Slashdot Mirror


Making CAPTCHAs Even Harder With 3-D Models

Michael G. Kaplan writes "CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart) are commonly used to prevent computers from filling out web forms. Computer vision experts have been able to design programs to foil CAPTCHA with a high degree of success. I have designed a CAPTCHA that is based on the identification of attributes contained in an image generated by the grouping of easily recognized 3-D objects. I call this the Virtual Photographic CAPTCHA and it is likely to remain invulnerable to automated attack for many years to come. A novel anti-spam system necessitated its development."

17 of 326 comments (clear)

  1. Famous last words. by Anonymous Coward · · Score: 5, Funny

    Wow, you're just asking some bored hacker out there to prove you wrong.

  2. Here's another test... by Anonymous Coward · · Score: 5, Funny

    Show them the acronym, CAPTCHA. If they don't cringe, they are obviously non-human.

    1. Re:Here's another test... by null+etc. · · Score: 2, Funny

      CAPTCHA = Create A Phrase Then Create Humongous Acronym.

      Of course that's not the way it currently is done. Glitzy marketing folks tend to generate the acronym first, and then come up with humongous phrases that retrofits into the acronym.

  3. Kinda scary... by Sanity · · Score: 4, Funny
    ...when you can't make out the numbers or letters on one of these things, as has happened to me on a number of occasions.

    The logical conclusion is that I'm not actually human. My girlfriend will be very upset when I tell her.

    1. Re:Kinda scary... by Anonymous Coward · · Score: 2, Funny
      " My girlfriend will be very upset when I tell her."
      • Just use your other hand... it's her twin.
  4. already been done by Anonymous Coward · · Score: 5, Funny

    Deckard: You're reading a magazine... You come across a full page nude photo of a girl...
    Rachael: Is this testing whether I'm a replicant or a lesbian Mr Deckard?
    Deckard: Just answer the questions please.

  5. It's great fun failing Turing tests... by Jack+Taylor · · Score: 1, Funny

    RandomPerson: Hi there.
    Me: Hello. What is your name?
    RandomPerson: Uh, Jeff. What's yours?
    Me: ERROR: TRACEBACK CALL IN ^^^^^
    Me: ERROR: NO SIGNAL CARRIER DETECTED

    --
    One good turn - gets all the covers.
  6. Counter to this method by Anonymous Coward · · Score: 3, Funny

    They will design a Captcha that only females can solve. You can ask your mom to solve it, machines can't.

  7. Re:This is a good thing! Not!! by tomhudson · · Score: 5, Funny
    The porn industry already defeats this easily by asking people who want to continue on their porn site to do the recognition - they then harvest the answer and use it to, for example, auto-register spam yahoo/hotmail accounts.
    1. Porn surfer wants more porn
    2. Porn/spammer's script tries to register a bogus email account
    3. Porn/spammer's script sends surfer image to be recognized
    4. Surfer types in the text, number, whatever
    5. Script then tries to register email account using info typed in by surfer
    6. If successful, let surfer continue
    7. Result: a new spam address validated by a human
  8. About time? by EdwinBoyd · · Score: 2, Funny

    Finally 'real' hackers can now join their Hollywood counterparts by eschewing complex algorithms, buffer overruns and good old-fashioned skullduggery. Now secure systems will be protected by spinning multicoloured 3D geometric shapes. Hack the gibson anyone?

  9. Obligatory checklist by Wesley+Felter · · Score: 4, Funny

    Your post advocates a

    (X) technical ( ) legislative ( ) market-based ( ) vigilante

    approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea, and it may have other flaws which used to vary from state to state before a bad federal law was passed.)

