Worst CAPTCHA Ever
svedic.org
svedic.org
Executive: What can he do?
Spouse: He's really good at programming. He took a class in it in high school five years ago, and I'm pretty sure he didn't fail. He even has his own web page.
Executive: Hmmmmm. I think we have something he can work on....
Good news: we're hiring! We have day long meetings Mondays and Wednesdays, but other than that it's great.
They should reject corectly filled in captchas.
This isn't by any means a complete solution however it does catch 90% of drive-by spam.
None of which is all that difficult for a full size browser, but it may be prohibitively resource intensive for a high-volume spam bot.
No guessing required.
Looks like it's designed for not to be deciphered either by humans or computers.
http://techcrunch.com/2012/03/29/google-now-using-recaptcha-...
BUT! These are actually easy to solve. reCAPTCHA will give you two words, only one of which it knows the ground truth on (it's using you to solve the other). It will accept any gibberish for the one word it doesn't know. I've made a point of trying to guess which one is the 'real' captcha (usually the more-distorted one), but next time you see Cyrillic or an integral, just mash the keyboard.
[1] http://www.troyhunt.com/2012/01/breaking-captcha-with-automa...
You actually don't have to get the latter one anything close to right; and I think you're given the option of at least one typo in the actual CAPTCHA test.
So when a CAPTCHA looks impossible, try doing the possible half and typing in "balls" for the other half. It actually works with pretty reasonable accuracy.
That doesn't help with the digitization of books. :)
Capchas are a pox on the web, and reCaptcha a sleazy immoral one, too.
Hilarity ensues.
Credit card forms are sometimes used that way too, they get a lot of extra information because if they don't, people feel that they're scammy.
I can't imagine coming up with your own clever hacked-together bogus CAPTCHA would be simpler than that. So they actually did it the hard way?
Some things we been doing for so long that we forget why we do them at all.
The reason you confirm a password is because you can't see the password, and so you never know if you mistyped it. Confirming an e-mail address, in a normal text field, is just stupid busywork.
So, elegantly, two different issues use the same simple solution.
The better solution is to send an e-mail with a confirmation link upon signup. This also protects against deliberately falsified e-mails, and against typing it incorrectly twice, and against folks who automatically copy & paste when they see "Confirm your..." And it's only a tab switch and click rather than having to key in a few dozen characters, which matters even more in the brave new mobile/tablet world.
Edit: Sorry I kind of misread your comment, but what I said is half relavent. None of the protections you state you get without forcing them to click the link before continuing.
A feature like this should probably be considered based on the expected type of user vs. the convenience of signing up quickly. Non-technical users where there isn't a significant dropoff from the signup form => probably a good idea.
<input name="actualSpoofValue" type="hidden" id="actualSpoofValue" value="TFU3P">
and TFU3P was the CAPTCHA code!
Lt. James Gordon: No, no, you can't! You're not! Batman: I'm whatever Gotham needs me to be.
[cut to Gordon at Dent's funeral]
Lt. James Gordon: A hero. Not the hero we deserved but the hero we needed. Nothing less than a knight. Shining.
[Gordon is shown on top of Gotham Central. An axe is in his hand. He is being watched by an assortment of reporters and police officers. The next lines are heard in voiceover]
Lt. James Gordon: They'll hunt you.
Batman: You'll hunt me. You'll condemn me. Set the dogs on me.
You circumvented COMPUTER SECURITY on a GOVERNMENT WEBSITE. This is how the judge will see it.
Extremely slow is a function of the interdependencies and the CYA (nobody gets fired for buying IBM).
And the unwillingness to replace is because nobody actually knows everything the current system does, much less how it does it. Projects that have 10+ year lifespans and touch every aspect of the business are incredibly scary to touch.
So, at some degree of distance, the internets get. the definition mostly correct, but the reason it has chosen (eg all enterprise developers are stupid) is as simplistic as every other conclusion the internets have come to. While there are many people writing code in IT dev shops who really should be analysts, there are also a lot of smart people working in environments constrained like nothing your average startup developer has ever seen.
I've been there, and the only way I'm going back is if it's the only way to keep a roof on my kids' heads. I'll go homeless myself first! :)
Several years ago when I was doing contract enterprise development work for various Fortune companies, EJB was all the rage in the Enterprise Java space. I started to feel a little rate pressure, so figured I'd better at least pick up a book and get up to speed.
