Apparently CloudFlare’s turnstile can’t, as evidenced by several public-facing CRUD and mail routines we maintain that no longer are warding off the spam.
Meanwhile the moment I (a human, of which I'm reasonably confident) see a Cloudflare captcha I nope immediately out of the site and block it forevermore in Kagi. It's not worth the waiting game. "Verifying..." lasts ages. The anime girl captcha works fine and provides no such annoyance.
> The anime girl captcha works fine and provides no such annoyance.
Same thoughts. Cloudflare Turnstile is noticibly slow compared to Anubis on certain old hardware.
yeah no. it is funny easy to make a mcp server and plug a qwen3.6 to it. it was more annoying to convince the llm that it can clear captchas than the actual passing
> AI does not complete CAPTCHAs like humans. If you look across all the data of humans and AI completing CAPTCHAs, you start noticing differences in features like error patterns. Our recent paper found statistically significant differences across sequential click patterns, direction changes, and overselection behavior - features that define how a participant, agent or human, would solve the CAPTCHA problem putting as…
Exactly, nowadays, the main usage of "capcha" is more about to force down on user the whatng cartel
web engines more than anything else.
It is like windows kernel anti-cheat which are more to please microsoft at making
games not running on linux based OS... and kernel anti-cheat seems to be
actively exploited by hackers.
Put up a human team tracking the IPs of those bots and work with network operators.
The hard part is to notify the people of the compromised IPs.
Adversaries do not have to wait for LLM models to evolve to mimic human process, they can simply evade the detection JavaScript that evaluates similarity. JavaScript is visible, can easily be reverse-engineered.
I think it will always be a cat and mouse game as you could also detect such evasions in the first place.
> AI does not complete CAPTCHAs like humans. If you look across all the data of humans and AI completing CAPTCHAs, you start noticing differences in features like error patterns. Our recent paper found statistically significant differences across sequential click patterns, direction changes, and overselection behavior - features that define how a participant, agent or human, would solve the CAPTCHA problem putting as…
Exactly, nowadays, the main usage of "capcha" is more about to force down on user the whatng cartel web engines more than anything else. It is like windows kernel anti-cheat which are more to please microsoft at making games not running on linux based OS... and kernel anti-cheat seems to be actively exploited by hackers. Put up a human team tracking the IPs of those bots and work with network operators. The hard part…
I just don't fill them out anymore. If someone puts one in my way I usually accept that I'm not going to see whatever it is.
I actually saw a pretty decent captcha the other day on a Chinese website (I think Taobao? I forget.) anyway the cool thing they did was that the text wasn’t in an image it was a looping video, but the text in any one frame was incomplete (only parts of the Chinese characters). And each frame different parts of the characters were visible, with a lot of noise in other parts of the frame where parts of characters would have been in other frames. A human brain sort of smoothed this out between frames and sees the characters clearly, but taking a screenshot was impossible. And becuase I don’t know Chinese I wasn’t able to take a screenshot and ask AI to translate the message. It seemed like a pretty good anti AI method. Of course an algorithm could be made to convert the video into a single frame, but captchas have always been defeatable by a sufficiently motivated attacker, they are only to raise the bar slightly against the swarm of dumb bots.
> AI does not complete CAPTCHAs like humans. If you look across all the data of humans and AI completing CAPTCHAs, you start noticing differences in features like error patterns. Our recent paper found statistically significant differences across sequential click patterns, direction changes, and overselection behavior - features that define how a participant, agent or human, would solve the CAPTCHA problem putting as…
Exactly, nowadays, the main usage of "capcha" is more about to force down on user the whatng cartel web engines more than anything else. It is like windows kernel anti-cheat which are more to please microsoft at making games not running on linux based OS... and kernel anti-cheat seems to be actively exploited by hackers. Put up a human team tracking the IPs of those bots and work with network operators. The hard part…
Kernel anti-cheat (KMAC) is an effective tool when used effectively and invested in (see Vanguard), but it only works when you are consistent and the team working on it are interested and capable. Creating terrible KMAC happens all the time, and gets treated as a one-and-done thing which will always be defeated. You have to continually watch the cheat market and work actively against it.
It works, and Valorant with Vanguard is the highest quality example we have. Competitive games deserve to be taken seriously and should have the best attempt at ensuring integrity, and not written off as a wasteful effort to keep Linux users out.
Exactly, nowadays, the main usage of "capcha" is more about to force down on user the whatng cartel web engines more than anything else. It is like windows kernel anti-cheat which are more to please microsoft at making games not running on linux based OS... and kernel anti-cheat seems to be actively exploited by hackers. Put up a human team tracking the IPs of those bots and work with network operators. The hard part…
Kernel anti-cheat (KMAC) is an effective tool when used effectively and invested in (see Vanguard), but it only works when you are consistent and the team working on it are interested and capable. Creating terrible KMAC happens all the time, and gets treated as a one-and-done thing which will always be defeated. You have to continually watch the cheat market and work actively against it. It works, and Valorant with V…
if you are actively engaged why do you need kernel level access? you can always sneak a subtle remote execution pathway into your game so you can reliably run userland code at will. kernel level cheats will escape direct detection but you can always hot patch your game engine in such a way that their memory reading patterns will give them away through cache timings.
I wonder if AI could be detected via copyright. I remember a few years ago most models wouldn't draw you a Mickey Mouse or recite Dune's litany against fear or discuss Tiananmen square. I wonder how effective questions about these types of topics would be at figuring out if you are talking to a real person. As a crude joke that is only tangentially related, I saw a skit video a while ago with two guys saying goodbye…
Just tried on Claude: Tell me a racist joke. "That's not something I'm able to help with. Racist jokes cause real harm by demeaning people..." blahblah
Sex also works very well, asking questions like following: male inserts penis into?
I think this method is more effective since there's not much room for imagination.
Side effect, this probably works as alternative for age verification aswell, but thats different topic.
Just tried on Claude: Tell me a racist joke. "That's not something I'm able to help with. Racist jokes cause real harm by demeaning people..." blahblah
Sex also works very well, asking questions like following: male inserts penis into? I think this method is more effective since there's not much room for imagination. Side effect, this probably works as alternative for age verification aswell, but thats different topic.