Show HN: wehatecaptchas – we’ll keep the bots out without annoying your users
wehatecaptchas.com
wehatecaptchas.com
A nonce is valid on average every 2 * * 20 hashes computations, which is about 1 million hashes.
A modern GPU can compute several billion SHA-256 hashes per second.
---
Since this protection is uncommon, it will protect against spam, until someone creates a dedicated bot to bypass this captcha.
Also, I suspect phone users will have a hard time getting through. My phone took 30s to validate the captcha used in the demo, which has the N variable set to 2.
I tried it on my phone as well and I thought it did not work, because the progress bar did not move. I didn't even notice there was a progress bar.
The idea is great, but I would not use it for my apps, because I would expect a heavy loss of conversions.
Isn't there a mathematical puzzle which cannot be optimizer by GPU usage so that desktop and phones are on par? Maybe something like scrypt which takes less computation and more ram? I guess ram is also a very sparse resource for bots, no?
If you can answer that question, you can create a blockchain Proof-of-Work algorithm that won’t use half the world’s electricity.
The global annual consumption for 2017 was 21,372 TWh. [2]
While Bitcoin's energy consumption is notable, it accounts for nowhere close to half of the world's electricity usage, but rather about 0.3% of it.
https://hackernoon.com/the-blockchain-scalability-problem-th...
But in the context of "what if the the whole world uses bitcoin", the vast majority of transactions will not be onchain. But instead will be transacted via other more efficient layers (sidechains - like Liquid, or level 2 - like lightning).
Edit: Huh, based on other comments in this thread where it took more than a minute on iPhone X’s, this makes no sense. Uh, I only know what I saw...
This strategy involves a
(X) technical ( ) legislative ( ) market-based ( ) vigilante
approach to fighting bots. This idea will not work. Here is why it won't work.
...
(X) It is defenseless against brute force attacks
(X) It will stop bots for two weeks and then we'll be stuck with it
That was pretty annoying. If I hadn’t been on a site demoing captchas, I would have assumed the site broken and moved on...
It took my computer 47 seconds and spun my CPU to 100% in the process. This is in Safari on a 2015 MacBook Pro.
I'm a bit skeptical about the claim.
Still though, props to anyone who tries to come up with a way to kill captchas.
> Completely Automated Public Turing test to tell Computers and Humans Apart
The scheme presented here proves that a certain amount of hashing work was done, but doesn't prove that a human did that work. Oddly enough, no human can complete this task by hand.
[0] Dwork, Cynthia, and Moni Naor. "Pricing via processing or combatting junk mail." Annual International Cryptology Conference. Springer, Berlin, Heidelberg, 1992.
https://www.semanticscholar.org/paper/%E2%80%9C-Proof-of-Wor...
Not to mention with the current parameters it barely works on mobile devices so in practice it'd have to be weakened even farther.
If your spam target has any decent value, this simply won't work. Spammers will pay milliseconds while regular users pay minutes.
You could at least try to make some money on this by solving work on a mining pool, but I just can't see it being a good general strategy.
With WebGL, a website can run a program (shader) on the GPU [1]. Whether that's a good idea is another issue, but it's already available on current browsers.
ASICs would be harder, but supposedly some PoW algorithms are harder to optimize that way.
[1] https://developer.mozilla.org/en-US/docs/Web/API/WebGL_API/B...
For those of you who are interested about puzzle protocols, this is a good paper: https://eprint.iacr.org/2010/649.pdf
Trouble is, I don't think this is a better solution.
It's basically the same reason why cryptocurrencies cannot do meaningful work or it would be possible to do 'free' 51% attacks.
and why couldn't a bot do this again?
Well, at least there are less CPU cycles left to ddos wikipedia I guess..
okay. I think my compute instances could handle that. the way I pay for them (heroku) usually results in underutilized resources which could accommodate this level of computation.
The anti bot bullshit needs to stop. Put some verification or hard captchas around sentive pages like login but don't fucking blanket everything under recaptchas and proof of work nonsens - your website turns into hot garbage that no one enjoys using.
Here in SEA captchas and anti-bot protections pretty much ruin the web in PC bangs. reCaptcha is the fucking worst and renders the web completely unusable. If I go play some video-games I play more of "find that storefront" than a video-game that I came to play. Some places are wising up and installing bunch of browser extensions to prevent/solve captchas automatically but those don't work for program embedded captchas.
Can you do this asynchronously? It does take a long time, but I only noticed because I clicked on something and waited for something to happen. If you start PoW on page load (perhaps save success result in localstorage) then probably even 30 seconds of processing isn't bad at all.
There is something wrong with the fact that you can't host one as easily as consuming a black box API from Google.
It's only really efficient for computers to solve hash functions, and not humans.
There have been other analyses of recaptcha before, but it is an incredibly detailed, complex piece of software.
"Old school" captchas (i.e. have a human do something that is difficult for a computer) are getting more and more useless because there aren't many quick, easy tasks left that almost all humans can do that few computers can do, and they are vulnerable to mechanical turk farms.
So Google's approach now is basically they know so much about your average user (especially your average Chrome user) that it is very difficult for a bot to affordably "replicate" this user behavior over time. The downside is, of course, that Google knows so much about you.
Any proof-of-work scenario like this is pretty much doomed to fail, because is will be slowest on consumer devices (i.e. phones) and fastest on dedicated bot farms with rows of GPUs/ASICs designed to solve the problems.