Live data from Hacker News

CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

pcgamer.com

121–130 of 143 posts

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#121
post #26

The problem with this paper is that, while technically true, there are many website owners who have found that CAPTCHAs have effectively reduced the spam on their site to zero. The fact that a CAPTCHA _can_ be bypassed doesn't mean that it _will_, and most spam bots are not using cutting-edge tech because that's expensive. To say "it's worthless from a security perspective" is a pretty harsh and largely inaccurate re…

Cutting edge tech like paying cents to captcha solving services?!

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#122

Wouldn't some sort of proof of work be a good solution to the captcha problem? Specially since all of the sudden, a bot service running hundreds of thousands of requests will suddenly and inadvertedly have to compute cryptographic hashes at the cost of the user running the bots?

no, because a lot of bot service run on botnets, made out of hacked regular residential computers, routers and so on. They will feel a bit more sluggish, but it won't cost the botnet authors that much more.

On the other side, an amount of work reasonable for modern desktop will absolutely overwhelm an older cell phone.

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#123
post #26

The problem with this paper is that, while technically true, there are many website owners who have found that CAPTCHAs have effectively reduced the spam on their site to zero. The fact that a CAPTCHA _can_ be bypassed doesn't mean that it _will_, and most spam bots are not using cutting-edge tech because that's expensive. To say "it's worthless from a security perspective" is a pretty harsh and largely inaccurate re…

Cutting edge tech like paying cents to captcha solving services?!

Yep. You'd be surprised how stupid some bots are.

(And while I don't have hard data on this, I suspect that bot authors that don't know how to properly set up rate-limits and don't know how to set up captcha solving service bypass, so captchas are especially effective against them)

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#124
post #60
post #47

Earlier quoted context omitted.

This automatically means that you're penalizing smaller websites. And killing off the independent alternatives to Reddit/Disqus. Do you want this? Large sites like Amazon or CNN can afford to eat the bot traffic. Smaller sites can't.

Did you read the article? What you said directly goes against the study's conclusion.

I can believe study's results on user interaction, but their "security analysis" section (6.2) is deeply flawed - it only looks at the best bots, and not at the average ones. Meanwhile, as many other people in this thread can attest, (1) most of the bots are not really sophisticated, and get stopped by CAPTCHa, (2) the defense does not have to be 100% efficient, as long as form spam goes from 100/day to 1/day, things are OK.

Of course authors really wanted to write their conclusion, so they just ignored all the practical considerations. It's really a shame on the part of paper's reviewers.

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#125

Earlier quoted context omitted.

While I get the draw, I never understood how PoW is ever supposed to work practically. PoW tasks are meant to work on a wide range of mobile phones, desktops, single-board computers, etc... you have vastly different compute budgets in every environment. For a PoW task that is usable on a five year old mobile phone, an adversary with a consumer RTX 50 series card (or potentially even an ASIC) can easily perform it man…

Perhaps you think all PoW algorithms are still crackable by ASICs? A few years ago that was the case, but some years ago Monero developers made a breakthrough with RandomX. Now it is no longer true that a GPU or ASIC can outperform a typical consumer device to the extent that you seem to imagine. The Tor project uses a similar algorithm, i think with the same developer contributing to it as RandomX. It is nothing lik…

Will RandomX work on the old cell phones, via Javascript interface only?

The website says: "Fast mode - requires 2080 MiB of shared memory. Light mode - requires only 256 MiB of shared memory, but runs significantly slower"

If you want your website challenge to work on the cheap phone - slow CPU, with little memory, and when implemented in Javascript, you'd have to tune complexity way down. And when a modern PC with fast CPU and tons of memory tries to solve it.. it probably will take only a few milliseconds, basically being useless.

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#126
post #35
post #6

What's the alternative?

I think we need to critically re-evaluate what is it exactly we are doing on the internet, how we do it, and examine existing assumptions. For instance, do we really need all services to be centralised? Do we really need services to be "free" (part of the payment is selling your data ok). A server serving static files doesn't care about bot users, but apps... why would you let a stranger use your cpu/ram over the int…

Who are "we" and what are "we" going to do with the answer once "we" come up with it?

For example, there is a someone's personal blog, which is beset by comment spammers. The blog's owner is tired of deleting spammy comments, and do not want their comment section to look like garbage bin, so they want some bot protection. The website's author is not that technical, so they do some googling and install reCaptcha (or cloudflare) and this cuts off bad comments to 1/week, which is easy to clean manually.

So in that story, who should be re-evaluating what, and what answer do you expect?

(keep in mind the blog's author cannot host their own captcha service / AI bot detector, as they are not proficient enough to install all the required dependencies for such a complex task, nor is their VPS powerful enough to keep it running.)

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#127

Earlier quoted context omitted.

Can't you just put a 5 second "loading bar" delay instead of a captcha then i wonder?

Not easily: if it's enforced client side it may as well not exist, if it's enforced server side you just let anyone lock anyone else out of their account by running a constant brute force attack against their account (a DoS vuln). It also does nothing for attackers who try a giant list of accounts but only one or two passwords for each. I worked on Google's system for solving this. It's a pretty sophisticated analysi…

> without bothering the real user, who won't be shown one.

bullshit

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#128
post #124
post #60

Earlier quoted context omitted.

Did you read the article? What you said directly goes against the study's conclusion.

I can believe study's results on user interaction, but their "security analysis" section (6.2) is deeply flawed - it only looks at the best bots, and not at the average ones. Meanwhile, as many other people in this thread can attest, (1) most of the bots are not really sophisticated, and get stopped by CAPTCHa, (2) the defense does not have to be 100% efficient, as long as form spam goes from 100/day to 1/day, things…

My thinking is that these days, the unsophisticated bots will still be stopped by literally any effort, like a hidden form field that causes the form to be rejected if it's filled in. Almost nothing will stop sophisticated bots, and nothing will stop a boiler room. This doesn't really leave a place for more sophisticated CAPTCHAs.

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#129

Naive question: how can clicking on the motorbike or traffic light image help to train an ML algorithm if they already know what image has a motorbike in it, or otherwise the captcha would not make sense. Maybe they put 3 image which are already with a score of >0.90 and one which is just 0.40?

> Naive question: how can clicking on the motorbike or traffic light image help to train an ML algorithm if they already know what image has a motorbike in it, or otherwise the captcha would not make sense.

It's more than just your answers that are fed into ML and more than just what others have already said: there's also the way that your browser functions and the way you interact with it. Your IP address, browser, OS, screen size, input type, timezone and current time of day, how fast do you select different images, etc etc. All of this gets fed into ML algorithms and answers to the obvious images are used as corollaries to support/deny your ancillary information.

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#130

Earlier quoted context omitted.

Not easily: if it's enforced client side it may as well not exist, if it's enforced server side you just let anyone lock anyone else out of their account by running a constant brute force attack against their account (a DoS vuln). It also does nothing for attackers who try a giant list of accounts but only one or two passwords for each. I worked on Google's system for solving this. It's a pretty sophisticated analysi…

> without bothering the real user, who won't be shown one. bullshit

Lots of signals used to prevent people seeing captchas when their passwords were being attacked, but you never see it so never think about it.
Post reply on HN