About 3 chapters into it, I couldn't believe how bad it was (especially entity beans). I mean, it was almost like the perfect anti-pattern. Anyway, that didn't stop massive numbers of enterprises from jumping in head first, because it was sold as "the way" to do enterprise development. The tooling and app servers were insanely expensive too. But many IT managers didn't want to take any chances on not going the standard route.
Anyway, that about sums up enterprise software. Even for groups not into EJB specifically, the culture and thinking are the same. There is this meme that enterprise software must be more robust or scalable, etc., but the funny part is that consumer facing Web apps must typically be far more robust and dynamically scalable to serve much larger user bases. Enterprise software is typically run in a more tightly controlled environment too (specified required browser and OS, Intranet-based, etc.).
Yet, just labeling something "Enterprise" and targeting it as such, seems to command a premium.
It doesn't take long to find out that best practices exist for captchas, what they are, what the typical vulnerabilities are, and then pick one from the top shelf of existing solutions once you realize captchas are hard to do properly and you're probably not being paid what it's worth to roll your own.
Actually, even if it was real captcha, a computer could still easily guess the answer because the random parts are outside the answer text.
Maybe they assumed that bots would interpret the page the way a human being would, when they're not looking at the source code? Though my money's on someone just not caring.
Manager: Make me a captcha. Dev: We don't really need one, all we need is a simple way to avoid dumb automatic submits. M: Use a simple one, then.
... a few minutes later...
D: Here it is, the user just has to copy over those four letters. M: Hey this is not a captcha. It does not look like a captcha.
... a few minutes later...
D: Here it is, now it looks like a captcha.
On the other side, it could be very true that if you don't put some annoyances behind it, "normal" people don't recognize it as a captcha... And most of the time (on most custom low traffic sites...) you don't really need much more that a static "write the result of 2+2".
I've been there, I've already done it :-)
The problem is not how much effort to stop this one mistake, the problem is how much effort to stop every potential mistake of similar importance to this.
Or worse, perhaps they did get this from a shelf of existing solutions.
I'd like to believe that was impossible but of course given how irrational it would be to go through the trouble of making this, it's probably likely. Though I don't know why you'd necessarily skip over recaptcha and securimage and how far down the list you'd have to go to get to this sort of thing... but ZeljkoS has a couple more examples like it on his site. So apparently it's a captcha anti-pattern.
[1] admittedly questions like "type someword in this box to prove you're not a spambot"[2] rather than actual captchas, which I agree would be rather silly.
[2] if this is what you meant by a "printed in plain text in the source code" question, remember that most spambots aren't customised to an individual site, they just roam the internet submitting their crap to anything that looks like a comment form. Sure, it's trivial to write a script to parse the page and find the answer to the question - but nobody's actually going to do that for a typical company's "Contact Us" form. Adding this sort of check cuts down on spam enormously (from hundreds a day to zero), and is way easier for humans than solving a captcha.
This is not silly. This works extremely well for the low traffic forum I run. Since there are a huge number of phpbb3 forums out there, spammers have made spam bots specifically targeting the platform. If you make your forum epsilon different from the default then the bots don't work without manual intervention. That's enough to keep you off of autospam lists for very, very long periods of time.
And when someone inevitably adds your extra form element to their spam bot (it's happened to me 2 or 3 times over about 6 years) then you just change the answer and it stops working (and they might not even notice since it's a bot).
THe most common one I see is the integral symbol that used to be used as an S. On very rare occasions I see characters like:
¡™£¢∞§¶•ªº–≠œ∑®†¥øπ«åß∂ƒ©˙∆˚¬…æΩ≈ç√∫˜µ≤≥÷⁄€‹›fifl‡°·‚—±Œ„´‰ˇÁ¨ˆØ∏»ÅÍÎÏ˝ÓÔÒÚÆ¸˛Ç◊ı˜Â¯˘¿
Of course, the developer could have also just slapped RECAPTCHA on there and been done in even less time...
