• MehStrongBadMeh@programming.dev
    link
    fedilink
    English
    arrow-up
    157
    arrow-down
    1
    ·
    3 months ago

    There’s a reason captchas have moved mostly image identification systems. These text-based captchas have all been defeated for years.

    • ironhydroxide@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      73
      ·
      3 months ago

      Yeah because whomever “owns” the data needs humans to train their bots, not because the image based bot detection is better than other methods.

    • TheSlad@sh.itjust.works
      link
      fedilink
      arrow-up
      65
      ·
      3 months ago

      The images are not actually the captcha. They’ve used other methods and tools to verify your authenticity, then they force you to help train their image recognition AI under the guise of it being the actual captcha. Its Distributed Forced Labor, and Google has been using captchas to do this for decades. Remeber the picture-of-two-words captcha? One word was always squiggly and the other was not. The squiggly word was the real captcha, the other word was from a scanned book and you were helping to train their OCR algorithms.

        • hinterlufer@lemmy.world
          link
          fedilink
          arrow-up
          13
          ·
          3 months ago

          I also remember services you could pay to get your captcha solved via a browser extension. You could also register as a captcha solver there to earn a few bucks stupidly solving captchas. Although I’m not sure if they were actually legit.

        • Terrasque@infosec.pub
          link
          fedilink
          arrow-up
          4
          ·
          3 months ago

          I remember back in the day this automated downloader program… the links had a limit of one download at a time and you had to solve a captcha to start each download.

          So the downloader had built in “solve other’s captcha” system, where you could build up credit.

          So when you had say 20 links to download you spent some minutes solving other’s captchas and get some credit, then the program would use that crowdsourcing to solve yours as they popped up.

      • MehStrongBadMeh@programming.dev
        link
        fedilink
        English
        arrow-up
        6
        ·
        3 months ago

        Yeah, at this point, most forms of image identification catches have also been defeated, not quite 100% success yet, but they’re getting there

    • breakingcups@lemmy.world
      link
      fedilink
      arrow-up
      18
      ·
      3 months ago

      Funnily enough, the reason they switched to those was to use the data to train machine learning (AI) models, just like Google’s recaptcha was originally pictures of words from old, scanned books so they could transcribe all of them “for free” and train their transcription algorithms.

      • antonim@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        8
        ·
        3 months ago

        Man I miss the times when Google used to trick us into helping make knowledge more easily accessible to everyone. Now we just train fucking AI for luxury cars.

    • RonSijm@programming.dev
      link
      fedilink
      arrow-up
      8
      ·
      3 months ago

      It’s a bit weird how that actually works though…

      “Which of these pictures are traffic lights?”

      I’d hope with all the self-driving-(ish) cars coming out, any AI like that should be able to identify a traffic light, right?

      • null@slrpnk.net
        link
        fedilink
        arrow-up
        24
        ·
        3 months ago

        When you “solve” a captcha like that, you’re just helping train the AI you’re talking about.

        The stuff that determines whether you’re a not or not is based on browser information, how you interact with the page, etc.

    • SkunkWorkz@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      3 months ago

      If they add audio captchas for the visual impaired then those image captchas can be circumvented. There is a Tampermonkey script on GitHub that can defeat Recaptcha by solving the audio captcha.

  • Aoife@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    129
    arrow-down
    9
    ·
    3 months ago

    Nobody mentioning it got the captcha wrong? That’s a p not a P which while admittedly a tiny mistake would still be counted as a fail

    • ulterno@lemmy.kde.social
      link
      fedilink
      English
      arrow-up
      5
      ·
      3 months ago

      metalbags

      metal, semi-metal, plastic, fibre-glass.

      If you just talk about the material of the bag, yes, it is mostly metal and plastic. The costlier the stuff, the more the metal.

      • Darkassassin07@lemmy.ca
        link
        fedilink
        English
        arrow-up
        4
        ·
        3 months ago

        Sure; but with a simple mistake that many people would (and inevitably did in this thread) make.

        I’d say it’s at least on par with people solving them.

  • Shanedino@lemmy.world
    link
    fedilink
    arrow-up
    31
    ·
    3 months ago

    Fun fact not only to captchas monitor your input but also can analyze how you input it. If you mouse moves in a perfectly straight line if all your key presses are precisely spaced, you are probably not human.

  • Daemon Silverstein@thelemmy.club
    link
    fedilink
    arrow-up
    23
    ·
    3 months ago

    Nowadays there are some really annoying CAPTCHAs out there, such as:

    • “Click over the figures that are upwards/downwards” and various rotated bears
    • “Rotate the figure until it matches the given orientation” and a finger pointing to some random direction, as well as rotation buttons that don’t work the way you would mathematically expect them to work
    • “Select all the images with a bicycle until there are none left” and the images take centuries to fade away after you click them
    • “Select all the squares containing a bus” and there are squares with the very corner of the bus that make you wonder if they are considered as part of “squares containing A bus”
    • “Fit the puzzle piece”, although this is the least annoying one

    In summary, the CAPTCHAs seemingly are becoming less of a “prove you’re not a robot” and more of an forced IQ test. I can see the day when CAPTCHAs will ask you to write down a Laplacian transform for the solution f(x) to the differential equation governing the motion of a mass considering the resistance of air and aerodynamics, or write down a detailed solution to the P versus NP problem.

    • fsxylo@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      21
      ·
      3 months ago

      It’s when they make you do like 20 of them. Bitch you already stopped the DDOS let me see my balance fuck.

    • AwkwardLookMonkeyPuppet@lemmy.world
      link
      fedilink
      English
      arrow-up
      21
      ·
      3 months ago

      Sony has the most annoying ones, which are designed to prevent people from submitting tickets. They’ll show you like 10 dice, and ask what they add up to. They make you solve like 16 of them before they let you continue. Shit should be illegal.

      • TachyonTele@lemm.ee
        link
        fedilink
        arrow-up
        12
        ·
        edit-2
        3 months ago

        The math ones are ridiculous.
        Guess what computers are inherently great at?
        Math.

        • AwkwardLookMonkeyPuppet@lemmy.world
          link
          fedilink
          English
          arrow-up
          7
          ·
          3 months ago

          Because they’re not there to stop computers, they’re there to stop people from getting legitimate support from a company that owes it to them.

    • variants@possumpat.io
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      3 months ago

      at that point i just assume im the one they are keeping out and just close the tab

      AlrightThenKeepYourSecrets.gif

    • chuckleslord@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      3 months ago

      No, CAPTCHAs these days track mouse movements and other factors. They make you second guess if something should be included because, as a human, that’s going to be something you do. And it’ll be obvious from both that hesitation and your squishy, inaccurate mouse movements that you’re a human.

          • Daemon Silverstein@thelemmy.club
            link
            fedilink
            arrow-up
            4
            ·
            3 months ago

            They can’t without the given permission from the browser to do so. While they can indeed track the mouse, when they try to access mobile motion sensors (I’m considering a CAPTCHA inside a webpage being accessed through a mobile browser such as Firefox mobile or Chrome for Android), they need to use an HTML5 API that, in turn, will ask the user for permission, something like “This site wants to use sensor motion data. Allow or block?”

  • TheCookingSenpai@lemmy.ml
    link
    fedilink
    English
    arrow-up
    12
    ·
    3 months ago

    While everybody’s right in saying text captchas are outdated, there are concerning amount of services (especially for small-mid businesses) that still use them.

    Anyway, if an AI could control something like Selenium with the necessary modifications (aka not presenting itself as Selenium), I am pretty sure most of the “Click here to confirm you are an human” captchas like the cloudflare one would be defeated too.

    I think the most challenging are image-based weird challenges that are difficult even to humans. The annoying ones.

  • Ahardyfellow@lemmynsfw.com
    link
    fedilink
    arrow-up
    2
    ·
    3 months ago

    Most bots out there aren’t backed by chat gpt. We had a flood of Russian boys using a sign up for on a site to send spam emails by putting the spam in the names and address fields. Slapping the most basic of captchas on the page solved it.