Goodbye (Crummy) CAPTCHAs. Hello Ad Dollars?
mediamemo.allthingsd.com
mediamemo.allthingsd.com
for the solution I put in 'stupid', and it worked
this definitely doesn't solve the security considerations that captchas were designed for.
Update: Ok so it didn't take long to break this thing. These guys have the plain text of the CAPTCHA in the document DOM. It isn't even an image - the CAPTCHA is rendered in javascript. See: http://imgur.com/9VO4J.png
The 'brand' logos are an image, but they are simple to OCR.
So to break this CAPTCHA, simply hook v8 up to your auto-submit bot and interpret the JS that is being returned to you. You can't read it from the client because they serve that IFRAME from a diff domain - so they base their security on the browser x-domain policy. But that is all moot if you are building a bot, or if you build a browser extension that solves these things.
Problem with those are that they need to be constantly updated from a reliable source, or else, once the solution becomes popular, the spammer can bruteforce it in linear time (no matter how high N is, there are only N possible patterns).
This seems to be an attempt at fixing this. Ads are often relatively short lived so by the time the spammer has them bruteforced, it might be out of circulation - and more importantly, there are new ads in. It's an armsrace, and this is a way to pay our troops. Also, it's trivial for advertisers to make many different variations (e.g. one for each sales bulletpoint), so there are many variations in circulation. Since there's often more textual content than the password in the ad, they're not prone to simple OCR, while still easy to comprehend for the user.
Obvious shortcomings are if ads are not so shortlived, and if it's easy to identify and break classes of ads (e.g. if it's yellow and has the IE logo in position X, OCR area Y, done). Also, it's a bit of a dealbreaker if I'm forced to open and visit a website to get the password.
> show a picture of an animal or a shape and ask what it is,
Ok, so let's say you come up with pictures of 20 different animals. A spam script that picks the same answer every time will have a 5% success rate.
> or even just ask a simple math problem or riddle in writing.
Computers are way better at solving most math problems than people.
If you display 10 random animals (or shapes), and ask a user to pick the right one, a dumb spam script would have a 10% success rate.
If you display one image of an animal and give 10 possible answers, a dumb spam script would have a 10% success rate.
What if I combine three pictures in each challenge - e.g. "cat house triangle"?
Plus you constantly have to update your image library, which a huge pain.
Also, recognizing 10,000 images will take me around one day and less than $1000 with Amazon turk, thus giving me a perfect 100% success rate. After that you would have to completely renew your image database.
YES, it would be a pain to update the library, which is why I'm commending this particular concept for solving that problem ...
If you present 10 images (still a stretch), bots will have 10% success rate just answering randomly.
EDIT: Wait, from what I see you mean that the user will have to write "cat" or "dog" or whatever? That's better, yes. Communication, however, is hard, which is why me the GP didn't understand what you meant.
Please be careful. It could be that his thoughts are excellent but his communication is flawed. It could also be that he has a great deal of general expertise in the subject but is mistaken in this specific statement.
Thus, a general statement about him could be false is also aggressively ad hominem. You might want to consider focusing on the statement itself rather than the speaker, such as:
"Your suggestion is entirely wrong."
JM2C of course, and it is possible that I don't know what I'm talking about. I am not a psychologist or a logician.
Specific ads may be in circulation for a short time, or there may be many running concurrently, but it is the message that the advertiser is trying to get across, the tagline, and it would be of most benefit to the advertiser to get the user to associate their brand with a single concept. Using the example in the article, Subaru may want to be associated with "outback", not "four wheel drive" or "comfy" or "sporty". Businesses who try to target too many things or too wide an audience end up not getting their message across.
I'm not saying that what Solve Media is trying to do isn't a great idea. I think it has lots of potential, but they clearly still have more to work on.
This was later, awesomely riffed on by HotCaptcha (http://valleywag.gawker.com/246656/a-face-only-a-bot-could-l...) which pulled HotOrNot data and asked you to select the 3 hot women out of 9. Sadly, the site is down now but I remember trying it and it was remarkably useful and a hell of a lot more fun than word captchas.
If you're saying that it's possible to prevent manual, outsourced captcha solving, I would have to strongly disagree. It's similar to the futility of DRM as an antipiracy measure. As long as I can see the captcha, I can pay someone in another country to solve it for me.
I will agree that it's rare- but the most sophisticated and high-volume spammers do it, and they're the ones you have to worry about.
In case people start giving me sideways glances I want to make it clear that I haven't done any blackhat stuff in a very long time, but I'm still interested in the blackhat community from a security researcher's perspective.
All I have is anecdotal evidence- I know several people who are making their living spamming Craigslist and outsourcing their ReCaptcha solving. Since they can make $XX per post, paying pennies for captcha is a tiny expense. I don't condone this behavior, but be aware- it happens more than you think.
Anyway, probably best to take the discussion to email if you want more...perspective from the other side.
Then I installed reCaptcha, and now Akismet catches ~10 a month, and I've had to manually flag zero.
