“No-CAPTCHA” reCAPTCHA
google.com
google.com
Obviously there are privacy concerns. That being said, this looks like a boon for anyone interested in bot detection, as you can periodically challenge your users' humanity without getting too much in their way. Nice one, Google.
From the thread:
Implemented it successfully for a website. I have to say, it works great!
it also checks if html pages are changed at runtime and how many times you "reload" the page where the captcha is. When it thinks you are a bot a captcha popups, when entered, it got checked on googles servers if it's right and fills in a hidden input. When the user submits the form, the filled in captcha coded, again, will be verifed. [sic]
[0] http://www.google.com/recaptcha/api2/demo
[1] Edit: don't go to this url without adblock (see comment below). http://forum.ragezone com/f144/googles-captcha-recaptcha-1023607/
- http://www.bbc.com/news/technology-12772319
- http://money.cnn.com/2012/03/26/technology/microsoft-raid/
- http://www.allspammedup.com/2013/06/microsoft-and-fbi-take-d...
Facebook sues spammers:
- http://www.theverge.com/2014/10/3/6901293/facebook-has-sued-...
They can enjoy my content for free no problem, but I really don't care what they have to say in regards to how I run things or have things set up.
"Fuck you, pay me" comes to mind
This is probably different for larger sites of course but on our scale there's no worries blocking Tor
Edit: Although thinking about it I don't know any ads that aren't served up without some form of Javascript
Actually I don't think Tor disables javascript by default anymore, but even when I do disable it I still see ads.
"Since it goes through Google's servers, they can verify a lot of things. Whether you are logged in currently to google, have you been logged in the past, verify your activity on your IP address, etc. Even if you signed in from the same ip or ip range like a year ago, they can still tell it's you based on your previous actions."
If I click from a normal tab I don't see a captcha, but I click from a privacy tab I do.
If captchas got simpler, you could still do Mechanical Turk jobs if you wanted to.
But for at least a couple of months now I haven't seen a two variable captcha. I can only assume every captcha has been solved and verified to a reasonable degree of certainty. If Google, who is probably most able to benefit off of captcha solutions is willing to move past it I can't really argue with them.
Also, if you look really suspicious (particularly if you fail an easier CAPTCHA, or ask for lots of challenges), Google will still give you one of the old two-scrambled-words CAPTCHAs. Except both of the words are ones they know the answers for, and you'll have to enter them both correctly to pass.
(As a note, I'm browsing using a private window)
Based on what? It assumes the same for me. There's zero information anywhere. When does it assume you're a human?
The problem is that the OP posted nothing at all.
It sounds like others are seeing something different however?
It's a trick I learned from industrial SCADAs. Sometimes buttons simulate how a literal contractor works by watching for down-debounce-up events. No idea if that's the case here, but it seems to help to dwell slightly on the button to let the event thing really catch the event fer sure.
I'm not sure if these are manually solved from people hired to just solve captchas or if perhaps it's a bit too lenient. Ultimately I think the improved usability is more important than spending a bit more effort deleting spam.
I think asking really simple questions that only a human could understand seems to get the job done most of the time.
Perhaps something like: "What is the opposite of bad?" or "How many planet Earths are there?"
I've used things like this for a handful of projects and have never had any problems: https://github.com/kiskolabs/humanizer
What is the most widely used project you have successfully used it on?
They have created interesting methods to combat Captcha images. They even have outsourced OCR services, where people in other countries are paid to solve ocr 1 image at a time. [0]
Basically, whoever answers most of these questions correctly, earns $15,000. People submit MILLIONS of answers.
This list is then incorporated into the Xrumer itself.
I can tell you that these things are easily broken: a) Answering questions and building global list of answers, as in this case. b) Reading image captcha - spammers send it to Pakistani manual solvers for dirt cheap. c) More complex puzzle captchas can also be broken in software if a lot of websites implement them.
What works the best is using non standard html form field names. Also, try to not use text labels for the fields ( no "password", "captcha" etc. ) - because the software will try to match the best field by text surrounding it. It is better to use image for labels.
This solution will stop spambots because they simply match form field names. Unless someone specifically targets your website, in which case there's not much you can do.
From the most common of captchas, Mollom seemed to be the biggest pain in the ass for spammers. Mainly because it banned suspicious IPs ( you could solve the picture correctly and it wouldn't authorize it. )
Except browser autofill breaks and anyone who needs a screen reader will go elsewhere if the screen reader can't parse the images.
"Either one or probably infinity, depending on whether the universe is infinitely sized and whether unobservable parts of it are considered to 'exist'."
That's the hard thing about captchas, bots don't have to solve them perfectly to completely break them.
Amusingly, the examples they give are actually readable. Most of the time, when I see a CAPTCHA displayed, it's not a word, or anything close to a word. I've seen ink smudges, math symbols, and Cyrillic.
Besides, machine learning is good enough now it can beat most people at CAPTCHA solving. Look on Black Hat World for the software.
I hope Cloudflare soon adopts it for their anti-bots protection – my home connection is often flagged as malicious on a few websites.
CloudFlare does not actively block visitors who use the Tor network.
Due to the behavior of some individuals using the Tor network (spammers, distributors of malware, attackers, etc.), the IP addresses of Tor exit nodes generally earn a bad reputation. Our basic protection level issues captcha-based challenges to visitors whose IP address has a high threat score.
https://support.cloudflare.com/hc/en-us/articles/203306930-D...
I've often had problems when using a VPN too.
Just fill one word and put some random crap for the other and you just halved the annoyance.
This one is better.
Mine was a list of boxes with similar pictures in them, and ask the users a question.
* Choose the only dog
* Choose the cars
* Choose everything but the men in these pictures
Microsoft then created something similar a few years later but then killed it, I still think this was a better way than OCR type stuff. http://research.microsoft.com/en-us/projects/asirra/
Here is a demo http://www.google.com/recaptcha/api2/demo
The old version used to be customisable so I really hope Google adds the ability to customise this soon.
Another trivial but important oversight: the captcha has a background color of f9f9f9 but the fallback captcha has a background color of ffffff. So even if you try and style around it unless you manually detect what kind of captcha is showing and change the background color on the fly one of them is going to look off.
"reCAPTCHA offers more than just spam protection. Every time our CAPTCHAs are solved, that human effort helps digitize text, annotate images, and build machine learning datasets. This in turn helps preserve books, improve maps, and solve hard AI problems. "
They're using captchas to solve text analysis and digitizing problems.
It is much more convenient and painless from a user's PoV but I'm a bit surprised it actually stops bots.