AreYouHuman CAPTCHAs defeated using SimpleCV
spamtech.co.uk
spamtech.co.uk
So I think beating this captcha wouldn't require computer vision and stuff, simply sniffing the traffic on a successful run of the game and then replicating it appropriately later.
Also, how will this captcha system scale? They'll have to keep coming up with new sets of objects where some of them belong on a target and some don't.
Meanwhile, a simple bot, as demonstrated, achieves high success rate. Could also be improved with automated learning , using suitable AI library; such libraries are freely available for making games.
With both false negatives and false positives high, the captcha's either done for, or at least needs some serious tweaks.
And why it lets you keep trying once you solved it?
Not that any of that would really fix the captcha, you'd just need to improve the code accordingly.
You can find the research details here. If any CAPTCHA scientist want to further research on my CAPTCHA, I can OpenSource it completely.
Autopy: https://github.com/msanders/autopy
PyMouse: http://code.google.com/p/pymouse/wiki/Documentation
Dogtail: https://fedorahosted.org/dogtail/
If you're on Windows, I believe win32api / win32con also can work.
We cannot just assume that everything that is automated is something we need to stop simply because it is automated.
Maybe the design of email is the problem?
Maybe the design of blog comment systems are the problem?
CAPTCHA's are aimed at stopping automation. That appears to be the only criteria they filter on. It just seems strange.
Of course CAPTCHA's will eventually be useless. Because most of us are working our tails off trying to push automation forward, not find ways to block it simply because it is automation.
How would you design a blog comment system that doesn't get spam without using a CAPTCHA?
So it seems to me at least one person has designed a system that allows this and keeps out spam without using a CAPTCHA.
Consider this:
CAPTCHA is prohibiting comments based on the manner in which they are submitted. But what are really trying to stop? "Spam". How do we know what is "spam"? We look at the content. It might be hard to define "spam" because it is a subjective determination. But we know it when we see it.
What if someone writes some interesting content that is "not spam" but wants to submit it in an automated fashion? CAPTCHA stops him from doing that.
CAPTCHA stops automation. It may stop spam. Or may stop something else.
That's my issue with CAPTCHA. It is not aimed at spam, at least not directly. It is aimed at automation.
That more to do with Hacker News being a low-value target than with its anti-spam prowess. If you really wanted to spam Hacker News, you could.