Bro, everytime I get the select all the 'x' tiles (motorcycle, bicycle, bus, etc) one I never know if it means "all" of them, like even ones with just a little bit on the tile. Does it want the tires, too? It's bullshit. Never seems to be correct, what I select.
post
me: clicks all the traffic lights
<wrong!>
I hate that captcha -- the Google captcha where a single image (like a picture of a street with traffic lights, bikes, buses, etc) is divided up -- it is the worst one by far.
I've always thought it was intentional so that humans could train the edge detection of the machine vision algorithms.
What really stresses me out is the question of whether a human on a motorcycle becomes part of the motorcycle.
Of course not. But what about that millimeter of tire? Or the tenth of the rearview mirror?
You can just click a couple squares and hit ok. It doesn’t have to be right.
So we just invert the logic now, right?
Make the captcha impossibly hard to get right for humans but doable for bots, and let people in if they fail the test.
I haven't been able to solve CAPTHCAs in years.
Proof of work. This won't stop all bots from getting into the system, but it will prevent large numbers of them from doing so.
What prevents the adversaries from guafanteeing their bots that then guarantee more bots?
I feel like this could be abused by admins to create a system of social credit. An admin acting unethically could revoke access up the chain as punishment for being associated with people voicing unpopular opinions, for example.
So what would be a good solution to this? What is something simple that bots are bad at but humans are good at it?
Knowing what we now know, the bots will instead just make convincingly wrong arguments which appear constructive on the surface.
So, human level intelligence
I work in a related space. There is no good solution. Companies are quickly developing DRM that takes full control of your device to verify you're legit (think anticheat, but it's not called that). Android and iPhones already have it, Windows is coming with TPM and MacOS is coming soon too.
Edit: Fun fact, we actually know who is (beating the captchas). The problem is if we blocked them, they would figure out how we're detecting them and work around that. Then we'd just be blind to the size of the issue.
Edit2: Puzzle captchas around images are still a good way to beat 99% of commercial AIs due to how image recognition works (the text is extracted separately with a much more sophisticated model). But if I had to guess, image puzzles will be better solved by AI in a few years (if not sooner)
Not if we build our own open and free-as-in-freedom Internet first.
With blackjack and hookers.

I love Microsoft’s email signup CAPTCHA:

Repeat ten times. Get one wrong, restart.
iPhones already have it
Private Access Tokens? Enabled by default in Settings > [your name] > Sign-In & Security > Automatic Verification. Neat that it works without us realizing it, but disconcerting nonetheless.
So, the spammers will need physical Android device farms…


More industry insight: walls of phones like this is how company's like Plaid operate for connecting to banks that don't have APIs.
Plaid is the backend for a lot of customer to buisness financial services, including H&R Block, Affirm, Robinhood, Coinbase, and a whole bunch more
Edit: just confirmed, they did this to pass rate limiting, not due to lack of API access. They also stopped 1-2 years ago
Oh my god. I lost my fucking mind at the microsoft one. You might aswell have them solve a PhD level theoretical physics question
Pizza toppings. Glue is not a topping.
Isn't the real security from how you and your browser act before and during the captcha? The point was to label the data with humans to make robots better at it. Any trivial/novel task is sufficient generally, right?
Hey, failing at being a human being while trying to highlight where the bicycle starts and end on the picture is my job! You won't take that away from me, you fucking robot!
am I gonna need an AI to solve captchas now?
cause they've gotten so patently stupidly ridiculous that I cant even solve them as a somewhat barely functional biological intelligence.
If some sites only need me to click the one checkbox to prove I am a human, why aren't ALL sites using this method?!
when you have to click once, means they have been gathering all your actions up to that point, and for sure you are human. If you get asked to click images, means they don't have enough information yet, or you failed some security step (wrong password) and the site told captcha to be extra sure

top 50 comments