AI bots are now better than humans at decoding CAPTCHAs
qz.com
qz.com
If bots that can break CAPTCHAs become widespread, the volume of spam, scams, and other junk traffic is going to cause problems for many people and small websites.
Increase the cost of having bots do it, while...
...also increasing the time wasted by humans. Time which is considered much more costly/valuable than whatever $ value spent on the bots.
So maybe the time has come to regard captcha's pointless, and just drop that nonsense.
Big Tech built their empires on scraping and stealing data (How do you think LinkedIn or Facebook got started?) But when we try to scrape them they throw a massive hissy fit, and so they put a lot of engineering into CAPTCHA systems to keep their data locked away. Eventually, the pinnacle of bots will be something that reads the framebuffer, and manipulates a mouse and keyboard to scrape websites.
This has got these companies freaked out, because all the founders know the dirty secret of their origin story, and that someone else can come along and do exactly the same thing to them.
The main tenets of apps that are resilient to bot spam are 1) scalability, so that they can handle huge quantities of traffic and bot-generated content, and 2) the ability to differentiate high quality from low quality content (regardless of whether it was created by a human). Ironically, AI is probably the solution to the second problem.
But the bots I wrote to get unfair advantages in auctions or tickets are probably of the kind most bots are.
Thus the XKCD CAPTCHA: https://xkcd.com/810/
We’ll have to change the game again now that bots can beat humans at it.
This is by design. The ones where you have to identify a bus, crosswalk etc are all used to train ML models. Your results are checked against other for the captcha, but sometimes you are the first person to see the image and there’s no way to check your answer so you’ll always get served another.
Another smart thing is that they actually segment the picture by moving the squares slightly.
Do you have a reference for this? I wouldn't have thought a process like that would be needed now-a-days for training ML models.
Human labels are absolutely still needed, for now at least.
https://techcrunch.com/2012/03/29/google-now-using-recaptcha...
And even though you can do a lot unsupervised these days, supervised labeled data is still something really useful for training ML models (often in combination with larger unsupervised corpuses).
The Captcha presents you with 9 squares. It selects a identification test at random (crosswalks, trains, buses, stoplights, etc). For this example let's say the identification test is to identify crosswalks. The squares are then filled as follows:
1) Two of the squares are requested that pass the identification test at an alpha value p < 0.05 (meaning it is more than 95% confident it IS a crosswalk).
2) One square is requested that passes the identification test at an alpha value of p < 0.01 (meaning 99%+ confident, effectively certain it IS a crosswalk)
3) One square is requested that fails the identification test at an alpha value of p < 0.01 (it is almost certainly NOT a crosswalk)
4) Two squares are requested that fail the identification test at an alpha value of p < 0.05 (it is 95% confident that it is NOT a crosswalk)
5) Three squares are requested that need have low confidence intervals p > 0.05
The captcha then shuffles these 9 images at random, it offsets the images a little bit by altering the crop slightly to prevent memorization by bots. Then it presents these 9 squares to the users asking them to identify according to the identification test.
The captcha scores the user based on their selection with the 6 known squares. The response you give on the 3 low-confidence squares has zero impact on you passing or failing the test. From what I was told, you must successfully identify both of the 99% interval squares correctly (one that passes the id test and one that doesn't). That is a hard pass/fail. From there, the captcha scores your response on the 95% confidence interval squares to the expected values. It compares that to other variables such as the speed that you answer them, the movement of the cursor and other variables (such as selecting, deselecting, etc). It also compares IP address google session data as part of its determination to determine the liklihood of humanity in the user. My understanding is that is is moderately forgiving. If the user is determined to be human based on those responses, then your responses are fed back into the confidence intervals for all of the images presented (other than the two "known" squares). Data by users that fail the Captcha is discarded so it doesn't feed into the confidence metrics of the images presented.
From what I was told, you can actually incorrectly identify 2 squares and still pass the captcha. The IP address and mouse movement plays a significant impact in the response as well as your ability to identify the two known squares.
Three of the squares are entirely unknown to the bot. You are purely feeding the confidence on those images for future use in the CAPTCHA and other google products. But there is no test where you are "guaranteed to fail" as mentioned above. Every test presented to you can be passed. There are 2 known squares which you MUST answer correctly. Your behavior and computer data and answers on the mid-confidence squares are what further impact your pass/fail determination. The three unknown squares never impact your pass rate. They are filler, the captcha only watches how you interact with the filler squares, not what you actually respond.
