| Author |
Message |
LP-Harvey Forum Moderator

Joined: 23 Feb 2004 Posts: 3287
|
Posted: Thu Jan 31, 2008 4:12 pm Post subject: Impossible CAPTCHAs: Part II |
|
|
A continuation of this thread: http://www.lifelesspeople.com/.....hp?t=46127
Russian security researchers have developed a way to crack the most popular usage of CAPTCHAs, originally developed by IT analysts at Carnegie Melon University.
In the article, the group claims that their crack has a 35% success rate.
While some might scoff at 35%, that's still a VERY large number. Is it time to replace standard image CAPTCHAs with logic CAPTCHAs? |
|
| Back to top |
|
| |
krt ...

Joined: 11 Jan 2005 Posts: 4780 Location: Down Under
|
Posted: Thu Jan 31, 2008 6:44 pm Post subject: |
|
|
I doubt anyone who has the slightest understanding of bots would scoff at 35%. Anyway, I had a look at Yahoo's CAPTCHA and this crack seems to be pretty impressive, as Yahoo's seems to be one of the better ones in terms of usability/obscurity.
Anyway, it was bound to happen and probably did happen before without being publicised. I'm not so sure about your suggestion of logic CAPTCHAs, it seems to assume a level of competence many end users do not have. _________________
 |
|
| Back to top |
|
| |
jthomsonmain Ardent Poster

Joined: 11 Jan 2008 Posts: 80 Location: Albion, NY (USA)
|
Posted: Sat Feb 02, 2008 12:14 am Post subject: |
|
|
I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs _________________ [img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c] |
|
| Back to top |
|
| |
Rashy Lifeless Person
Joined: 25 Sep 2006 Posts: 731
|
Posted: Sat Feb 02, 2008 12:35 am Post subject: |
|
|
Second on rapidshare, but they might not be around for much longer anyway...
I think we need to install logic CAPTCHAs that are just difficult enough to keep the trolls and other idiots from posting. Such as: what is the indefinite integral of sin(x)^4  _________________ Rashy! |
|
| Back to top |
|
| |
jthomsonmain Ardent Poster

Joined: 11 Jan 2008 Posts: 80 Location: Albion, NY (USA)
|
Posted: Sat Feb 02, 2008 12:08 pm Post subject: |
|
|
Na, I think 2+5 would be hard enough to keep most idiots out... _________________ [img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c] |
|
| Back to top |
|
| |
Pie32 Not Banned

Joined: 17 Mar 2005 Posts: 1443 Location: Lost in 84
|
Posted: Sat Feb 02, 2008 8:12 pm Post subject: |
|
|
| jthomsonmain wrote: | | I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs |
Right now Rapidshare has really easy to read CAPTCHAs. _________________ [img]http://luneknight.com.ru/counter.jpg[/img]
Random Battle: [img]http://luneknight.com.ru/l.jpg[/img] vs. [img]http://luneknight.com.ru/r.jpg[/img] |
|
| Back to top |
|
| |
jthomsonmain Ardent Poster

Joined: 11 Jan 2008 Posts: 80 Location: Albion, NY (USA)
|
Posted: Sun Feb 03, 2008 3:56 pm Post subject: |
|
|
| Pie32 wrote: | | jthomsonmain wrote: | | I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs |
Right now Rapidshare has really easy to read CAPTCHAs. |
Right now, yes, but they didn't a few months ago. _________________ [img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c] |
|
| Back to top |
|
| |
Jacky 3.14159265358979323846264

Joined: 01 Jan 2005 Posts: 3893
|
Posted: Wed Feb 06, 2008 3:21 am Post subject: |
|
|
| jthomsonmain wrote: | | I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs |
It's CAPTCHA, not CAPCHICA. _________________
| ClickFanatic wrote: | Your nonsense make my forum visits rather brief, Jacky. It's like:
"Hey look, a reply notification!"
*click* *click*
*reading garbage*
"Oh it was Jacky again..."
*close* |
|
|
| Back to top |
|
| |
jthomsonmain Ardent Poster

