Live data from Hacker News

An Empirical Study and Evaluation of Modern CAPTCHAs

arxiv.org

171–180 of 338 posts

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#171
Bot operators can already pay human captcha solvers as the paper mentions. So all this does is potentially replace those humans with AI, driving down prices for bot operators.

As prices for bot operators decrease, website operators will increase the challenge and drive up effort for the intended website audience (humans) who are solving captchas instead of paying bots.

In the end, the website operators will have to stop using captchas as the intended website audience will no longer be willing to solve harder captchas.

Website operators can use alternatives, like asking for micro-payments, high enough to discourage most bot operators.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#172
post #8
post #7

I think captchas disappear next year or so. Already was soft human determination.

What replaces captchas? Are there any not excessively burdensome tests that a standard issue human can pass that a machine somehow cannot? I'm assuming the "find all the bicycles" tests are also obsolete.

Option 1: Micropayments, high enough to discourage bot operators but not the intended human audience will be better for website operators as soon as it becomes too easy for AI to solve captchas.

If website operators don't explicitly introduce micropayments as a captcha alternative, there will be browser plugins that outsource captcha solving to AI for a micropayment, which has the same effect.

Option 2: Using a means of authentication that can't be obtained cheaply at scale by bots, e.g. Twitter accounts, Gmail accounts, government ID, ...

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#173
post #26

Someone will get rich turning this into a browser plug-in.

Nope, the moment this becomes a viable solution then spammers will pick it up, making captcha useless amost overnight. Websites will very quickly pivot to alternative solutions like payment card verfification, etc.

The spammers can already do this with captcha farms. The fact that captchas are still around means that the cost of captcha farms are still high enough to discourage enough spammers to be worth the annoyance that website operators cause for human users.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#174

As best as I can tell this study explores many facets of how humans solve captchas. I couldn't find anything about AIs outperforming humans in the study. Can someone give me a section reference? Solving reCAPTCHA v2/v3 requires more than just clicking the box and an image puzzle. If that was all it was we would be overrun by now. Lots of folks commenting that the title's statement makes sense because CAPTCHAs are mea…

It's in Table 3.

Thank you. The data in that table (for reCAPTCHA, citation 63) is from another paper from 2016 which is focused on solving the actual user-presented problems. It doesn't (directly at least) say they achieved a reliable automation of captcha acceptance, though.

https://ieeexplore.ieee.org/document/7467367

From the abstract:

> Through extensive experimentation, we identify flaws that allow adversaries to effortlessly influence the risk analysis, bypass restrictions, and deploy large-scale attacks. Subsequently, we design a novel low-cost attack that leverages deep learning technologies for the semantic annotation of images.

I'd suspect reCaptcha has been updated in the 7 years since to address shortcomings.

Another entry in the table (citation 45) is from 2020 and talks about using an object detection AI to solve the image tests. This again looks like it's focused on the task, not the primary mechanism (behavioral analytics).

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#175

I guess validating a payment card is going to be the next step to sign up for whatever. Don’t allow pre paid BINs and let’s go. Gonna be pretty miserable, however someone needs to find something as I currently would rather pay 0.01$ instead of solving a captcha. Especially the select all the bicycles; it’s a waste of life.

Please. Last time I had to solve a captcha it was wasted 15 minutes (not exaggerating!) of my life, clicking on an endless stream of bikes, motorcycles, buses and stoplights. As punishment for using a vpn.

I don't even use a VPN, just a browser that blocks fingerprinting by default. My interpretation of CAPTCHA hell is, "oh, you don't want me to spy on you! Here, let's put some pain in the skinner box."

(Amusingly, pain was proven to be preferable to boredom... and CAPTCHAS are boring as hell.)

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#176

I guess validating a payment card is going to be the next step to sign up for whatever. Don’t allow pre paid BINs and let’s go. Gonna be pretty miserable, however someone needs to find something as I currently would rather pay 0.01$ instead of solving a captcha. Especially the select all the bicycles; it’s a waste of life.

At this point the amount of friction added to all these things is pushing things towards just not doing them in the first place (buying less stuff, using social media less). Nature walks and paper books doesn't have captchas.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#177
post #150

Earlier quoted context omitted.

> they do serve a non-theatrical purpose in many cases of throttling the speed of brute force attacks Might do that unobtrusively for the average person, by using projects like mCaptcha [0] for instance. [0] https://mcaptcha.org/

Is it similar to https://friendlycaptcha.com/ ?

It’s funny how they have a section with three human avatars and one robot, with green checkmarks on the humans, yet those faces look AI-generated.

Re: An Empirical Study and Evaluation of Modern CAPTCHAs

#180
post #131
post #119

Earlier quoted context omitted.

EU digital ID, asking for mobile number and sending text, so something that is linked to an ID and/or costs money to have. Goodbye anonimity, probably.

This just made me ponder again—where does the assumption that the Internet should allow unconstrained anonymity come from, other than that’s how it used to be for some time? The real world doesn’t allow that. It’s hard to remain anonymous in the real world. The real world largely runs on identity and (identity) trust. Why should the Internet be different?

Because there is a real demand for staying anonymous online. You'd know why, if you lived in a country taken over by a fascist regime.
Post reply on HN