Sadly, when a site with captcha has decided to fail your every attempt, there is no feedback on why. You can request new sets as much as you wane; you can submit perfect results as much as you want, and you can try alternate methods offer (such as audio captcha) as much as you want. Typic'ly, when this happens, the following don't help: incognito/private mode; toggling extensions, adding some less direct mouse movement, forrce-reloading the page. Occasionally, other browsers or other hardware (phone, tablet, desktop), Windows/Linux/Mac, changing user-agent string might help.
Humans will lose!! lol ;-)
At least that's how the old "type these two words" CAPTCHAs worked. It was crowdsourced human OCR of whatever text the machine OCR couldn't make sense of. I'm not sure if "find the bus/motorcycle/crosswalk/light" is the same way, but perhaps, and it does seem to offer leeway when there's only a few pixels of that item in the frame.
I used to choose correctly but being sent through 5 chains of CAPTCHAs is modern hell.
This is trivial.
I've also noticed that captchas are getting more difficult. Is that because the AI needs to sharpen recognition skills or because that's needed for differentiating human from 'bot?
Nowadays, it seems the kind of captchas I get when under suspicion of being a bot are simply there to delay. Especially google captcha with their extremely slow fade out box selections.
>>“Furthermore the bots’ solving times are significantly lower in all cases, except reCAPTCHA, where human solving time of 18 seconds is nearly similar to the bots’ time of 17.5 seconds.”
This is currently an obvious tell for the standard CAPTCHAs, as you mentioned, "performing at a superhuman level". However, it's an easy bot behavioral fix, so.... what is the next step? Offer a game of chess and look for a human the playing style? Seems you'd have to offer a menu of games, but not "Global Thermo...."
Modern captchas do a lot of background work regarding how human your inputs look, whether you have a human-seeming fingerprint, etc. Often when I'm behind a VPN and on Linux I have the same issue, because my setup simply looks "too botty" no matter how good I am at telling which squares have a firetruck in them.
Curious, do you use a VPN or Tor? Either of those will cause CAPTCHAs to make you solve multiple puzzles.
The only site I visit that has ever been annoying with CAPTCHAs is PCPartPicker.
Job done!
Even maybe add a
answer = getrandombool(somesensiblepercentage) : rightanswer() : wronganswer();
For good measure
Many CAPTCHAs already operate this way. "Bots can do things at suspiciously superhuman speed" isn't new.
Failing that, we can't be more than a couple of years away from generalized solvers that can simply be implemented as browser plugins, at least on the desktop. The job of coming up with a fair, equitable and non-discriminatory test that only humans can pass is going to be an impossible one.
That's the Epic Games Store for me.
Anyway, I highly recommend buster, I barely notice captchas anymore with it.
Can you give me an example of a site that is not usable?
I know it probably needs that permission, but no thanks lol
Captcha was never really the limiting factor for spammers. It was generating human readable content at scale (comments, reviews, responses, etc). But with AI that's not an issue anymore.
For now. But we're slowly walking towards the future where you can only consume web using an official and conformant browser running on a locked-down platform. That'd make it considerably harder for spammers, but of course spam isn't what this is about, it's more like a cherry on top.
I see it like everything else we use for communication. Still junk mail, still robo calls, still spam texts. And you will still get spam under your nationalized id. But YOU(the individual) won't be allowed to do the same.
Edit: on a brighter side with high capacity drives being cheap and various wireless protocols sneaker net might be a thing. Your info won't be up to date but maybe that's not so bad, no doom scrolling. Beware the honeypots though.
This might actually be a pretty enjoyable experience for a lot of users. If every user can be assured that every communciation is actually from a real person, or a real organization that can be sued, or at least a fake personality that someone put tens of thousands of dollars behind.
if the choice comes down to two options, what makes you think it would be between wei and blockchain
i think there might be some confusion here simply because parent used the work cryptographic, but this has nothing to do with blockchain
I don't have any solutions or ideas to float. Just painful acceptance that nice things are going to break.
It’s clearly burning, nobody seems to be in charge, there’s little hope that anyone is going to fix it, and individual actions seem like shouting into the wind. Even worse, the problem is undefined and hard to measure - and different groups have different complaints and priorities.
Or, said another way:
“That pretty much sums it up for me” - drunk guy in the bar in the movie Groundhog Day
We need a new foundation. I don't know what it looks like, exactly, but I think it's going to have to built around micropayments.
I think we are going to need some kind of certificates vouching for humans being humans.
Could slow spam down though.
This is possible with the German identity card. (I have no idea but my guess would be that this is possible with other identity cards from Europe or around the world too.) You can even make age checks with out transmitting the actual birthday. It just returns whether the card holder has or is above the age in question. You can't cross reference those certs with other sites.
