CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

CAPTCHA comment

 
Post new topic   Reply to topic       All -> FavForums -> General Site [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Scott_Hollingsworth

Sergeant
Sergeant
Premium Member

Joined: May 09, 2006
Posts: 101
Location: USA
Premium

PostPosted: Wed Oct 31, 2007 1:10 am    Post subject: CAPTCHA comment
Reply with quote

Wow, the login CAPTCHA has become rather hard to read. Not just here either. It is a necessary trend I know. I fear we are fast approaching a point where we must find an effective replacement. If CAPTHAs must become any more obfuscated, then the bots will have won that battle.

I don't wish to trigger a discussion over appropriate use of CAPTCHA. But I am interested in thoughts on what can be done to fill the void where they belong when bots are better able to read them than humans.

I'd like to hear some ideas on this. A nod towards accessibility would probably be welcomed by many sight challenged 'net users as well.

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Oct 31, 2007 2:04 am    Post subject:
Reply with quote

I concur we need to do something better and more sophisticated. This is hopefully a short term measure.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Wed Oct 31, 2007 4:14 am    Post subject:
Reply with quote

See also CastleCops Link/t206321-PC_stripper_helps_spam_to_spread.html

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1033
Location: USA

PostPosted: Fri Nov 02, 2007 7:45 pm    Post subject:
Reply with quote

Yea, I was just about to mention the reCAPTCHA project Wink It looks very cool hehehe.

The only question I got, is how do they know if the user is entering a "correct" captcha, if they (Internet Archive) can't read the the text themselves? Smile

In fact, over at http://recaptcha.net/learnmore.html I misspelled one of the captchas, and it still said I was "correct"...maybe it lets it through if only 1 character is mispelled...? heheh

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 779
Location: USA
MIRT Premium

PostPosted: Fri Nov 02, 2007 7:59 pm    Post subject:
Reply with quote

kittenauth also looks interesting.

Back to top
View users profile Send private message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16509

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Sat Nov 03, 2007 1:58 am    Post subject:
Reply with quote

ahoier wrote:
The only question I got, is how do they know if the user is entering a "correct" captcha, if they (Internet Archive) can't read the the text themselves? Smile

Dunno about recaptcha but the way I could see this working is that the interloper, upon getting the "mule" input, directs it to the site originating the captcha. Upon successful interpretation, the interloper gives the mule the desired peep show. In the meantime the interloper uses a bot to automate whatever nefarious tasks are at hand.

It's ingenious really ... but a PITA for legit sites who don't really need the bots bypassing CAPTCHA. Sad

Back to top
View users profile Send private message
Scott_Hollingsworth

Sergeant
Sergeant
Premium Member

Joined: May 09, 2006
Posts: 101
Location: USA
Premium

PostPosted: Wed Nov 07, 2007 3:53 am    Post subject:
Reply with quote

Here's a thought. Why are most CAPTCHAs in use these days nothing more than obfuscated graphical forms of text with the correct response being the text? I think we need to break from this mold.

Why not have images of things to be identified and the response is to choose the correct identifier among multiple choices?

What about using a mapped graphic with multiple differing elements and instruction to the user to click on one particular element for the response? Or multiple elements clicked in the correct sequence as instructed?

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Nov 07, 2007 4:19 am    Post subject:
Reply with quote

I'd love to run something like that, but I need help setting up the images. I never did get into graphics.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 779
Location: USA
MIRT Premium

PostPosted: Wed Nov 07, 2007 4:05 pm    Post subject:
Reply with quote

Scott_Hollingsworth wrote:
I think we need to break from this mold.

Why not have images of things to be identified and the response is to choose the correct identifier among multiple choices?
you mean like this?

http://www.asirra.com/examples/ExampleService.html
Code:
artsoft.org/forum/profile.php?mode=register&agreed=true

Back to top
View users profile Send private message
Scott_Hollingsworth

Sergeant
Sergeant
Premium Member

Joined: May 09, 2006
Posts: 101
Location: USA
Premium

PostPosted: Thu Nov 08, 2007 6:04 pm    Post subject:
Reply with quote

That asirra.com example does look good. I had to allow javascript though to see it.

I had to pull out my references to verify. I guess both of my suggestions would require javascript to pull off.

That creates a usability dilema in some situations. One must first trust the site's javascript in order to establish trust with the site. This can be confusing for the typical internet user. They are likely to get fed up and allow javascript globally (literally when we are talking the internet).

As they say, security aint easy.

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 779
Location: USA
MIRT Premium

PostPosted: Thu Nov 08, 2007 7:44 pm    Post subject:
Reply with quote

The typical user doesn't use noscript.
The typical noscript user would read castlecops before deciding to register or post, and decide it is trustworthy enough to allow javascript when encountering kittenauth.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> General Site All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer