Slashdot Mirror


Google's reCAPTCHA Turns 'Invisible,' Will Separate Bots From People Without Challenges (arstechnica.com)

Google is making CAPTCHAs invisible using "a combination of machine learning and advanced risk analysis that adapts to new and emerging threats." Ars Technica reports: The old reCAPTCHA system was pretty easy -- just a simple "I'm not a robot" checkbox would get people through your sign-up page. The new version is even simpler, and it doesn't use a challenge or checkbox. It works invisibly in the background, somehow, to identify bots from humans. Google doesn't go into much detail on how it works, only saying that the system uses "a combination of machine learning and advanced risk analysis that adapts to new and emerging threats." More detailed information on how the system works would probably also help bot-makers crack it, so don't expect details to pop up any time soon. When sites switch over to the invisible CAPTCHA system, most users won't see CAPTCHAs at all, not even the "I'm not a robot" checkbox. If you are flagged as "suspicious" by the system, then it will display the usual challenges.

2 of 160 comments (clear)

  1. Lots of work to do by arth1 · · Score: 5, Informative

    For some reason, I get flagged for captchas all the time, but no matter how vigilant I am at choosing storefronts, mountains, street signs and house numbers, I have to go through at least a dozen pages of them before it believes me.
    I wonder whether being behind load balanced proxy servers might have anything to do with it.
    Anyone else having similar problems?

    1. Re:Lots of work to do by AmiMoJo · · Score: 3, Informative

      The invisible ones seem to be using things like mouse movements and other measurements of human interaction, which can be difficult to fake. They must have some way to prevent replay attacks. Not sure how they will handle people disabling Javascript, probably fall back to the old HTML5 method.

      I find what triggers to endless captcha loops is:

      - Privacy settings in your browser, especially Privacy Badger and uBlock
      - Blocking Flash/WebGL/Canvas fingerprinting
      - Disabling Javascript
      - Using a VPN
      - Especially using TOR

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC