News: 1692102477

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

So much for CAPTCHA then – bots can complete them quicker than humans

(2023/08/15)


Completely Automated Public Turing test to tell Computers and Humans Apart – better known as the ubiquitous CAPTCHA we see standing athwart the doors to many websites – may now be a misnomer as researchers have found that computers are much better at completing them.

The bot defense measure dates back to 1997 and the tortured acronym 2003, with the technology starting out as a distorted series of letters and/or numbers. Google's implementation, reCAPTCHA, eventually did away with much of these shenanigans to make the browser identify low-risk human users in the background, but the image verification method still pops up occasionally if risk cannot be ascertained.

Normal people see them as a time-waster, web devs see them as a crucial defense against bots, and criminals see them just as another obstacle to be hurdled.

[1]

"We do know for sure that they are very much unloved. We didn't have to do a study to come to that conclusion," team lead Gene Tsudik of the University of California, Irvine, told [2]New Scientist . "But people don't know whether that effort, that colossal global effort that is invested into solving CAPTCHAs every day, every year, every month, whether that effort is actually worthwhile."

[3]

[4]

Thanks to the inexorable march of progress, the answer appears to be no.

Having found that 120 of the 200 most popular websites used CAPTCHA tests of one sort or another, the team enlisted 1,000 people of all ages, sexes, location, and education, and got them to each perform 10 CAPTCHA tests on these sites.

[5]Cloudflare's invisible CAPTCHA works by probing browsers with JavaScript

[6]DataDome looks to CAPTCHA the moment with test of humanity that doesn't hurt

[7]A great day for non-robots: iOS 16 will bypass CAPTCHAs

[8]How CAPTCHAs can cloak phishing URLs in emails

They then compared their successes to those of a number of bots coded by researchers and published in journals for the purpose of beating CAPTCHA tests. The results make for embarrassing reading.

For distorted text fields, humans took 9-15 seconds with an accuracy of just 50-84 percent. Bots, on the other hand, beat the tests in less than a second with 99.8 percent accuracy.

[9]

"There's no easy way using these little image challenges or whatever to distinguish between a human and a bot any more," commented team member Andrew Searles, recommending that organizations should use "intelligent algorithms" to sort bot interactions from legit ones rather than CAPTCHA.

The full paper, "An Empirical Study and Evaluation of Modern CAPTCHAs," is [10]here .

Shujun Li, professor of cyber security at the University of Kent, explained that the explosion in advanced machine learning methods have rendered the defense obsolete.

[11]

"In general, as a concept CAPTCHA has not met the security goal, and currently is more an inconvenience for less determined attackers," he said. "New approaches are needed, like more dynamic approaches using behavioural analysis."

Jess Leroy, senior director of product management at Google Cloud, added: "We are increasingly focused on recognizing and interrupting malicious activity, whether perpetrated by bots or humans. As such, we are able to help our customers prevent loss even as AI bots become better at masquerading as humans. Further, we have a very large focus on helping our customers protect their users without showing visual challenges, which is why we launched reCAPTCHA v3 in 2018." ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.newscientist.com/article/2384228-bots-are-better-at-beating-are-you-a-robot-tests-than-humans-are/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/09/28/cloudflares_new_captcha_killer_enters/

[6] https://www.theregister.com/2022/07/21/datadome-captcha-verification/

[7] https://www.theregister.com/2022/06/21/believe_it_or_not_apple/

[8] https://www.theregister.com/2022/03/17/captcha_phishinbg_url/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://arxiv.org/abs/2307.12108

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNuhMajwH@vj9SQDbkOFKAAAAco&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



But surely an ethical bot

Neil Barnes

would never lie about being a human?

Task failed successfully.

Luiz Abdala

So if humans fail the task 50% of the time, you should present 2 or more tests, expect humans to fail, and bots to complete all of them successfully.

After 10 tests, there is only 1 in 1024 chance of humans doing all of them correctly, while bots will get them every time.

See icon.

Re: Task failed successfully.

Steve Kerr

You got there first - pass the CAPTCHA test based on human mistakes for doing them - except when the bots are programmed to do that too!

Of course someone from Google

alain williams

would say how great they are. Google must harvest an enormous amount of information from reCAPTCHA -- learning about the sites that you visit.

I got rejected on one

MJI

Said motorcycles, clicked on both, one missing.

Was a stinkwheel, not usually classed as a motorcycle.

Taxis are very difficult as usually none in the pitctures.

Paul Crawford

Usually I just give up on any site that asks for one. I have complained to a local trader but they said they outsourced the web site it so can't do anything. Of course I could, I put my trade elsewhere.

Andy Non

Ditto that. I once tried to order a consignment of electronic components from a supplier only to be prevented from completing my purchase at the checkout due to a failed captcha. As I was blocked from proceeding I abandoned my basket and placed the order with their competitor... who didn't use captchas. I'm sure there is a lesson there somewhere.

Gene Cash

I had to stop buying from a vendor I'd used since before the interwaebz (since the '80s) because I block Google, meaning their CAPCHA won't let me buy anything from them anymore.

Captchas, pah

Pete Sdev

It could be partially due to the fact I'm getting long in the tooth, but I find Google's recaptchas of the "select all pictures containing a bike" sort tricky on a mobile device.

I wonder if timing the form submission (from time page served) would suffice to filter out most bots. Hell, a referrer check would probably block half.

In other contexts (web server connection and request limiting plus fail2ban) I've realised how depressingly unsophisticated most bot implementations are.

myhandler

The article only refers to distorted text captchas being 'bottable', not the status of the ubiquitous image question things.

Haven't seen a distorted text captcha on a modern site for a long time.

Source would be nice

Gene Cash

It would be nice to have this code as a Firefox extension.

Re: Source would be nice

Anonymous Coward

There's a company that offers this called NopeCHA, but it is a paid service.

What next for security now?

Anonymous Coward

Now that SMS and CAPCHA's are regarded as insecure by certain sites for 2FA?

I hate the fact that I have to have my phone at my side when shopping. When this happens, it is probably charging in another room. That tells the world that my phone is not surgically attached to my hand.

So much for progress?

vistisen

As someone who is slighty dyslixic, I hate those CAPCHAs that use letters, number I have no problem with. And as a pedant I hate the images that almost always have edges of bridge, wheels, busses or what ever that overlap the suares by a pixel or two. IF you want me to mark the squares that I know are right then accept that your capcha is not correct. When really pissed off I take a screen shot, enlarge it and send an angry mail to the website, where I show them that I AM right, They ARE worng and THEY have just lost a customer.

Democracy is a form of government in which it is permitted to wonder
aloud what the country could do under first-class management.
-- Senator Soaper