authors even mention that this strategy is very economically viable.

From the paper: 'Assuming a selling price of $2 per 1,000 solved captchas, our token harvesting attack could accrue $104 - $110 daily, per host (i.e., IP address). By leveraging proxy services and running multiple attacks in parallel, this amount could be significantly higher for a single machine.'

Post reply on HN