<!-- Layer contains table with 5 cols (width is divide by no of chars) contains Captcha Chars --> <div id="captchdiv" style="position:absolute; left:10; top:15;"> <TABLE BORDER="0" CELLSPACING="0" WIDTH="170" height="30"> <tr> <td width="34" align="center" valign="top"><span style="font-family:cursive; FONT-SIZE:13.2 pt; color:#FFFFFF; text-decoration:none;"> <b>L</b></span></td> <td width="34" align="center" valign="bottom"><span style="font-family: cursive; FONT-SIZE:13.2 pt; color: #FFFFFF; text-decoration: none;"> <b>K</b></span></td> <td width="34" align="center" valign="top"><span style="font-family: cursive; FONT-SIZE:13.2 pt; color: #FFFFFF; text-decoration: none;"> <b>T</b></span></td> <td width="34" align="center" valign="bottom"><span style="font-family: cursive; FONT-SIZE:13.2 pt; color: #FFFFFF; text-decoration: none;"> <b>F</b></span></td> <td width="34" align="center"><span style="font-family: cursive; FONT-SIZE:13.2 pt; color: #FFFFFF; text-decoration: none;"> <b>B</b></span></td>
</tr> </table></div>
Are you fucking serious?
Your response implies that they are inept at their area of expertise.
They also try to upsell you to one of the many other plans starting at $299. To somewhat soften their touch the basic service is free after all. And the expedited service is free for businesses considering doing government contracting (maybe we should all consider this as we apply to the Apple developer program).
There is no impact on the user except a better user experience.
The corporate developer may have looked at the spam levels and decided that a basic measure would be fine considering the exposure to the page, or other reasons.
CAPTCHA is anti-people. It's a step back to the dark ages every time a website asks you to type in a fuzzy word, often just a jumbled string making it even worse for reading.
Surprised some comments are taking aim at the developer, who at least isn't using the stupidly backwards, barely visible full version of captcha. Check en.wikipedia.org/wiki/CAPTCHA it's a joke that the examples posted there seem so much easier than the overly-abstract usual suspects out there in reality. That wikipedia article needs a new section, something like 'criticisms' or 'UX Fail'.
D&B's 'captcha' is whack? So is Google's.
People must prove they are people. And spam crawlers don't need to prove anything. Turing wouldn't have liked his name associated with a test that humans fail often (needing to refresh the captcha), and a test that machines must fail in order to be effective.
<span id="code-desc">Next, return to TrainerLists and enter this PIN to complete the authorization process:</span>
<kbd aria-labelledby="code-desc"><code>7996044</code>
This is a cpf (something like social security number in brazil) validator from this site: http://via7solucoes.com.br/curriculos/cadastro.asp
Really, the only thing wrong with this picture is that they got called out on HN, so now whoever is doing the automated lookups won't be able to kill off D&B by releasing their information.
Edit: Just listen to it:
Em is for emphasis.
As for the older tags, they were deprecated in XHTML, but have been redeemed in HTML 5. <i> is used for elements that are traditionally set it italics but are neither emphasized nor citations. Often that will be foreign words (where one ought to use a lang attribute). Similarly <b> is used to indicate elements that are traditionally set in bold face, but which do not indicate importance (as headings or <strong> in running text would do). Both are better than the semantically-meaningless <span> tag, and vastly better than misusing the <em>, <cite> and <strong> tags for their presentation effects.
I could even use <strong style="font-weight: normal" /> if I wanted to emphasize something without making it bold. Because that has a functional purpose with screen readers, and isn't strictly a styling thing.
(There's some crazyness where they actually become <em> tags in China and are styled differently, because Chinese typographical conventions avoid bolding characters and instead turn them red for emphasis. I tried to simplify this once and do everything via CSS, but it turns out to be quite complicated because you also have to handle the case of interface text that's not in Chinese and supposed to be bolded, and exceptions for single-character words, and mixed English/Chinese text, and other languages like Arabic that run RTL, and mixed Arabic/English text, and presumably mixed Arabic/Chinese text though I've never seen such a page. It turns out CSS is fairly limited when you get into the complexities of human typographical conventions across the globe.)
"What is 2+4?"
...or isn't it?
You are guaranteed to get scammy-sounding emails and phone calls from D&B after signing up. Emails with subjects like "Your business is in danger!" or messages like "Your business credit report has some big issues!" and you find out that in order to get "protection" or to find out what these "issues" are, you have to pay Dun and Bradstreet a shitload of money.
That company is a SCAM and a perfect example of how completely retarded/bought-and-paid-for the United States government is.
The startup crowd doesn't see it much, but D&B is a critical component of how non-technical medium to large businesses vet each other and prevent fraud. They are effectively the Better Business Bureau for B2B.