Death to Captchas
timkadlec.com
timkadlec.com
I've seen some captchas that have you do simple math problems or other basic questions, which seemed to be a better alternative. I also remember seeing prototypes of a captcha that showed nine pictures and told users to select the three that were cats. Not sure why that never caught on, though.
I could probably get away with using the cat captcha on my blog, but Facebook or Google wouldn't be able to use it. But the thing is, for a site like my blog, I don't even need to use a cat captcha. I just need to make sure dumb bots can't submit anything, eg using hidden fields:
https://secure.grepular.com/Blocking_Comment_Spam_Using_ModS...
So where do these image captchas have a place? Not on big sites, and not on small sites...
secure.grepular.com uses an invalid security certificate.
The certificate is not trusted because the issuer certificate is unknown.
(Error code: sec_error_unknown_issuer)
Edit: On both FF 3.6.6 and IE8 on Win7
https://secure.grepular.com/Why_Does_this_Website_Generate_S...
Yes, I realise the irony about the explanation being behind the same certificate.
The simple truth is that CAPTCHAs are a very good initial defence to spammers. We've been trying to find a problem to replace CAPTCHAs, but we haven't been able to find one that satisfies all these properties:
1. It has to be easy for a computer to create.
2. It has to be easy for a computer to verify.
3. The problem space has to be very large to thwart precalculation attacks.
4. It has to be easy for a human to solve.
5. It has to be hard for a computer to solve.
Your math example fails #4, and the cats example fails #3.
EDIT: How do we make lists in HN markdown?
"""But if a computer can't read such a CAPTCHA, how does the system know the correct answer to the puzzle? Here's how: Each new word that cannot be read correctly by OCR is given to a user in conjunction with another word for which the answer is already known. The user is then asked to read both words. If they solve the one for which the answer is known, the system assumes their answer is correct for the new one. The system then gives the new image to a number of other people to determine, with higher confidence, whether the original answer was correct."""
Solving a CAPTCHA sucks for the person submitting the comment, but having a page full of Viagara spam burying any legit comments sucks for everyone.
What scares me is the noticeable rise in spam comments being submitted by actual humans apparently in India and China. I set up a ModSecurity rule to block inbound hits coming from a Google search that includes the phrase "post a new comment" but that's only going to work for so long.
I disagree.
An automated system that calculates the probability that user data is invalid will inevitability report false positives, leading to blocked or deleted content. Try explaining that to a user.
In general things of "value" can't be both secure and fast/easy. If it's fast/easy it can(and will) be brute forced and/or Amazon Turked.
Obvious problem is that in case of directed attacks spammers (or other malicious persons) would use native code or even GPUs to perform computations, while ordinary users would be limited by slower JavaScript implementations. It would help (but not solve the problem completely), though, if someone would show us some non-trivial code, that performs computation in background (without any noticeable impact on page interactivity), that'll finish in some minimal time required to write a meaningful comment or fill out a form.
The people working to get through security measures will always be there, we might as well put them to good use. Get them to build innovative AI software to bypass security. The code to identify the animal in the picture will eventually find its way into the public and be put to good use.