Slashdot Mirror


Analyzing CAPTCHAs

Bruce Schneier's blog pointed me to a research paper on "Attacks and Design of Image Recognition CAPTCHAs" (PDF). The abstract says, "We systematically study the design of image recognition CAPTCHAs (IRCs) in this paper. We first review and examine all IRCs schemes known to us and evaluate each scheme against the practical requirements in CAPTCHA applications, particularly in large-scale real-life applications such as Gmail and Hotmail."

7 of 105 comments (clear)

  1. hmm... by radicalpi · · Score: 2, Insightful

    I wonder how long until we have no way of distinguishing a bot from a person. existing CAPTCHAs don't work all that well, and I can't see future ones working much better for very long. The Cylons are among us! Any one of us could be one!

    1. Re:hmm... by Anonymous Coward · · Score: 1, Insightful

      ...and I am a human.

      Can you prove that?

  2. Re:Why not... by clone53421 · · Score: 2, Insightful

    There are only so many such images available for use, and the image library could fairly easily be exhausted and all of the images correctly identified at which point a bot could be used with near-100% accuracy.

    --
    Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
  3. Re:Too focused on being perfect by Cro+Magnon · · Score: 3, Insightful

    At some point, CAPTCHAs will reach the point where ONLY a bot can get past them.

    --
    Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
  4. Re:Too focused on being perfect by clone53421 · · Score: 3, Insightful

    Then they’re designed wrong.

    You should at least skim over the paper, that’s actually a significant portion of what it’s focused on... finding something that humans are good at and bots are not. As better bots have been written, that may have changed significantly... most present CAPTCHA systems are relatively broken.

    --
    Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
  5. Human resources are cheaper by Arty2 · · Score: 2, Insightful

    Seriously, what use of are captchas anymore when they pay actual humans to do the dirty work? I got like hundreds of fake users with IPs from India and China in my forums, that sign up just for putting a CEO tailored message and URL in their signature.

  6. Re:Why not... by ObsessiveMathsFreak · · Score: 2, Insightful

    Reverse image searches like TinEye blow this idea out of the water before it's even begun.

    --
    May the Maths Be with you!