This entry | Main blog

***Dave Does the Blog

Tuesday, 23 August 2005, 11:14 AM
Released from CAPTCHA

CAPTCHAs are those little graphic boxes with distorted-but-visible number and letter combinations that you're asked to retype in order to authenticate that you are a human being with eyeballs, not an software bot out to hack a site, spam a site, etc. The acronym stands for "Completely Automated Public Turing test to tell Computers and Humans Apart."

Some folks use CAPTCHAs on their blogs to block comment spammers, and it's been pretty effective. I mean, you can do comment spam manually, but that's awfully labor intensive vs. using spambots (and unprotected sites). While accessibility folks have argued that CAPTCHA is an awful idea in a world with visually-impaired people, etc. (and, in fact, some CAPTCHAs are difficult for the unimpaired to decipher), it's been a fairly popular option. It's even one I've toyed with.

But now comes "PWNtcha" (Pretend We?\'re Not a Turing Computer but a Human Antagonist), a software project to learn to read and decode CAPTCHAs -- with published success rates of up to 100%. It's not out in the wild yet, but believe it that if the Black Hats decide there's value in breaking past CAPTCHAs, they'll be able to do it.* That doesn't mean it's useless security -- a determined burglar can get past your deadbolt, but it may deter a more casual one who moves on to easier pickings -- but its value is likely to decrease over time.

*Other than the documented approach of republishing them as admissions on pr0n sites and getting customers to unwittingly key them in.

(via BoingBoing)


Filed under :: Blogging :: Hi-Tech

***Dave Does the Blog (10-Apr-06 11:47 PM): http://www.hill-kleerup.org/blog/2006/04/10/captcha_the_kit.html - CAPTCHA the Kitten
It's no more visually-impaired friendly than the traditional text/numbers CAPTCHA codes (those "type in the string above" verification used in comment forms for many blogs), but the KittenAuth test is... ...
Original material on this weblog is available under a Creative Commons License (http://creativecommons.org/licenses/by-nc/1.0/) from
The views expressed by me on this website/weblog are mine alone and do not necessarily reflect the views of
my employer, my church, my party, my candidate, my community, my spouse, or, on occasion, myself.
Views expressed by others are, well, theirs.
This document's URL is: http://www.hill-kleerup.org/blog/2005/08/23/released_from_c.html