News: 1658405712

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

DataDome looks to CAPTCHA the moment with test of humanity that doesn't hurt

(2022/07/21)


Apple last month gave hope to a large segment of the mobile device-using population when it announced that the upcoming iOS 16 operating system will eliminate the requirement to use CAPTCHAs to verify their humanity before accessing a website.

The advent of the [1]Automatic Verification feature will mean that users of iOS 16 devices will no longer have to hunt and peck when selecting which pictures in a set show a car or crosswalk, or decipher a distorted set of letters and numbers, to prove they are not a nefarious bot.

Instead, the OS will automatically verify devices and Apple ID accounts, without requiring user intervention. Apple's actions created such jubilant headlines as [2]"A Eulogy for the CAPTCHA" (on Gawker ) and [3]"iOS verification update marks the end of 'captchas'" ( The Guardian ).

[4]

However, DataDome – a seven-year-old company whose job it is to protect websites, mobile apps and APIs from online fraud and automated threats (including bots) – doesn't believe the end of CAPTCHA is nigh. On Wednesday the company introduced its own CAPTCHA tool, which officials claim is faster and more secure than Google's reCAPTCHA (which DataDome has been using for several years) and offers better privacy and an improved user experience.

[5]

[6]

With other technologies it's developed, DataDome can automatically verify 99.99 percent of users without having to resort to CAPTCHA, co-founder and CEO Benjamin Fabre told The Register .

"When DataDome has some concern about the requests that might be automated, that might come from an attacker, then we will block the request and we can leverage in some situations CAPTCHA to prevent those bots and to grant access to the websites if it's a false positive," Fabre said. "In that case, 0.01 percent of the time, we use CAPTCHA to access the website."

[7]A great day for non-robots: iOS 16 will bypass CAPTCHAs

[8]Your AI can't tell you it's lying if it thinks it's telling the truth. That's a problem

[9]How CAPTCHAs can cloak phishing URLs in emails

[10]To CAPTCHA or not to CAPTCHA? Gartner analyst says OK — but don't be robotic about it

While developing its own CAPTCHA, DataDome listened to complaints from companies and users about reCAPTCHA. Surveyed sentiments ranged from a poor user experience – and a resulting impact on the conversion rate of ecommerce sites – to privacy, with the worry being that Google's main focus is ads and not security. Google also uses data from its reCAPTCHA service to train AI algorithms, Fabre said, adding that cybercriminals could use AI to train their bots to get around reCAPTCHA.

Another [11]security concern : threat groups also use cheap labor in so-called "CAPTCHA farms" to answer a lot of CAPTCHA puzzles for low wages.

[12]

DataDome's CAPTCHA involves the user being shown a picture puzzle with a missing piece and sliding that piece into place. While loading and solving a Google reCAPTCHA takes an average of 22.1 seconds, the company says the average time to complete a DataDome CAPTCHA is 3.1 seconds.

The key to DataDome's verification tech is behavioral detection models that track a user's web session from the start – collecting signals ranging from the screen size and resolution of the device to the CPU or GPU it's running and the history of the pages that device goes to when on the site. If anomalies indicate a bot is trying to access the site, DataDome's technology may move the session to a CAPTCHA.

Even then, the signals will indicate whether it's the legitimate user or something else using DataDome CAPTCHA.

[13]

"It's not only about if the CAPTCHA is solved," Fabre said. "It is how you pass the CAPTCHA and that's what we are doing. It's behavioral detection. It's not just that you slide it properly, but how you slide on the page. How did you move your mouse on the page? What was your device? What was your policy? What was the size and the resolution of your screen? What's all the plugins set up on the device?"

DataDome is "collecting thousands of different signals to understand if the CAPTCHA was passed by the user or by a bot or by the human that is working for the bots," he said.

About 40 percent of DataDome's 250-plus enterprise customers – which include The New York Times, Tripadvisor, Reddit, and Foot Locker – are using the new CAPTCHA and more will adopt it, Fabre said.

Whether DataDome's technology calms the debate about CAPTCHA is unclear. Darryl MacLeod, vCISO at Lares Consulting, told The Register that the CAPTCHA ship has not sailed despite the criticism.

"CAPTCHA is still a very effective authentication tool," MacLeod said. "While it is true that there are other authentication methods available, CAPTCHA remains a popular option due to its ease of implementation and a high degree of security. Many users are already familiar with CAPTCHA and find it easy to use, so it is likely to remain in use for the foreseeable future."

Others are not as sure. Bud Broomhead, CEO of cybersecurity company Viakoo, told The Register that CAPTCHA doesn't fit in a world shifting to passwordless authentication and zero-trust architectures. In addition, Apple's Automatic Verification feature is the latest proof that certificates can scale as an authentication approach.

"It's always been a way to answer the question of whether the user is organic or silicon rather than a secure authentication method," Parkin told The Register . "While it may be possible to fix it, the question is whether it's worth fixing, or whether it's time to find a new solution." ®

Get our [14]Tech Resources



[1] https://www.theregister.com/2022/06/21/believe_it_or_not_apple/

[2] https://www.gawker.com/news/net-positive-a-eulogy-for-the-captcha

[3] https://www.theguardian.com/technology/2022/jun/21/ios-verification-update-captchas-apple-iphone?utm_term=62b1abbd6e551f1c626f6ba7e921be64&utm_campaign=GuardianTodayUS&utm_source=esp&utm_medium=Email&CMP=GTUS_email

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ytl4Isgue-GxOvx4FBhbHgAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ytl4Isgue-GxOvx4FBhbHgAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ytl4Isgue-GxOvx4FBhbHgAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/06/21/believe_it_or_not_apple/

[8] https://www.theregister.com/2022/04/25/machine_learning_verification/

[9] https://www.theregister.com/2022/03/17/captcha_phishinbg_url/

[10] https://www.theregister.com/2021/06/22/to_use_captcha_or_not/

[11] https://www.theregister.com/2022/03/17/captcha_phishinbg_url/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ytl4Isgue-GxOvx4FBhbHgAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ytl4Isgue-GxOvx4FBhbHgAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



DataDome behavioural analysis

OhForF'

>DataDome is "collecting thousands of different signals"<

DataDome is using thousands of signals and analyses my behavior when i access a web site to figure out if i'm a real user or bot.

