I've often wondered about the effectiveness of simple custom things like "what's the sum of these two numbers?"
Maybe couple it with some server-side rotating variable names... Dunno.
Maybe couple it with some server-side rotating variable names... Dunno.
step 2: ask LLM to build better captcha
step 3: oh shit, skynet?
But if everybody writes their own custom challenge, now that's a lot of targets. Whereas right now we've already trained the AI to identify all the stoplights, and that kind of captcha is ubiquitous. They just have to solve it once and then a whole bunch of websites are vulnerable.
And most websites aren't actually that high value, for example mine. Is anybody going to spend the time reverse engineering a simple captcha just so they can post comments to my blog that no one reads? :)
But if I used something off the shelf that they already have a solution for, then sure they would.