$1.39 for 1000 decoded CAPTCHAs
deathbycaptcha.com
deathbycaptcha.com
It would detect a captcha on a page the moment the browser renders the field and it would be completed in ~15 seconds by the time the user scrolls down to the form and completes the other parts.
With most captchas I have to try 3-4 times before I can actually spell out what the image is showing. The only exception is ReCaptcha, those tend to be easy to decipher.
I wonder if 3-4 years down the line, everyone will continue using captchas...even when they stop working as a method to fight spam
The evidence that they work is right in front of you. The incremental cost of posting 1000 spam comments went from basically zero to $1.39.
I use ReCaptcha on my sites and, as far as I can tell, the only spam getting through is humans (typically with .cn hostnames) manually entering the CAPTCHA. Meanwhile it's blocking 100s of dumb, automated attempts.
I'd pay $1.39 for 1000 links from sites that haven't been spammed to death with out thinking about it.
You can also join with others who work to stop this kind of spam. For example, Project Honeypot ( http://www.projecthoneypot.org/ ) offers honeypots to trap all kinds of spammers, including comment spammers.
If you're expecting some kind of 100% solution to spam, I doubt that will never happen. The best anyone can do is combine a bunch of decent solutions, preferably in unique combinations, and hope to reduce spam to a manageable level. If one countermeasure blocks 50% of spam and another 70% and another 90% and their failures are independent, you're down to 0.5 x 0.3 x 0.1 = 1.5% of spam getting through. Chain enough partial solutions together and you get something better than any one alone.
I do agree that they are outdated.
The people that use it have very specific purposes in mind. Spamming through CAPTCHA'd systems makes little sense as it costs too much. That said, there are many businesses, large and small, that use breakers to engage in commerce.
We had this issue with spammers where after sending 50 emails a day we would ask users to solve a captcha after each email sent. That didn't work.
Upon further investigation and adding some code to track keypresses, we discovered the reason: it had been humans all along, sending spam semi-manually from a cybercafe/sweatshop in Nigeria using an add-on like Roboform as an aid. And yes, these were the usual H3rb4l V14gr4 spammers as well as some Nigerian Princes.
While there is poverty, Captchas are necessarily broken.
You can't directly attach value to the money they spend on this. They create accounts on many services like Gmail, Yahoo, Hotmail, etc for email spamming and they need to use these services for the tools that they purchased to work. These tools basically automate everything except the captcha solving part.
Does this service break any EU directives or "laws"? There should be a law for that (even if similar services pop up elsewhere in the world).
edit: note about Cyprus
Or simple math problems at random.
here's a good ruby library for using this service: http://rubygems.org/gems/deathbycaptcha
Some other famous sites that are doing this since the mid 2000s - http://decaptcher.com
They integrate with just about every famous spam tool.
UPDATE: Automated Gmail, Yahoo, Hotmail account creation, etc. They create accounts in bulk and then spam through the gmail, yahoo, and hotmail accounts by tools that are being sold.
If you're going to forum profile spam, you'll go broke paying for captchas.
But for other stuff that I mentioned in my previous comment, it does make sense for them economically and they do use it.
Using something like Celerity or Watir for Ruby, combined with this captcha service, you can essentially automate the entire process.
Building a bot to do something like that really teaches you a ton about how you would prevent such activity on your own systems.
Care to share some of what you've learned? Or is this an exercise left to the reader?
1) if you're using a popular CMS platform, ELIMINATE ALL FOOTPRINTS. Change all url strings from the default, remove standard text/descriptions on signup and comment forms. Kill anything that can be scraped against the rest of the installs to hide your own sites from the scrapers the spammers use to find you.
2) Tap into distributed spam prevention systems. Akismet is probably the most popular example. Your single site will most likely miss the indicators of a spammer, but a system like Akismet can see the 10000 links all pointing to the same url in one hour and lock things down for you.
I've legitimately thought about doing a talk at a Wordcamp one day called "How I Spam You" that just walks people through how to spam wordpress, so they can then go protect their sites.
I interpreted the OP to be more disgusted at someone making a business out of actively circumventing a control then we discussing that it exists.
That is a bit different than discussing the existence of flaws. In this case it's making money off actively exploiting the flaws.
I would gladly consider working on a browser extension that implements this service for his sake. It's a double edged sword, and really, if your spam prevention relies heavily on captchas, it's not feasible in the long term anyway. This is not the first or last or cheapest service to break them.
I haven't even gotten started on my own personal gripes about captcha abuses. Top on my list right now is one I'm going to encounter again on my flight later today: gogo inflight wifi asking me to fill out a captcha after payment...on wifi on a plane 35000 feet up in the air in the middle of California. Talk about pointless.
1. http://www.w3.org/TR/turingtest/ lists some interesting alternatives to captchas that may work for lower traffic sites.
Taken from their website:
Contact We’re here to help you! Please send us a message to any of the emails below: Technical Support Payment Support System Admin