It really grinds my gears if a identity check wants a video call or what ever instead of them using eID features.
The best you can do is pseudonymity. If the attestations are completely anonymous then you have no way of dealing with bad actors, like those who sell their digital identity to spammers.
No it is not a solution. What prevents me from "selling" my biometrics to someone to be used for nefarious purposes? Or you are proposing putting an orb in from of every computer and not allow accessing the Web without scanning user's iris every time they type web-site address? Even if such dystopia get implemented we will end up with situation when bunch of real people in third-word countries are getting paid 2$ a day to sit in front of a computer playing games all day while getting their eyes periodicaly scanned to allow spammer botnet to browse the Web.
> I think we are going to need some kind of certificates vouching for humans being humans.
Who are "we"? Me and probably absolute majority of other users are perfectly fine with the way the Web currently works and don't care about the cost of fraud for Google's ad empire.
1. Have a service worth paying for.
2. Collect a payment with registration/account creation.
My theory is that if there was a way to frictionlessly pay, say, $0.02 to access a piece of content ad-free, most people would be pretty okay with it. They key part is making the transaction frictionless - no more than 1-click/1000ms.
I really liked it. A view Blogs, Podcasts and the KeePass-Homepage had it. Then they sold to Chines investors and pivoted to god knows what.
I feel this is a business negotiation instead of a tech issue. But then I may be just clueless.
Including some way to keep that from marginalizing people in the current very inequitable capitalist environment.
A non-technical challenge is that you'd need someone to lead this in good faith, and they'd need both principles and clout. The first 5 candidates I thought of just now seemed much better candidates in the past, than currently.
People who don't believe this are probably biased because they are Alice.
Don't be Alice.
When challenged, rationalizations might come out.
Circumstantial evidence of this is that we really don't see a lot of clear altruistic looking towards human progress... on other topics.
If we mostly only talk about principled stands when it happens to be very convenient in a selfish way, the selfish way seems a more likely explanation.
If there were a way to give two cents for each article I read, I'd do that, but there isn't.
I don't ever read one single thing, but I read an article or two from countless of services.
I happily pay for Youtube Premium so that I can listen to whatever music I want anytime. Spotify and other services are fungible with that. I sort of happily pay for Netflix, but their catalog is shrinking. I would happily pay a subscription for access to all or at least ~99% of newspapers.
Whatever music did right (ASCAP, BMI) isn't perfect but it's miles ahead of the trash subscription schemes anywhere else.
Yeah this is a super good idea. I would pay $5 a lot of the time to access these just so I don't have to deal. Would have to accept paypal and I'd do it.
That modern society is structured around protecting Alice rather than protecting Bob and helping him free the 0s and 1s is simply a side effect of this, and an extremely unfortunate, progress-stalling one... the kind where you seriously contemplate going back in a time-machine to fix whatever went wrong to make us end up with.. this...
I agree, it's so weird that people who devote time, effort, and resources to the production of articles or books somehow think they're entitled to be compensated for the use of those products! What a bizarre belief! I mean, obviously they should just give them away for free. Not like they need money to survive or anything. They can just go on food stamps and live under a bridge or something.
As a creative person currently making an obscenely high amount of money doing rust development (north of $350k/yr), I'd happily throw all of that away to just be able to work on my open source projects in perpetuity if I could trust that society will take care of me, forever, in exchange. In fact, playing this whole capitalism game is a huge waste of my time and energy that I'd much rather spend making creative works without worrying about how I'll monetize them.
As someone who makes creative works, I don't _want_ to have to charge people to use/access/enjoy them.
We finally invent a thing (the Internet) that will let us share knowledge for free, and one of the first things that happens is a bunch of lawyers invent more work and job security for themselves by creating this fantasy notion that you can have Imaginary Property and they call it "Intellectual Property" so it's not immediately obvious how ridiculously selfish and society-retarding it is.
We live in a world of actual scarcity and they invented some artificial scarcity to benefit themselves exclusively, then immediately funded a bunch of bribery^H^H^H^H^H^H lobbying to make it illegal to share information for free.
>As someone who makes creative works, I don't _want_ to have to charge people to use/access/enjoy them.
Same here. I self published some stories on amazon and they won't let me charge less than a dollar for them, or I would. I'm infinitely more interested in people enjoying them than profiting from it. In fact, I found that they almost immediately ended up in some pirated torrent and was like, "How cool is that? Somebody thought it was worth pirating."
This notion that creative types won't create without financial incentive seems to come from lawyers, not creative types.
