4 ms·
You could also just pay a service that uses human workers in third world counties. It's a little over a tenth of a cent per captcha.
by sotrueee 11y ago
You could also just pay a service that uses human workers in third world counties. It's a little over a tenth of a cent per captcha.
- davedx 11y agoNot so economical if you want to brute force a login page.
- amelius 11y agoOr you could set up a pr0n site that shows the material only after the user has completed the captcha. This trick has been done before.
- dspillett 11y agoI've never seen a documented case of such tricks actually being used, and I've seen calculations that suggest the cost/benefit outcome is no better than just paying the poor to do the menial work. The last such analysis I paid attention to was some years ago so the situation may have changed, but I suspect the hassles of running a porn site and CAPCHA proxy still aren't worth it: * obtaining content sufficient to attract interest * paying for bandwidth & other resources) * writing the authentication system * then maintaining it (every time the CAPCHA service(s) change their process you potentially need to make and test changes to your code) * and you need to work around rate limits (depending on the CAPCH design it may not be possible to make the relevant requests client-side so if the services has rate limits you'll have to route through something that sufficiently randomises your source address). * providing support * dealing with bad press
- ErrantX 11y agoAnd also, if you got to the point where that porn site was then active and usable enough for the captcha cracking service... it would probably be more profitable just to monetise the porn.
- jamessb 10y agoThe closest thing to a documented case I've seen is a report of people gaming the Time Person of the Year poll so that the top person was moot, and the first letters of the candidates spelt out "Marblecake. Also the game.": By understanding how reCAPTCHA worked – the team was able to double their productivity (since they usually only had to enter one word instead of two). To further optimize their voting they created a poll front-end that allowed you to enter votes quickly while giving you an update of the poll status (and since it is a 4chan kind of crowd, they also provided the option to stream some porn just to keep you company while you are subverting one of the largest media companies in the world. https://musicmachinery.com/2009/04/27/moot-wins-time-inc-loses/ https://musicmachinery.com/2009/04/27/moot-wins-time-inc-los... However, this is slightly different as people were deliberately solving CAPTCHAs (and watching porn) rather than wanting to watch porn and also incidentally solving CAPTCHAs that they had no direct interest in.
- bpires 11y agoThe author did compare their performance with captcha-solving services. His accuracy is comparable to the service with no extra cost to the attacker. From the paper: "We compare our performance to that of Decaptcher, the (self-reported) oldest captcha-solving service. We selected Decaptcher for two reasons. First, it supports the image reCaptcha, charging $2 per 1000 solved captchas. [...] Interestingly, some of our summitted challenges rejected due to the service being overloaded, and had to be resubmitted at a later time, and received a time-out error as the solvers did not provide an answer in the time window allocated by the service. 258 challenges (36.85%) were an exact match. When taking into account the flexibility, 321 (44.3%) of the captchas were solved. The average solving time for the challenges that received a solution was 22.5 seconds. While the accuracy may increase over time as the human solvers become more accustomed to the image reCaptcha, it is evident that our system is a cost-effective alternative. Nonetheless, our completely offline captcha-breaking system is comparable to a professional solving service in both accuracy and attack duration, with the added benefit of not incurring any cost on the attacker."