Why is this even necessary and is it worth the effort?

In my opinion its definitely not a valid reason for browsers to provide all those signals - those signals shouldn't even be available.

I'd rather deal with the occasional captcha than sending all that data for analysis.

What valid uses cases are there where you need to distinguish between real users and bots and where its not better to just ask the users to actually log in?

Re: DataDome behavioural analysis

Anonymous Coward

> What valid uses cases are there where you need to distinguish between real users and bots and where its not better to just ask the users to actually log in?

On the login page

Re: DataDome behavioural analysis

tiggity

So probably running lots of js for its metrics

.. unless js blocked

I wonder if it even works at all with js blocked?

I block lots of js, & dont see captchas, probably because sites that are likely to demand a captcha break so badly when I'm accessing it with my standard dubious 3rd party script blocks that I leave the site and go elsewhere (too many sites give a blank or minimal page with a lot of js disabled, when that happens I leave*)

* There's too much shoddy design of js for everything, you can give basic information and functionality with HTML and just use js for non essential bells & whistles (or user experience improvements as the BS merchants would call it)

Why is this even necessary

Mike 137

Possibly because they can see a way to monetise the data?

I see no good reason for a 3rd party service to decide whether they think I'm a bot or not, and I can see this automation backfiring with large numbers of fallacious validations.

The growing and non-circumventable intrusion of intermediaries between me and what I want to see on the web is not only making things more fragile - it's also contracting the view of what's out there. Such intermediaries include (obviously) search engines with proprietary agendas, but also 3rd party components that only work on the latest client side kit. So we're creating a 'digital divide' between a majority who constantly upgrade and browse will no protections and an increasingly devalued minority who either use older kit or are security aware (or both). Also yet another example of the [1]'ignorance amplifier' identified by Mark Pesce (taking the decision out of our hands so we lose the ability to decide).

[1] https://www.theregister.com/2022/07/20/mark_pesce_40_years_in_tech/

Re: Why is this even necessary

Headley_Grange

As a simple end-user of websites I wholeheartedly agree, but I assume that there are other people and companies out there who, without some sort of defence, would get bombarded with sign-ups, queries, scraping, messages, and whatever else bots do make life miserable or your website slow and unuseable.

I don't like captchas cos they are annoying and, I believe, mean that I'm giving free help to Google to train their AIs. If there are better ways to do it then I'm sure someone will come along soon and educate me.

Re: Why is this even necessary

Mike 137

" If there are better ways to do it

There certainly are. Just a cursory look at a Gooooooogle captchas show how little thought has gone into them - not least the absolute US bias in the images, which takes for granted, for example, that everyone in the world knows what an american street sign means. Admittedly, every time we come up with a person vs. bot discriminator, the bot folks will try to find a way for their bots to pass it, but the most human attribute we have in this context (which AI doesn't have) is common sense, so that could be a good basis for the task - and probably less of a nuisance to humans as it can incorporate humour.

Unless I'm required

M.V. Lipvig

to sign into a work website with a captcha-like system, I won't do it. A US-based automotive performance parts company associated with mountaintops routinely expects me to prove I'm a people just looking for parts. As soon as that screen goes up I close the window and send them an email detailing how much I just spent with a competitor. This year alone it's cost them 5,000USD in sales just from me. It's not my job to stop bots, it's their job, and I'm not doing it for them unless they want to pay my short-term contractor rate.

Re: Unless I'm required

Mike 137

" This year alone it's cost them 5,000USD in sales

Sadly, the person who reads your email doesn't give two hoots about the loss of your business, and almost certainly they won't pass it to anyone who might. The isolation of business decision makers from the customer is so vast these days it's practically impossible to get their attention - about the only way is a law suit, and even that may not bring home the real point you're trying to make as it will be handled by the legal department whose sole interest is defeating you. The primary function of 'customer relations' and 'complaints' departments is to reject criticism and ignore customer concerns.

Locked inside an apple

Pete 2

> Apple's Automatic Verification feature is the latest proof that certificates can scale as an authentication approach.

Which relies on a person using an Apple device with their Apple account and running an Apple approved app

Where does this leave the freedom that the internet is supposed to be advocating?

Fingerprinting

Randesigner

"The key to DataDome's verification tech is behavioral detection models that track a user's web session from the start – collecting signals ranging from the screen size and resolution of the device to the CPU or GPU it's running and the history of the pages that device goes to when on the site.

So fingerprinting and tracking. How is this different than what Google does? How does this protect privacy? Really... how is this better?

The bottom line is that any piece of javascript can read the contents of anything that is displayed on a page and send it back to the mothership. I just love captchas on the order confirmation page of some websites. Such valuable information to be gathered.

Nobody takes a bribe. Of course at Christmas if you happen to hold out
your hat and somebody happens to put a little something in it, well, that's
different.
-- New York City Police Commissioner (Ret.) William P.
O'Brien, instructions to the force.