Twitter’s new captchas are also pretty insane, though not quite this bad last I ran into them.
Twitter’s new captchas are also pretty insane, though not quite this bad last I ran into them.
We will soon need this, and I feel government will gladly present a solution: provide your ID when you connect to the Internet, and we will guarantee you are a human.
Who's actually working on this and has released papers I can study? Because all this AI nonsense will only accelerate us towards this total control of the Internet because the spam and AI bots have made it worse for everyone.
I guess spam is an issue currently, but if bots become advanced enough to avoid heuristics, by making insightful and useful comments, they are probably better than most human users.
Proof of work captchas like mcaptcha can stop, or at least make very expensive, (d)dos attacks.
It's all fun and games until foreign agencies are controlling who wins in your elections through misinformation and propaganda.
Or an AI using a human's ID?
https://scholar.google.com/scholar?hl=en&as_sdt=0%2C5&q=capt...
Because in the age of ever smarter AI do you really want to solve CAPTCHA more and more frequently, and not to show you're not a bot, but to prove you are human with a physical body borne from an ovum.
It is not crazy to think we will eventually need to prove this fact somehow.
> We will soon need this, and I feel government will gladly present a solution: provide your ID when you connect to the Internet, and we will guarantee you are a human.'
I'm extremely hesitant to give any State the ability to track an individual user's online activity that intensely. It's been extensively documented that any State will fully utilize its size to violate an individual's personal privacy, with this often being done on a grand scale.
> Who's actually working on this and has released papers I can study? Because all this AI nonsense will only accelerate us towards this total control of the Internet because the spam and AI bots have made it worse for everyone.
The alternative is relatively straightforward: Utilize compute-intensive & memory-intensive tasks in CAPTCHAs.
https://github.com/mCaptcha/mCaptcha
What would only take a few seconds for a single user would take hours for anyone seeking to establish a bot network spanning thousands of pseudo-users. With such tasks, it adds additional friction to the bots at minimal frustration to the user. these can be placed as periodic silent challenges when trying to watch an episode, taking up only a few seconds at the user's end where they wouldn't notice.
but it's absolutely not a captcha: it is not a test to tell humans and computers apart. it's a test that can only be completed by a computer. its only utility is to be expensive. it's not a test to determine if there's a human behind the computer, it's only a test to determine if the computer has more resources than it currently needs, and can tolerate wasting some of them for a while.
The claims on the mCaptcha site contradict this. They say it takes about 2 seconds worst case for a computer to do the work, which is hashing sha 256. Looking around, an unaccelerated celron is about 1/20th the speed of a single ryzen core, and gpus are much faster.
Assuming the attacker has an 8 core ryzen with no gpu, they can hash 160 times faster than the person with an older machine.
Assuming the 2 sec upper bound is correct, this means a sub $1000 desktop can create 80 accounts per second, or 4800 accounts per minute.
If they are operating a botnet, then they presumably have access to more than one machine.
One look at what happened with cryptocurrencies tells me that isn't going to work.
What I am asking for is a reverse Turing test. Because there will come a time that any single site will need you to prove you are a human to do any action, i.e. post a reply or create an account.
We need a better plan than CAPTCHA that takes minutes to solve every time someone needs that type of proof.
I know government ID schemes are awful for privacy, but that is the only decent solution I can think of. If we, the computer people, do not have a better solution, the government will solve it for us, big tech will adopt it, and we have opened the doors to total surveillance.
The U.K. government developed something called GOV.UK Verify for exactly this.
It’s sort of like OAuth via a stateless gateway I think. The promise is that the entity doing the auth doesn’t know what you’re using it for, and the entity receiving the auth doesn’t know how you proved auth and only gets the level of detail about you they asked for (and you agreed to).
For example, if a govt website wants to know whether I’m eligible for something based on my local council, I could authenticate with my bank, who would say where I live with only that granularity, not my full address, and my bank wouldn’t know what service I’m trying to use.
I’m not sure how much of this got put into practice but all the ideas were pretty smart and showed there are good approaches to this sort of stuff.
The PM did not like the idea of the government being the porn passport for the whole country.
To me, that's still *way too much*.
Just from that, the government now immediately knows what site you've been to (via the token that you've given to the service), and what said site has access to, as well as when you've accessed it. On a long enough timescale, the government can build a daily profile of your life, that when coupled with geo-location data, can be used to see what & where an activity's happening in real time.
If I understand the idea correctly, this isn't how it works. Your user agent sends a signed request (with proof of identity) to the GOV.UK verification server, saying "please give me a signed certificate that provides no information other than my age". Because GOV.UK knows who you are, they can provide such a certificate. Your user agent hands this to the porn site, saying "you requested proof I was over 18, here's proof". Because the certificate was signed by an authority the porn site recognizes, they approve the certificate and let you in the site.
So the government doesn't know what site you visit, and the porn site doesn't know any of your personal information.
Each agency holds only the data they need for the time they need it. There are no national ID cards. And in the case of Verify, the verification was purposefully outsourced to private companies that already had this data due to their business (e.g. your bank, PayPal, Amazon who have a trustworthy address history, Experian, and so on).
Commenter 1: System X is evil!