I think your narrative has gotten the relation between the invention of the internet and the creation of the subcategory of intangible personal property known as “intellectual property” very, very wrong.
Like, intellectual property is older than the USA and the internet is... not.
No. Get out of my search results.
Pinterest, for example, should NEVER appear in my links or search results. If the New York Times wants to appear in my search results, then that article should be free otherwise GTFO.
Google used to heavily penalize sites that pulled this trick, but then gave in because it interefered with their ad revenue.
Seems strange that the bots are allowed to read content for free, while the humans can't, but also the humans shouldn't read the bot's reposting of the content for free.
It seems to me that if they really don't want humans reading things for free, they shouldn't give it away to the (human owned, operated, and designed) bots.
okay... so they're piracy links is what you're saying?
From just yesterday in fact:
>Past bot defenses are failing. Only subscription works at scale.
https://twitter.com/elonmusk/status/1691969296543711471
The included chart is super interesting: https://i.imgur.com/WI2XMCj.jpg
Majority shops have captchas since crawlers are like mini denail of service attacks on their resources and they continue day and night.
You will not pay a single webshop to browse its inventory let alone dozens you currently check before buying anything.
Like it or not this is what the internet runs on nowadays so killing that would have much bigger fallout than anything annoying captchas could do.
Things like "please type your credit card number here and pay a 1 cent fee".
Or "send us a selfie with your passport".
Or "Get 5 friends to vouch for you".
Or "please log into a government website and oauth this app"
Or "please log in with a gmail account that is at least 5 years old".
All of these might work today just because they aren’t widely used yet. Once they are and are understood they’ll be cracked.
The government oauth is maybe the most interesting; it probably just kicks the can to a government site which is going to have all the same problems, but could potentially benefit from a secure national id. But now the government has a database of all the sites you are logging into; forget privacy of library records, that’s a massive loss to the 4th amendment in practice. No need for prism or other NSA exploit nonsense when sites are literally pinging a government server to verify citizen network activity.
The only issue is that it could lead to cross-site tracking because you are reusing the same public key everywhere.
But maybe cryptography experts have a solution?
They do! The field of zero-knowledge cryptography targets exactly this sort of use case, proving things to a recipient without revealing other things.
In this case, you might send a zero-knowledge proof that you have the private key corresponding to a government-signed public key, without revealing either key and, importantly, without communicating with the government or sending correlatable information on each transaction. (If you were ok communicating with the government you could just get it to sign a random public key for each transaction without needing zero-knowledge cryptography).
You can do a lot more, for example proving "I am 18+ [attested by gov signature]" without revealing your age, birthday or identity, or "I have security clearance level 2 [attested by gov signature]" without revealing anything else, or "I have a driving license [attested by gov signature] and current paid-up insurance [attested by insurer signature]" etc.
The field has advanced technically a lot in the last few years, to the point that those sorts of zero-knowledge proofs are now easy to implement technically and reasonably fast to compute.
Then websites site rate limit each authenticated person.
Also, it could be made opt in so the people freaking out would have nothing to object to, and then whoever wants to participate, can.
You can also architect it so that the government doesn't know who is trying to authenticate you.
It does prevent you from making multiple accounts with the same company though.
Bet that's vulnerable to Stable Diffusion in-painting.
This approach is used by wechat, you can't make your own account and can only be invited by an existing user. I suspect that wechat has reached enough market penetration that this is now worth it.
There are tricky requirements for Americans
I have a feeling other humans verifying you mechanicalturk style one time is the future.
But imho, the payment route makes sense and also this is the problem as random paywalled sites and web monetization. A cash equivalent bearer of token payment method is what is needed.
1) verify+lock funds 2) get bearer to pay funds or funds unlock in x minutes, cancelling the payment 3) token is presented to payment processor who will revoke the token, issue funds to payee with a new token matching that value paid 4) anyone holding that token can pay for stuff, you can just email or move tokens with usb drives or store them im a secure vault service
I believe the main obstacle to solve so many web issues are KYC laws and lack of constitution amendment level laws that give the people right to trade using a bearer token (cash or not) and transfer funds peer-to-peer without a third party or disclosing their personal info (again, all like cash).
Probably <1 year away from beating automated detection of this reliably and 2-3 in fooling humans a high % of the time economically. I was at siggraph recently where I think I saw a whole room of papers of people’s approaches to doing just this problem of photorealistic faces saying arbitrary things.
Depends on how badly the given service wants to keep out bots as to whether they'll start requiring some kind of guaranteed identity check.
I don't know if that's feasible, but that's the premise.
