Lifelesspeople.com

 Forum FAQsForum FAQs  Knowledge BaseKnowledge Base  RulesRules   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   HostingHosting   RegisterRegister 
 DonateDonate   WikiWiki   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Impossible CAPTCHAs: Part II
Goto page 1, 2  Next
 
Lifelesspeople.com Forum Index -> Local Bistro
Post new topic   Reply to topic View previous topic :: View next topic  
Author Message
LP-Harvey
Forum Moderator


Joined: 23 Feb 2004
Posts: 3287


PostPosted: Thu Jan 31, 2008 4:12 pm    Post subject: Impossible CAPTCHAs: Part II Reply with quote

A continuation of this thread: http://www.lifelesspeople.com/.....hp?t=46127

Russian security researchers have developed a way to crack the most popular usage of CAPTCHAs, originally developed by IT analysts at Carnegie Melon University.

In the article, the group claims that their crack has a 35% success rate.

While some might scoff at 35%, that's still a VERY large number. Is it time to replace standard image CAPTCHAs with logic CAPTCHAs?
Back to top
 
krt
...


Joined: 11 Jan 2005
Posts: 4780
Location: Down Under

PostPosted: Thu Jan 31, 2008 6:44 pm    Post subject: Reply with quote

I doubt anyone who has the slightest understanding of bots would scoff at 35%. Anyway, I had a look at Yahoo's CAPTCHA and this crack seems to be pretty impressive, as Yahoo's seems to be one of the better ones in terms of usability/obscurity.

Anyway, it was bound to happen and probably did happen before without being publicised. I'm not so sure about your suggestion of logic CAPTCHAs, it seems to assume a level of competence many end users do not have.
_________________
AU Proud
Back to top
 
jthomsonmain
Ardent Poster


Joined: 11 Jan 2008
Posts: 80
Location: Albion, NY (USA)

PostPosted: Sat Feb 02, 2008 12:14 am    Post subject: Reply with quote

I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs
_________________
[img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c]
Back to top
 
Rashy
Lifeless Person


Joined: 25 Sep 2006
Posts: 731


PostPosted: Sat Feb 02, 2008 12:35 am    Post subject: Reply with quote

Second on rapidshare, but they might not be around for much longer anyway...

I think we need to install logic CAPTCHAs that are just difficult enough to keep the trolls and other idiots from posting. Such as: what is the indefinite integral of sin(x)^4 Very Happy
_________________
Rashy!
Back to top
 
jthomsonmain
Ardent Poster


Joined: 11 Jan 2008
Posts: 80
Location: Albion, NY (USA)

PostPosted: Sat Feb 02, 2008 12:08 pm    Post subject: Reply with quote

Na, I think 2+5 would be hard enough to keep most idiots out...
_________________
[img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c]
Back to top
 
Pie32
Not Banned


Joined: 17 Mar 2005
Posts: 1443
Location: Lost in 84

PostPosted: Sat Feb 02, 2008 8:12 pm    Post subject: Reply with quote

jthomsonmain wrote:
I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs

Right now Rapidshare has really easy to read CAPTCHAs.
_________________
[img]http://luneknight.com.ru/counter.jpg[/img]
Random Battle: [img]http://luneknight.com.ru/l.jpg[/img] vs. [img]http://luneknight.com.ru/r.jpg[/img]
Back to top
 
jthomsonmain
Ardent Poster


Joined: 11 Jan 2008
Posts: 80
Location: Albion, NY (USA)

PostPosted: Sun Feb 03, 2008 3:56 pm    Post subject: Reply with quote

Pie32 wrote:
jthomsonmain wrote:
I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs

Right now Rapidshare has really easy to read CAPTCHAs.

Right now, yes, but they didn't a few months ago.
_________________
[img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c]
Back to top
 
Jacky
3.14159265358979323846264


Joined: 01 Jan 2005
Posts: 3893


PostPosted: Wed Feb 06, 2008 3:21 am    Post subject: Reply with quote

jthomsonmain wrote:
I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs

It's CAPTCHA, not CAPCHICA.
_________________
ClickFanatic wrote:
Your nonsense make my forum visits rather brief, Jacky. It's like:
"Hey look, a reply notification!"
*click* *click*
*reading garbage*
"Oh it was Jacky again..."
*close*
Back to top
 
jthomsonmain
Ardent Poster


Joined: 11 Jan 2008
Posts: 80
Location: Albion, NY (USA)

PostPosted: Wed Feb 06, 2008 1:50 pm    Post subject: Reply with quote

Jacky wrote:
jthomsonmain wrote:
I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs

It's CAPTCHA, not CAPCHICA.

