I wonder how CAPTCHA is going to evolve though to combat this long term. A finger prick to take a blood sample to confirm humanity?
I wonder how CAPTCHA is going to evolve though to combat this long term. A finger prick to take a blood sample to confirm humanity?
You can't rely on just CAPTCHAs anyway, because mechanical Turks are too cheap compared to the damage they can do.
Funny enough - I actually wrote a [cathartic] short essay on that very concept a few months ago when I was being buried alive by captchas. I called it 'Blood for Access: An Alternative Approach to Circumvent Captchas'.
Here is an excerpt from the final paragraph:
In conclusion, the current state of captchas deployed across the internet can be frustrating and exclusionary for many users. My proposal for a blood-based authentication approach aims to highlight the absurdity of captchas and advocate for a more user-friendly and inclusive internet experience. While there may be challenges in implementing this approach, the potential benefits in terms of improved user experience and inclusivity make it worthy of consideration. It's time to explore alternative methods that prioritize user accessibility and convenience while maintaining security, and blood-based authentication could be a step towards a more inclusive internet for all users.
CAPTCHA is really just a proof-of-work system, it just happens to use problems that are easy for humans but hard for computers. It has never proved that the request is a genuine human request, it just proves that a human was in the loop somewhere; that human can just as easily be a Bangladeshi employee of a CAPTCHA-solving-as-a-service provider who is accessed via an API call. If we run out of problems that are easy for humans but hard for computers, we can fall back on the infinite set of problems that are just hard.
it's an optimization problem, with context dependent levels of true negative, false positive acceptance criteria
[1] https://scifi.stackexchange.com/questions/92738/what-is-the-...
The downside is that this will quicken the normalization of consumer devices that we don't really own/control. Using an Android device without passing SafetyNet checks is already a painful experience.
I think we're still there as the cost of running the models stays high, though it's subsided at this point. And I don't if we'll ever hit a point where decrypting and encrypting costs reverse.
It's also likely to lead to some kind of privacy laws in various countries (or may already violate some) because a primary reason services use it now is so they can snatch your phone number and use it to correlate you across different services. Which for the same reason makes honest users wary of it, especially as it becomes increasingly common knowledge why services ask for it.
A good solution might be some kind of anonymous payments system, so you can make a nominal refundable deposit to create an account which is forfeit for abuse, and then sites can fund more expensive or manual abuse-detection systems from the forfeited deposits in proportion to how much abuse they encounter.
Oh, we are trusting the corps won’t train in that and won’t fine tune on our personal data. Ok!
Things can get really wild when AIs can open lots of fake accounts all over the place.
Most banks ask me verification stuff that has probably been stolen many times by now.
The problem with this theory is that phone numbers are actually just bits in a phone company's computer and gaining access to them in bulk will become both cheaper and more common the more demand there is for it.
Scale here is not the size of the service, it's the number of services that use this verification method. When you have 1000 phone numbers and one service requires this, you can use them to create 1000 accounts on that service. When you have 1000 phone numbers and 100 services do this, you can use them to create 1000 accounts on each of them, i.e. 100,000 accounts. So the value of each number increases but its cost stays the same.
There will no doubt be some cat and mouse game where they try to detect the numbers being used for this and block them, but that's not going to work too well since a prepaid SIM card is cheap and as soon as they're done with it, it goes back to the carrier to be assigned to an ordinary customer.