Why Captchas have gotten so difficult
theverge.com
Why Captchas have gotten so difficult
1–10 of 218 posts
Re: Why Captchas have gotten so difficult
#2I wonder how tracking-based captchas can be compatible with privacy regulations like the GDPR. Do you have to positively opt-in to a website seeing whether or not you're a robot?
We're basically moving towards a world where the venn diagram for the web and privacy no longer intersect.
Re: Why Captchas have gotten so difficult
#3The solution is to make captchas that are bespoke to each site, since it means the same bot or script can't be used on every one and spammers have to go out of their way to crack each one. You can already see this right now; sites with their own systems generally get no spam at all.
But given that most people aren't programmers, well it means they're stuck with mainstream captcha systems which present a giant target to the internet's never do wells.
Niche sites can avoid the issue with topic specific questions though.
Re: Why Captchas have gotten so difficult
#4A few days ago, I signed up for some service on a new-ish laptop, and it made me pass the storefront captcha three separate times.
This is yet another example of the social credit score being implemented in the US; in this case punishing users for opting out of continuous tracking (which will in turn be used for price discrimination or worse).
The good news is that this is almost certainly going to lead to a massive backlash as it becomes more common.
Re: Why Captchas have gotten so difficult
#5Re: Why Captchas have gotten so difficult
#6tbh I'm sick of just how often I have to solve those click-on-image captchas. It's a pain.
Re: Why Captchas have gotten so difficult
#7Re: Why Captchas have gotten so difficult
#8The issue isn't just that humans struggle with them or that bots are getting better or what not, it's because there's no way to make a captcha that works across multiple websites like a standard 'library' and expect it to remain uncracked. Anything that becomes common will be attacked and defeated, because there becomes a financial incentive for spammers and no gooders to do so. The solution is to make captchas that…
1. It's not feasible for various website to implement their own custom CAPTCHA formats. Building custom CAPTCHAs is a lot of work.
2. The custom CAPTCHA tasks wouldn't be that different from each other. As the article discusses, image/text/audio recognition are some of the only universal tasks that can work for CAPTCHA.
3. Nothing is stopping a malicious actor from implementing a "check which type of captcha" function and then selecting one of several CAPTCHA cracking functions. Fragmentation of CAPTCHA format just delays the cat and mouse game.
4. Some custom captchas, like the chess captcha, are actually not even that difficult for computers to solve. https://nakedsecurity.sophos.com/2013/03/12/chess-captcha/
Re: Why Captchas have gotten so difficult
#9> Malenfant says that five to ten years from now, CAPTCHA challenges likely won’t be viable at all. Instead, much of the web will have a constant, secret Turing test running in the background. I wonder how tracking-based captchas can be compatible with privacy regulations like the GDPR. Do you have to positively opt-in to a website seeing whether or not you're a robot? We're basically moving towards a world where the…
I’m down to about four sites now, and even those are beginning to look like they’re in doubt.
If I chart the trajectory of TV, and consider that much of what I do on the internet fills the void that TV once held, then I might completely drop the web from my list of time killing behaviors. Not impossible, since it’s pretty much a less convenient version of sitting on the couch, listlessly surfing hundreds of low quality cable channels with the remote control.
And of course, even TV is reaching an invasive climax too, these days. DVR set top boxes are worse than nielsen devices.
So, my spare time is mine to use as I wish, and we’ll see what I do with it...
Re: Why Captchas have gotten so difficult
#10Forcing users to prove their not bots is totally the wrong approach. They should be forcing bots to prove they're human so that real humans don't see this nonsense. Easier said than done, but that's not my problem.