Yea, I know, thanks for pointing it out. Im just totally out of it most days.
_________________
[img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c]
Back to top
 
Voldemort
Unhandled Exception


Joined: 27 Apr 2005
Posts: 948
Location: In a Galaxy far, far away

PostPosted: Wed Feb 06, 2008 3:27 pm    Post subject: Reply with quote

The best thing would be asking one or two questions I think.. Finding synonyms for simple words, doing simple calculations or things like that... Very Happy
_________________
It's beginning to look a lot like Christmas
Everywhere you go;
Take a look in the five and ten glistening once again
With candy canes and silver lanes aglow..

(It's beginning to look a lot like Christmas)
Back to top
 
jthomsonmain
Ardent Poster


Joined: 11 Jan 2008
Posts: 80
Location: Albion, NY (USA)

PostPosted: Wed Feb 06, 2008 5:49 pm    Post subject: Reply with quote

I saw one today that had four images and asked you to pick the correct image. Easy and hackproof (ish)
_________________
[img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c]
Back to top
 
Celvaeti
Portuguese Hypnotist


Joined: 19 Aug 2004
Posts: 1279


PostPosted: Wed Feb 06, 2008 6:37 pm    Post subject: Reply with quote

Oh, come on, are there no xkcd members on Lifeless People? The CAPTCHA problem has already been solved, thanks to contributions from the wonderful mind of Randall Munroe.

...on a serious note, yeah, there's no real easy way out of the CAPTCHA problem. OCRs are improving every day, chewing through randomly obfuscated text with relative ease. Alternatives, such as simple math problems or the like, take very little time to crack, and since generally people do not write their own CAPTCHAs, it's a nasty case of "write once, spam everywhere".
Back to top
 
krt
...


Joined: 11 Jan 2005
Posts: 4780
Location: Down Under

PostPosted: Thu Feb 07, 2008 6:17 pm    Post subject: Reply with quote

jthomsonmain wrote:
I saw one today that had four images and asked you to pick the correct image. Easy and hackproof (ish)

That would require a high number of images otherwise a bot could simply identify every image in its own database. Also, 4 images could be bypassed with trial and error.
Back to top
 
spock
iSpock


Joined: 23 Mar 2005
Posts: 2947
Location: The Netherlands

PostPosted: Fri Feb 08, 2008 7:22 am    Post subject: Reply with quote

krt wrote:
Also, 4 images could be bypassed with trial and error.

True, but with a chance of 25%, still blocking 75%. So if it's just for a really small sites where bots and spam problems aren't that big, it is an option. Especially as that method is quite userfriendly.
_________________
My new site
My OpenTTD data package
Back to top
 
ClickFanatic
Est. 2005


Joined: 18 Jan 2005
Posts: 4135
Location: A particular geographic area

PostPosted: Fri Feb 08, 2008 11:24 am    Post subject: Reply with quote

spock wrote:
krt wrote:
Also, 4 images could be bypassed with trial and error.

True, but with a chance of 25%, still blocking 75%. So if it's just for a really small sites where bots and spam problems aren't that big, it is an option. Especially as that method is quite userfriendly.

Exactly, it's simple math. If the OCR has a 35% succes rate on single images (ie. a chance of 0.35 per image), then the chance of breaking 4 CAPTCHAs in a row is 0.35^4 = 0.015.
1.5% isn't that much. However, it is important to consider that users will have to type 4 CAPTCHAs (or one that is 4 times as long). It is annoying.
_________________
Captain Jell-O Buster from the Future
[img]http://feeds.feedburner.com/sparepencil.1.gif[/img]
Back to top
 
Display posts from previous:   
Post new topic   Reply to topic    Lifelesspeople.com Forum Index -> Local Bistro All times are GMT - 6 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Home | Hosting | News | Forum | Links | System Status | About | Archive | Donate ]
Powered by phpBB © 2001, 2002 phpBB Group
All trademarks and copyrights on this page are owned by their respective owners. Posts and comments are owned by the poster. Everything else © 2001 - 2007 Lifelesspeople.com