Joined: 11 Jan 2008 Posts: 80 Location: Albion, NY (USA)
|
Posted: Wed Feb 06, 2008 1:50 pm Post subject: |
|
|
| Jacky wrote: | | jthomsonmain wrote: | | I have seen ALOT of crappy CAPCHICAs that make it near impossible for the user to actually read it. Rapidshare (no, I dont use it for warezing, I have it for legitimate file sharing) had some REALLY bad CAPCHICAs |
It's CAPTCHA, not CAPCHICA. |
Yea, I know, thanks for pointing it out. Im just totally out of it most days. _________________ [img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c] |
|
| Back to top |
|
| |
Voldemort Unhandled Exception

Joined: 27 Apr 2005 Posts: 948 Location: In a Galaxy far, far away
|
Posted: Wed Feb 06, 2008 3:27 pm Post subject: |
|
|
The best thing would be asking one or two questions I think.. Finding synonyms for simple words, doing simple calculations or things like that...  _________________ It's beginning to look a lot like Christmas
Everywhere you go;
Take a look in the five and ten glistening once again
With candy canes and silver lanes aglow..
(It's beginning to look a lot like Christmas) |
|
| Back to top |
|
| |
jthomsonmain Ardent Poster

Joined: 11 Jan 2008 Posts: 80 Location: Albion, NY (USA)
|
Posted: Wed Feb 06, 2008 5:49 pm Post subject: |
|
|
I saw one today that had four images and asked you to pick the correct image. Easy and hackproof (ish) _________________ [img:8728bad64c]http://i212.photobucket.com/albums/cc118/jthomsonmain/l2psig.jpg[/img:8728bad64c] |
|
| Back to top |
|
| |
Celvaeti Portuguese Hypnotist

Joined: 19 Aug 2004 Posts: 1279
|
Posted: Wed Feb 06, 2008 6:37 pm Post subject: |
|
|
Oh, come on, are there no xkcd members on Lifeless People? The CAPTCHA problem has already been solved, thanks to contributions from the wonderful mind of Randall Munroe.
...on a serious note, yeah, there's no real easy way out of the CAPTCHA problem. OCRs are improving every day, chewing through randomly obfuscated text with relative ease. Alternatives, such as simple math problems or the like, take very little time to crack, and since generally people do not write their own CAPTCHAs, it's a nasty case of "write once, spam everywhere". |
|
| Back to top |
|
| |
krt ...

Joined: 11 Jan 2005 Posts: 4780 Location: Down Under
|
Posted: Thu Feb 07, 2008 6:17 pm Post subject: |
|
|
| jthomsonmain wrote: | | I saw one today that had four images and asked you to pick the correct image. Easy and hackproof (ish) |
That would require a high number of images otherwise a bot could simply identify every image in its own database. Also, 4 images could be bypassed with trial and error. |
|
| Back to top |
|
| |
spock iSpock

Joined: 23 Mar 2005 Posts: 2947 Location: The Netherlands
|
Posted: Fri Feb 08, 2008 7:22 am Post subject: |
|
|
| krt wrote: | | Also, 4 images could be bypassed with trial and error. |
True, but with a chance of 25%, still blocking 75%. So if it's just for a really small sites where bots and spam problems aren't that big, it is an option. Especially as that method is quite userfriendly. _________________ My new site
My OpenTTD data package |
|
| Back to top |
|
| |
ClickFanatic Est. 2005

Joined: 18 Jan 2005 Posts: 4135 Location: A particular geographic area
|
Posted: Fri Feb 08, 2008 11:24 am Post subject: |
|
|
| spock wrote: | | krt wrote: | | Also, 4 images could be bypassed with trial and error. |
True, but with a chance of 25%, still blocking 75%. So if it's just for a really small sites where bots and spam problems aren't that big, it is an option. Especially as that method is quite userfriendly. |
Exactly, it's simple math. If the OCR has a 35% succes rate on single images (ie. a chance of 0.35 per image), then the chance of breaking 4 CAPTCHAs in a row is 0.35^4 = 0.015.
1.5% isn't that much. However, it is important to consider that users will have to type 4 CAPTCHAs (or one that is 4 times as long). It is annoying. _________________ Captain Jell-O Buster from the Future
[img]http://feeds.feedburner.com/sparepencil.1.gif[/img] |
|
| Back to top |
|
| |
|
|
|