While it's not the perfect captcha either (which I think is impossible), it makes a better tradeoff in terms of UX, price and privacy.
While it's not the perfect captcha either (which I think is impossible), it makes a better tradeoff in terms of UX, price and privacy.
> It's broken
>Tasks that are easy for all humans but difficult for computers may no longer exist.
>Using machine learning or even browser plugins one can solve ReCAPTCHA in under a second. There are even CAPTCHA solving companies that offer thousands of solves for $1.
This is probably a bad argument when your proof of work captcha can be solved for much cheaper. Your site says "Solving it will take a few seconds on a desktop computer", which I'll interpret as 5 seconds. The spot price for a c5a.2xlarge instance (8 thread zen2 CPU) is 21.6 cents/hr. That works out to 0.03 cents per solve, an order of magnitude less than the 0.1 cents per solve for commercial recaptcha solving services. It probably gets even cheaper if you get your compute through non-cloud providers, or through GPUs.
The difficulty can be scaled in a predictable way - it's similar to rate limiting but less all or nothing. We're about to release automatic difficulty scaling per IP, so if many CAPTCHAs are requested/submitted from a single IP the difficulty increases exponentially. Also being able to set the initial difficulty for your usecase and audience is something that should help.
Aside from that there's some more measures on the roadmap: using lists of known-to-be-datacenter IPs, and reputation lists such as [2], as hints to increase the difficulty.
But you're right - it will still be affordable to attack any CAPTCHA, FriendlyCaptcha is no exception. Proof of work approaches have downsides too.
The main ideas behind FriendlyCaptcha vs ReCAPTCHA:
* The user experience is superior. It can happen in the background while the user is doing something else. There is no labeling task.
* We don't have any incentive to collect user data or track users (GDPR compliant, no tracking cookies etc)
* It's as easy to add as ReCAPTCHA to your website. The API is a near copy of ReCAPTCHA's API. You can host the JS code yourself, or even bundle it. With recaptcha it must be third party.
* It works in any browser less than 8 years old (IE>=11), although of course it's much slower in old browsers that don't support WebAssembly.
* It doesn't have inherent accessibility problems (poor eyesight/hearing doesn't matter).
* Open source at its core [3], the SaaS wrapper is not open source.
[1]: https://news.ycombinator.com/item?id=24921288 [2]: https://www.stopforumspam.com/ [3]: https://github.com/friendlycaptcha/
All those upsides are not compelling if it doesn't effectively stop abuse.
There are ASICs for crunching blake2b designed for mining siacoin. One ~$2000 card [2] can do ~4 trillion hashes, or 30 million captcha solves, per second
Right now we use standard blake2b as nobody has repurposed a miner to solve hashes for spamming yet.
The thing is, a determined spammer will be able to attack any CAPTCHA - even in labeling tasks there is always the fallback to human-in-the-loop which is cheap at scale (or even free if these are MITM'd users..).
Any (new) CAPTCHA system will have flaws and break in some way at scale, we're open to ideas and of course will try to address any (future) concerns. We are trying to provide a viable alternative to ReCAPTCHA that respects the user - and we will iterate on these problems as we go. Without some new thinking and openness to new approaches we'll be stuck with ReCAPTCHA.
Small nit: the difficulty is set to require around 2.5 million hashes, not 115 thousand. Your point still stands though.
You can look around for "useful" work, similar to how recaptcha was originally about transcription. If you can find some problems of the right difficulty that people want solved (e.g. I dunno, protein folding or something), then the electricity isn't wasted and you might even be able to sell the solutions.
A trifecta of doing evil from Google (well at least two out of three, 1 should cover for 2). And I say that as a relatively pro-capitalist with no problem charging money for services but I'm also pro-privacy and don't like training their AI models for free with them charging the hosts on top of it.