>Unless you have a massive library of possible actions these can be pre-rendered too.
Combinatorial explosion gives you a massive amount of actions. Hold your right ring finger between your left thumb and pinky and move it around in a circle.
There's tools that you could use to limit what you had to prerender and it would be a cat and mouse game like captcha is today, but I think until we're at the point where you can completely replace an actor, and then you can do that in real time, picking out a real human will be possible.
People are working on generating animation on a rig from text prompts: https://www.motorica.ai/ It would be easier if we knew the prompts ahead of time and then we just render transitions.
Real time-ness and a good deal of rendering fidelity can be mitigated by pretending to have crappy network connection once the prompt is given, unless you are comfortable excluding people without reliable internet.
I think the bigger issue is probably with the premise though. This kind of video rendering is much more taxing but it’s also much more taxing on the verification side. I can’t imagine a company being able to do this at scale the way captchas are to defend against bots, you’d need an automated system on the frontline.
>Real time-ness and a good deal of rendering fidelity can be mitigated by pretending to have crappy network connection once the prompt is given,
Real timeless and rendering fidelity are the only part about this that isn't solved, so there's no real debate to have if those constraints aren't there.
>unless you are comfortable excluding people without reliable internet.
If this was a real thing, I will absolutely bet that companies would exclude people with unreliable internet once I becomes known that all scammers are pretending to have unreliable connections.
"Please find a more reliable connection, or stop by the nearest Identity Check facility to authenticate yourself."
>I think the bigger issue is probably with the premise though.
I don't think this is likely to happen either. I think the most likely solution is trusted third party in person verification. Where I could see something like this working is if the third party verification service offered a 1 time remote verification process that functioned something like this.
and in return, you will get this juicy Web Environment Integrity token that acts like a key to unlock Captcha and pornographic websites.
On my back burner I have a crowd-sourced data app and I keep wondering how I'm going to keep bots out. The ideas of shadow banning, throttling, or an approval queue for everything except known 'real' humans and new users that seem relatively human keeps popping up (eg, 2 approval queues for 'probably a bot' and 'probably not a bot')
There are always things computers do way better than humans. That’s why they have been created in the first place!
Anyway, what will the new CAPTCHAs consist of? If the answer is “nothing”, then that’s the age of AGIs
The CAPTCHA can ask humans to do a non-trivial research task, like look up the latest news and give an opinion, or actually appear on camera etc.
I'm surprised, too. My solve rate (as a human) is <50% for reCAPTCHAs of the form "select all squares containing a motorcycle/bicycle".
Does anyone have tips for solving them? (Is the rider part of the motorcycle? Should I select a mostly-empty square containing a single handlebar?) All I've determined is that the system prefers contiguous sets of ~6 squares.
How about the pole the stop sign is on?
It's purely anecdotical, but I'm convinced that Google CAPTCHA (which I don't see more often only because I rarely use Google Search) punishes me for being fast. I can half-ass it or do a perfect score, but if I'm done with it in less than 3 - 5 seconds, I'll only get another puzzle as a reward.
If there was no profit motive(ads) or its correlates(attention), none of this would be necessary. Companies would just provide utility to make people's lives easier. The most utilitarian company would win.
The only reason big tech needs to make this much money is share holder "value"(code for: 'we need to make our execs and engg rich so that other companies don't grab them'). This is a massive snowball; Its crash-only thinking(google the term).
Me, I'd love to see a world where everybody got enough money to live on, and then got to sit down and create whatever content they want, for the heck of it. They don't own it; we all pay for it and we all get to enjoy it.
But that's not happening any time soon. So I think we're stuck with the problem of intellectual "property" being a thing, and companies trying to artificially limit access to it despite knowing that there are a million ways around it. They're just going to hope that most people, most of the time, would rather take the legal and official route, if it's not too burdensome.
Lots of discussion here 2 days ago (and that wasn't even the bunch of posts from a week ago)
Edit: There's various efforts: https://captcha.com/captcha-accessibility.html
We will probably rest back on the old ways of doing things where we use authentication and trust-building with verified accounts to throttle and gate what users get what privileges.
The evolving coherence of stronger and less siloed identity attestation seems like an obvious way to go here, at least looking way back from the past where we are now.
Maybe we'll get back the good old web
I hate captchas as much as the next person and have long suspected that bots can solve them better than I can, but I hate the comment sections and forums made useless by spam messages even more.
Wait, did they use humans or computers to measure the accuracy of the solutions?
and honestly, I cant find a reason to privilege human bullshitting over AI’s
Particularly those where you have to slide the part of the image.
I guess I’m not human anymore?