Commenter 2: Actually, here is how system X works: (Demonstrates it does not work how Commenter 1 thinks it works)
Commenter 3: Well that's fine, until they change X to be evil!
I mean, sure, when X becomes evil, then we can say X is evil. But not until then. If your argument is that all systems eventually become evil, that may be true, but it's a different discussion.
This is a pretty dumb argument on the internet.
Me (1995): says something really stupid on the internet
Me (2020): shit hope on one finds that 1995 post and cancels my ass
With internet traffic and logging the default assumption should be: "All this data is logged and monitored for marketing purposes, and there is nearly a 100% chance it will be leaked by some hacker group", with the 2023 corollary of "And then used to train a LLM"
I think our (Germany) national IDs would theoretically have that option using certificates. I didn’t look too much into their online features as I never encountered anything supporting them, but my understanding is that I can prove some fact about myself (age, name, or simply being a citizen/resident), without either the government knowing I did it, nor the company knowing more than what I asked to show.
Visitor A is a legitimate human being from a poor country using a bargain brand Chinese phone with hardware that could be charitably described as "slow as molasses".
Visitor B is a troll for hire with a rack of used crypto mining machines in his basement, running hundreds of Chrome processes proxied through hundreds of hacked residential IP addresses.
Your approach would make the website unusable for human visitor A, while being the tiniest bit inconvenient for visitor B's hundreds of alts.
https://techcrunch.com/2022/06/21/apple-is-introducing-new-t...
But essentially allowing people to make "identities" via cryptography and then use a reputation system. Preferably by allowing people to follow/whitelist/favorite people across websites.
I like hacker new's method of making new people green. And I wish I could make it highlight the big names I recognize.
The problem with this is that nobody has figured out the distribution system for how we communicate the keys - IMO blockchains are the closest but it's so difficult to mention them because 98% of them are money-grabs. PGP/GPG has struggled so hard pypi literally removed support for it.
The second problem is that what will likely happen is sites like twitter will only allow very trusted accounts and never allow new ones - effectively locking you into one account.
git is a really popular blockchain, though I guess GitHub seeking to Microsoft may further the money-grab argument
I mean what people call "blockchain" in the cryptocurrency sense as actual projects - there's so much stigma largely because the motivation of most of the projects appears to be "making money/investing" and not actually solving a technical problem appropriately.
If github was like this there would be a "fee" for making making commits, this fee would be paid in some proprietary coin, initially created with an ICO/airdrop. Suddenly the motivation is holding these coins because developers will need to make commits right? And the more developers that make commits the more the coin is worth, so surely you should buy and hold them right? This will be a feedback loop of endless money! Oh and it'll be a DAO so the more coins the more voting power you get too!
^ This is what I mean, where the focus is on collecting some "coin/token" - this leads to both a lack of focus on the actual problem being solved, and the problem of people associating it with a ponzi scheme.
I'm not picking a fight with distributed graphs themselves, I don't like it when they're tightly coupled with "value" that can be traded as a fiat.
Why do sites need human verification anyway? If the problem is load, then you just need proper rate-limiting in place. Captcha always seems to be mis-identifying the real issue.
Unfortunately crypto folks are too busy selling shitcoins and scams to build this product.
As AI becomes more intelligent, you can prove humanity by exploiting our weaknesses.
(Another idea. Have a random image on a page actually be a text box with an image background. You cannot activate it if you focus on it, with your mouse or touch, but a bot doesn't need focus to change input.value.)
If we don’t have some way to prevent it, services will be increasingly populated by sophisticated bots either selling stuff, attempting security breaches, or pushing political agendas.
That’s a bad thing!
The current internet culture seems quite happy to slap captchas all over the place. When they first rolled out, captchas were predominantly a barrier for "write access" (e.g. make an account, complete a sale, write a comment). But companies like Cloudflare have been putting captchas everywhere for mere read access.
Because Captchas are designed to be easy for ("normal") people but hard for machines, they often disallow disabled users. I'm a ("mostly normal") 35 year old, but I _really_ struggle with captchas. I despise when Cloudflare tosses a captcha challenge before loading a page, as I'll need to spend 3-5 minutes of effort to figure out which tiny pictures have a stoplight, motorcycle, or crosswalk.
Will someone come up with a less restrictive anti-bot solution? I hope so. But even if not, I'm not sure it matters. According to comments in this thread (and elsewhere on the internet about the HBO Max captcha), many of these captchas are _already_ terrible at excluding robots. We're using captchas to exclude low-sophistication robots and disabled users. Seems wrong.
Are you imagining this would spur people to create a different, bot-free (how?) and disabled-human friendly Internet?
I think the fact that users are willing to give the site the finger and leave is a pretty good sign that you're human.
Not sure what a world without capture is going to look like but it's probably not going to be very good, I guess we'll all be forced to identify with a our "world coin(tm)" ID?
That will be the time when I log off most of the internet.
in trying to prevent bots from dominating, we end up making life very difficult for ourselves.
In the movie it is said that humans have scorched the skies in a bid to deny solar energy to the machines. But now humans have to live under dark skies.
CAPTCHA: Say something bad about Biden
ANSWER: I'm sorry, but as a large language model ...