I'll take that illusion, thanks.
i've used defensio.com for filtering comments on my site with no captcha and rarely ever get a false positive or negative. false negatives are easy to spot, and users can manually override false positives by supplying an email address to get a confirmation link (which gets fed back to defensio as a false positive once clicked).
https://secure.grepular.com/Blocking_Comment_Spam_Using_ModS...
It's still working now.
Not to mention how ridiculously easy it will be to break these limited edition captchas.
This is actually attempting to solve two problems at once, and in some ways it could be more interesting to the user if the ads are well targetted.
Why not help the site owner make a bit of $$??? are you really afraid that typing in a bit of ad copy is going to turn you into a mindless drone
It's evil, but evil in a kind of clinically beautiful way. I'd say it stands a good chance of working in the short term too - like punch they monkey ads made a lot of money for some people back in the day
The only way to do that is if it works.
So yeah, I am concerned.
Interesting idea, but I would never watch an ad clip to signup for something nor would I want my users to have to.
What I will note is that it is somewhat inspiring to see that an idea like this can get off the ground. I haven't dug into the details of "Solve Media", but I assume that some people poured a sum of money into this. Maybe there's a sucker born every minute, or maybe confidence in anything internet-related is just that high. Hopefully, both things are true, and I think that's a good thing. I'm not advocating taking suckers' money, but rather believing the following: If your idea is anything better than this, which it likely is, you have a shot at it.
Selling user content is not a stable net in proportion to user use of the site; you don't know that the content will continue to sell at a rate keeping pace with user-incurred costs.
Charity is also not a stable net in proportion to user use of the site; nothing directly and reliably ties charity income to user-incurred cost, and nothing can--it's charity.
The only way to meet proportionate cost incurred by user use is by tying a proportionate revenue to user use. Even if you don't charge a user to use the service, even if you only ask that they fill out a text box to use the site, just as they might with reCAPTCHa, it suddenly becomes 'milking the user'.
Sadly, users no longer merely expect services to be free for them, they get offended if the service provider derives any money at all for their activity. (I think I sort of understand the mentality--"Why are they getting money for my work, when I'm not?"--but that logic doesn't hold up if no money was changing hands while they did the work anyway.)
You're also rather vague about what "the actual problem of spam" is. What strikes you as a mere symptom, and what strikes you as a cause? Yes, these peoples' particular implementation of challenge-response is pretty poor. Is that what you were specifically referring to, or did you have something else in mind?
I failed to remember that captchas are indeed used for other things besides registering as a member to a site. Things like one-time viewing of information (eg: WHOIS), etc, will probably benefit a lot from this. I showed some oversight claiming this service was dumb. It's great for things where it's OK that I get insulted, because I want to see something bad enough anyway.
I was in the mindset of imagining this being on a registration form to become a user of a website. I think the money lost from the amount of users getting turned off by this would be greater than the one-time profit incurred whenever a user registers. That is, unless your site profits from less users. In equation form:
(amt profit per lifetime of user) x (number of users that won't sign up because of this) > (amt of users that do sign up with this) x N [where N is how much you make from this ad captcha].
Notice that the longer you plan on retaining users, the less you should be willing to risk slowing down your sign-ups, unless this ad captcha offers a high enough profit. It is my opinion that for sites seeking long-term relationships with users, that this thing sucks. On the other hand, if you can afford that the user not continue beyond a point, then it's great. That's why it'll work for porn and other seedy crappy sites, and probably why I have low regard for it. I admit this is a foolish mindset.
In regards to "actual problem of spam," I was referring to the answer of the captcha being in the DOM, and the otherwise flawed implementation of it.
Microsoft http://www.internetnews.com/webcontent/article.php/3836421/M...
Yahoo http://www.faqs.org/patents/app/20090012855
Ad Captcher http://adcaptcher.com/
The hard to read word is there to prevent spammers. With easy to read words, you have a limited number of words per a page. In the end, the probability that a program randomly guessing the assortment of words (O(n^2) combinations if we assume order) is actually quite high.
It looks like the advertisers can force you to click through to get the security code. (e.g. Catfish's "Click through to see the security code!") I'll pass.
I'll gladly contribute my time towards writing browser extensions to hide and automatically solve these things if they take off.
I was a big fan of this new captcha idea until the video.
And if you don't know that, then giving someone a CAPTCHA with Hebrew or a Rorschach inkblot in it when they're trying to buy Yo Gabba Gabba Live tickets for their four-year old is a surreal enough experience to make people think they're living in a situation comedy.
Ie, what color shirt was the man pumping gas wearing?
Bonus points if you tell the user the question after the video so they have to re-watch.
Anyway, it seemed like a promising idea, but they folded last year. Good write up from a former employee here: http://factoryjoe.com/blog/2009/06/05/the-fall-of-vidoop/
In any case I'll be watching their progress with this idea.
I would probably use this for media views or file downloads, but I wouldn't use it for signups because I think it would decrease conversions.
What can we do to make sure this product doesn't catch on?
So what can we do that will actually work?