Software In Action
5Nov/118

Captcha test broken by Stanford researchers

captcha

  Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) was founded in 2000 at Carnegie Mellon University. The test should be easy to pass for humans, but impossible for a computers. This kind of test is intended to protect websites from spam bots and automated attacks.

  CAPTCHA has been long questioned for its efficacy. Scientists from Stanford University finally proved that the text version of this test can be easily beaten by their new program. The tool developed for the study is proved to be extremely effective.

  Their bot is 25% effective in breaking the security used on Wikipedia, 43% on eBay and up to 66% on the Visa site belongs to authorize.net. The program worked pretty good on Digg and pages belonging to CNN. Most of the commonly used methods of protection are failing to the new tool created in Stanford University. However, two other popular spam preventing methods: reCAPTCHA and Google, successfully resist this new program. Interesting fact: reCAPTCHA is derived from the original test developed in 2000 on the same university. This kind of test is often problematic for people, so it's not really surprising that this new tool has a problem with it. If it comes to Google test, it was broken in 2008 by Russian spammers, after similar attacks on Microsoft and Yahoo!.

  The program removes background noise from the image and then splits the text into individual letters, which are easier to identify than a whole words. After the publication of the document, Visa and Digg started using reCAPTCHA on their websites.

I personally hate reCAPTCHA. You can find many examples how annoying this test can be. Like on this example:

 

captcha hard

 

Sadly looks like it's the last test remaining on the text based tests battlefield.

Comments (8) Trackbacks (2)
  1. Nice blog, I really love your post, great point made. I can\’t wait to dig into this material and learn from it. I am sure your next content would be very interesting. Can\’t wait to see more. Wish you all the best! Thanks.

  2. Do you know how easy it is to get a different test with recaptcha? Click the little refresh button. Now that wasnt too hard, was it?

    If you really detest captchas, there are several other effective methods. While captchas are far and away the most popular, they are far from the only solution.

  3. Great…so how long until the spammers get a hold of this new tool and defeat the majority of existing captchas out there?

    Did the people who created this tool think this was a good idea? I’m sure the millions of people who have to pay to have their websites updated to recaptcha won’t agree.

  4. It’s just annoying…

  5. I’ve seen a few things lately, just simple math problems instead of captcha. I like that a lot better. reCaptcha wouldn’t be too bad if it was at all legible..although it’s cool that it only needs one of the words, meaning you can just type whatever for the second word.

  6. I figured that it would be possible one day, everything is so high tech now its crazy -_-

  7. I hate capchas… they’re just so redundant and pointless…


Leave a comment

(required)


four + 9 =

WP Like Button Plugin by Free WordPress Templates