    ( ) Spammers can easily use it to harvest email addresses
    (X) Mailing lists and other legitimate email uses would be affected
    ( ) No one will be able to find the guy or collect the money
    ( ) It is defenseless against brute force attacks
    ( ) It will stop spam for two weeks and then we'll be stuck with it
    (X) Users of email will not put up with it
    ( ) Microsoft will not put up with it
    ( ) The police will not put up with it
    ( ) Requires too much cooperation from spammers
    ( ) Requires immediate total cooperation from everybody at once
    (X) Many email users cannot afford to lose business or alienate potential employers
    ( ) Spammers don't care about invalid addresses in their lists
    ( ) Anyone could anonymously destroy anyone else's career or business

    Specifically, your plan fails to account for

    ( ) Laws expressly prohibiting it
    ( ) Lack of centrally controlling authority for email
    ( ) Open relays in foreign countries
    ( ) Ease of searching tiny alphanumeric address space of all email addresses
    ( ) Asshats
    ( ) Jurisdictional problems
    ( ) Unpopularity of weird new taxes
    ( ) Public reluctance to accept weird new forms of money
    ( ) Huge existing software investment in SMTP
    ( ) Susceptibility of protocols other than SMTP to attack
    ( ) Willingness of users to install OS patches received by email
    ( ) Armies of worm riddled broadband-connected Windows boxes
    ( ) Eternal arms race involved in all filtering approaches
    ( ) Extreme profitability of spam
    ( ) Joe jobs and/or identity theft
    ( ) Technically illiterate politicians
    ( ) Extreme stupidity on the part of people who do business with spammers
    ( ) Dishonesty on the part of spammers themselves
    ( ) Bandwidth costs that are unaffected by client filtering
    ( ) Outlook

    and the following philosophical objections may also apply:

    (X) Ideas similar to yours are easy to come up with, yet none have ever
    been shown practical
    ( ) Any scheme based on opt-out is unacceptable
    ( ) SMTP headers should not be the subject of legislation
    ( ) Blacklists suck
    (X) Whitelists suck
    ( ) We should be able to talk about Viagra without being censored
    ( ) Countermeasures should not involve wire fraud or credit card fraud
    ( ) Countermeasures should not involve sabotage of public networks
    ( ) Countermeasures must work if phased in gradually
    ( ) Sending email should be free
    ( ) Why should we have to trust you and your servers?
    ( ) Incompatiblity with open source or open source licenses
    ( ) Feel-good measures do nothing to solve the problem
    (X) Temporary/one-time email addresses are cumbersome
    ( ) I don't want the government reading my email
    ( ) Killing them that way is not slow and painful enough

    Furthermore, this is what I think about you:

    (X) Sorry dude, but I don't think it would work.
    ( ) This is a stupid idea, and you're a stupid person for suggesting it.
    ( ) Nice try, assh0le! I'm going to find out where you live and burn your
    house down!

    (From http://www.craphound.com/spamsolutions.txt)

  10. wow by fred+fleenblat · · Score: 2, Funny

    People sure go to a lot of work just avoid creating a robots.txt file!

    1. Re:wow by Anonymous Coward · · Score: 1, Funny

      Robots sure go to a lot of work just to avoid creating a people.txt file!

  11. Like so many, he obviously doesnt think anyone can by dopeghost · · Score: 3, Funny

    Computer vision experts have been able to design programs to foil CAPTCHA with a high degree of success. I have designed a CAPTCHA that is based on the identification of attributes contained in an image generated by the grouping of easily recognized 3-D objects. I call this the Virtual Photographic CAPTCHA and it is likely to remain invulnerable to automated attack for many years to come

    spare us the modesty!

    --
    This UID is 7651 digits too high to subjectively infer IQ from.
  12. Re:This is a good thing! Not!! by Junior+J.+Junior+III · · Score: 2, Funny

    Close, but it won't be a cacophony -- it'll be more like a coprophagy.

    --
    You see? You see? Your stupid minds! Stupid! Stupid!
  13. Re:This is a good thing! Not!! by ingo23 · · Score: 2, Funny

    Just throw in a complete IQ test - then not only we will tell a human from a machine, but also a human that should use e-mail from one that probably should not.

  14. I Cannot believe by Lehk228 · · Score: 2, Funny

    how badly all of you fell for a freaking obvious troll.

    --
    Snowden and Manning are heroes.