Breaking and Fixing CAPTCHA
extremetech.com
extremetech.com
I'd argue that it is nearly as effective at preventing human readers from correctly interpreting the CAPTCHA as well. I am not proud of my success rate on Google's CAPTCHAs. It would seem the better route for CAPTCHA makers would be to figure out what makes recaptcha work so well, without having to resort to such levels of swirly distortion.
Granted, that approach takes up more screen real estate by definition, but is very hard to break, and can be made to look more professional than kitties and puppies.
The bigger problem is: where do you get a giant source of kitten and puppy pictures that the spammers don't also have access to? It needs to be large enough that it's not worth it for the spammers to sit down and manually categorize them. It needs to be difficult to replicate because if you're just taking 10K pictures of each from an image search, the spammers can do that too.
We commonly phrase the CAPTCHA requirement as being easier for humans than computers, but if you're really set on designing a system you need to think in terms of costs, not ease, and you really ought to think of them like security algorithms, where we simply stipulate that an attacker is assumed to have everything constant about your system, its algorithm and its data sources, in hand. You need to create a system where you have a huge cost advantage over the spammers even in that case. And not make the mistake of assuming the spammers are dumb or lack resources.
In short, CAPTCHAs are bothersome because they only deter, not prevent access, and are thus only slightly more effective than a "No trespassing" sign or robots.txt file.
I have a trivially breakable CAPTCHA on my web blog, but it cut automated contact form/reply spam down from dozens per day to zero.
They definitely have a place, just not for anything super high value.
The trouble is, you've made life more difficult for your users. On blogs, non-image "CAPTCHAs" are trivial. (e.g., "Put 42 in this box -->"), so long as your site is low enough traffic that no one cares to write a bot targeting you.
Also the article mentions that reCaptcha is the most secure implementation of captchas so far. This is semi-true. Up until mid-August of this year (if I remember correctly) reCaptcha was quite trivial to break. Then in late-August/early-September someone apparently kicked their ass into high gear and they released several different variants of reCaptcha only weeks apart (unfilled in letters and lines that ran through multiple words). Again these were trivial to crack by simply modifying the old OCR to work remove the new distortions.
Then in late September (I believe, I don't record these dates anywhere) they finally settled on a wave distortion that I have yet to figure out how to break (due to lack of skill, time, and interest). You can check it out here:
http://www.google.com/recaptcha/demo/ajax
But all spammers that need to crack reCaptcha usually do so for account creation. In this case, their margins are high enough for them to simply use deathByCaptcha. So, captchas are defeated, not due to the security of their implementation, but due to economics.
More info: http://www.chillingeffects.org/anticircumvention/
In fact, all your fields could be named that way, as long as you're willing to decrypt the names on POST.