So much for CAPTCHA then – bots can complete them quicker than humans
- Reference: 1692102477
- News link: https://www.theregister.co.uk/2023/08/15/so_much_for_captcha_then/
- Source link:
The bot defense measure dates back to 1997 and the tortured acronym 2003, with the technology starting out as a distorted series of letters and/or numbers. Google's implementation, reCAPTCHA, eventually did away with much of these shenanigans to make the browser identify low-risk human users in the background, but the image verification method still pops up occasionally if risk cannot be ascertained.
Normal people see them as a time-waster, web devs see them as a crucial defense against bots, and criminals see them just as another obstacle to be hurdled.
[1]
"We do know for sure that they are very much unloved. We didn't have to do a study to come to that conclusion," team lead Gene Tsudik of the University of California, Irvine, told [2]New Scientist . "But people don't know whether that effort, that colossal global effort that is invested into solving CAPTCHAs every day, every year, every month, whether that effort is actually worthwhile."
[3]
[4]
Thanks to the inexorable march of progress, the answer appears to be no.
Having found that 120 of the 200 most popular websites used CAPTCHA tests of one sort or another, the team enlisted 1,000 people of all ages, sexes, location, and education, and got them to each perform 10 CAPTCHA tests on these sites.
[5]Cloudflare's invisible CAPTCHA works by probing browsers with JavaScript
[6]DataDome looks to CAPTCHA the moment with test of humanity that doesn't hurt
[7]A great day for non-robots: iOS 16 will bypass CAPTCHAs
[8]How CAPTCHAs can cloak phishing URLs in emails
They then compared their successes to those of a number of bots coded by researchers and published in journals for the purpose of beating CAPTCHA tests. The results make for embarrassing reading.
For distorted text fields, humans took 9-15 seconds with an accuracy of just 50-84 percent. Bots, on the other hand, beat the tests in less than a second with 99.8 percent accuracy.
[9]
"There's no easy way using these little image challenges or whatever to distinguish between a human and a bot any more," commented team member Andrew Searles, recommending that organizations should use "intelligent algorithms" to sort bot interactions from legit ones rather than CAPTCHA.
The full paper, "An Empirical Study and Evaluation of Modern CAPTCHAs," is [10]here .
Shujun Li, professor of cyber security at the University of Kent, explained that the explosion in advanced machine learning methods have rendered the defense obsolete.
[11]
"In general, as a concept CAPTCHA has not met the security goal, and currently is more an inconvenience for less determined attackers," he said. "New approaches are needed, like more dynamic approaches using behavioural analysis."
Jess Leroy, senior director of product management at Google Cloud, added: "We are increasingly focused on recognizing and interrupting malicious activity, whether perpetrated by bots or humans. As such, we are able to help our customers prevent loss even as AI bots become better at masquerading as humans. Further, we have a very large focus on helping our customers protect their users without showing visual challenges, which is why we launched reCAPTCHA v3 in 2018." ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.newscientist.com/article/2384228-bots-are-better-at-beating-are-you-a-robot-tests-than-humans-are/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2022/09/28/cloudflares_new_captcha_killer_enters/
[6] https://www.theregister.com/2022/07/21/datadome-captcha-verification/
[7] https://www.theregister.com/2022/06/21/believe_it_or_not_apple/
[8] https://www.theregister.com/2022/03/17/captcha_phishinbg_url/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://arxiv.org/abs/2307.12108
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Task failed successfully.
So if humans fail the task 50% of the time, you should present 2 or more tests, expect humans to fail, and bots to complete all of them successfully.
After 10 tests, there is only 1 in 1024 chance of humans doing all of them correctly, while bots will get them every time.
See icon.
Re: Task failed successfully.
You got there first - pass the CAPTCHA test based on human mistakes for doing them - except when the bots are programmed to do that too!
Of course someone from Google
would say how great they are. Google must harvest an enormous amount of information from reCAPTCHA -- learning about the sites that you visit.
I got rejected on one
Said motorcycles, clicked on both, one missing.
Was a stinkwheel, not usually classed as a motorcycle.
Taxis are very difficult as usually none in the pitctures.
Usually I just give up on any site that asks for one. I have complained to a local trader but they said they outsourced the web site it so can't do anything. Of course I could, I put my trade elsewhere.
Ditto that. I once tried to order a consignment of electronic components from a supplier only to be prevented from completing my purchase at the checkout due to a failed captcha. As I was blocked from proceeding I abandoned my basket and placed the order with their competitor... who didn't use captchas. I'm sure there is a lesson there somewhere.
I had to stop buying from a vendor I'd used since before the interwaebz (since the '80s) because I block Google, meaning their CAPCHA won't let me buy anything from them anymore.
Captchas, pah
It could be partially due to the fact I'm getting long in the tooth, but I find Google's recaptchas of the "select all pictures containing a bike" sort tricky on a mobile device.
I wonder if timing the form submission (from time page served) would suffice to filter out most bots. Hell, a referrer check would probably block half.
In other contexts (web server connection and request limiting plus fail2ban) I've realised how depressingly unsophisticated most bot implementations are.
The article only refers to distorted text captchas being 'bottable', not the status of the ubiquitous image question things.
Haven't seen a distorted text captcha on a modern site for a long time.
Source would be nice
It would be nice to have this code as a Firefox extension.
Re: Source would be nice
There's a company that offers this called NopeCHA, but it is a paid service.
What next for security now?
Now that SMS and CAPCHA's are regarded as insecure by certain sites for 2FA?
I hate the fact that I have to have my phone at my side when shopping. When this happens, it is probably charging in another room. That tells the world that my phone is not surgically attached to my hand.
So much for progress?
As someone who is slighty dyslixic, I hate those CAPCHAs that use letters, number I have no problem with. And as a pedant I hate the images that almost always have edges of bridge, wheels, busses or what ever that overlap the suares by a pixel or two. IF you want me to mark the squares that I know are right then accept that your capcha is not correct. When really pissed off I take a screen shot, enlarge it and send an angry mail to the website, where I show them that I AM right, They ARE worng and THEY have just lost a customer.
But surely an ethical bot
would never lie about being a human?