6 ms·
ReBreakCaptcha: Breaking Google’s ReCaptcha v2 Using Google
- captchaz 10y agoYou can automatically bypass ReCaptcha v2 using a captcha solving service with https://www.captchasolutions.com https://www.captchasolutions.com
- captchaz 10y agoYou can automatically bypass ReCaptcha v2 using a captcha solving service with https://www.captchasolutions.com https://www.captchasolutions.com
- amenghra 10y agoMaybe they should have dubbed this ReNotBreakCaptcha? > I’ve testing in 3 examples, and none had the correct answer: first one only detected 3 out of 6 numbers, the seconds had 10 digits, one of them wrong, and the third couldn’t recognise. > Also, it seams that google implement a max number of retries for audio challenge."
- maxmcd 10y agoFrom previous recaptcha discussion[1] it seems like the going rate for solving recaptcha's is $2 for 1000 solved, or as low as $1/1000. This method would actually be more expensive than that at $6/1000[2] 1. https://news.ycombinator.com/item?id=11453697 https://news.ycombinator.com/item?id=11453697 2. https://cloud.google.com/speech/pricing https://cloud.google.com/speech/pricing
- hedora 10y agoSimilar to my other comment, as a normal user, I'd happily pay 1/10th a cent (as long as it went to the grey market, and not the website or google) to bypass a recaptcha.
- dsacco 10y agoThat incentive only works if a website's primary captcha use case is spam avoidance. Most websites that use captchas have a vested interest in preventing you from being able to bypass them by tossing money around. Paying to remove captchas is fundamentally unlike similar proposals (like paying to remove advertisements) that are designed to make innocuous users' lives easier because captchas aren't solely designed to prevent spam, nor are they designed as a passive revenue stream. For example, one common use of a captcha is, essentially, rate-limiting in a non-spam prevention context. It's arguable that rate-limiting should be implemented differently, but captchas are actually fairly effective for rate-limiting regardless. Websites that feature things like gift card numbers typically put captchas on lookups and validations to prevent people from simply brute-forcing them (especially if they do not use gift card pins). In scenarios like that, you don't want spammers to be able to bypass captchas, but if they fundamentally can, at least it costs them money. On the other hand, explicitly supporting captcha avoidance as a revenue stream, however, presents malicious users with the same opportunity that parents get if you offer to fine them for being late to pick up their children from daycare. You've just implicitly given them a choice that was not really allowed before, and they'll happily pay you directly instead of the shady API they have to use to get rid of the captcha. So to sum up - captchas aren't fun, but in principle you really don't want there to be a consistent method for cheaply bypassing them (whether grey market or officially supported) if the expected value of doing so is significantly higher than the cost.
- jorvi 10y agoFunny you mention Google. If you keep logged in to Google (yes, yes I know but for me its the lesser of two evils) you'll only occasionally need to tick a "I'm not a robot" box instead of doing a full captcha.
- hedora 10y agoWow. I want this as a browser plugin. The image recaptchas are extremely time consuming (maybe I click the wrong images, or they're just punishing me for logging out and clearing cookies...), and I don't want to futz with the audio ones.
- tdb7893 10y agoOne good thing about not really caring about cookies and trackers is that I only have gotten recapchas 3 times ever
- drewg123 10y ago+1 I get a recaptcha every time I log into hilton to book a hotel room for a trip. That's the only site this happens on; I wonder what I'm doing to trigger it.
- sml156 10y agoAn upgrade of your firmware may solve it.
- ehsankia 10y agoSites get to set the captcha security. There's 3 tiers. The highest one will always bug the user, the lower one will almost never do it (unless it's a specific flagged IP). Default is somewhere in the middle, but I'm guessing that site has it set to the highest. The person you're replying to has a different issue. The way the one button captcha works is by using your cookies to try to figure out if you're a real human user or a robot. If you clear your cookies, you'll almost always get the captcha.
- problems 10y agoYeah, it's really brutal. I find the new recaptchas which I hit almost every time are much more exhausting than the old text-based ones, and probably much easier for a machine to solve to boot.
- frogpelt 10y ago
- spullara 10y agoWhen I was at Yahoo we had a HackDay where there was one team that used Flickr data to make a captcha that asked for tags for an image it displayed. Another team used Flickr data to look at images and automatically tag them...
- chatmasta 10y agoWhat success rate have you seen? Google intentionally fuzzes parts of the audio and tries to induce false positives. Also, does google offer an audio captcha every single time? Even for very high risk profiles?
- lmkg 10y ago> Also, does google offer an audio captcha every single > time? Even for very high risk profiles? It might be a legal requirement from the ADA.
- tyingq 10y agoFound something mildly interesting playing around with this. One of the network requests when you ask for audio is this: https://www.google.com/js/bg/Kv2WsNzHE5GULL-TmjqX5N4dnwt4D3cPVKm_UbfMct4.js https://www.google.com/js/bg/Kv2WsNzHE5GULL-TmjqX5N4dnwt4D3c... Which presents this, in a comment at the top of the returned js: Anti-spam. Want to say hello? Contact (base64) Ym90Z3VhcmQtY29udGFjdEBnb29nbGUuY29t That decodes to: botguard-contact@google.com
- dabber 10y agoSome background on the code: http://stackoverflow.com/questions/21762076/why-does-gmail-use-eval http://stackoverflow.com/questions/21762076/why-does-gmail-u...
- hippich 10y agoCaptcha-replacement - https://hashcash.io/ https://hashcash.io/
- spullara 10y agoSeems interesting but failed for me in Safari.
- foobiekr 10y agothis is not a captcha replacement at all. the constraint on proof of work functions is that they are compatible with mobile users which puts an upper bound on the approach. custom work (even in the presence of scrambled approaches) and servers instead of mobiles both make this approach problematic.
- cavanasm 10y agoIs this a PoC bug bounty type of deal, or "here's a neat tool that can beat reCaptcha" type of deal? Seeing a bunch of comments about wanting a browser plugin that exploits this, but I'm wondering if that would be legal or not after reading (from HN several weeks ago) about the ticket scalpers who automated TicketMaster's site and were charged with fraud. The case isn't exactly analogous, but it's close enough to make me wonder. https://motherboard.vice.com/en_us/article/the-man-who-broke-ticketmaster https://motherboard.vice.com/en_us/article/the-man-who-broke...
- tyingq 10y agoThey did, indeed, get charged with wire fraud, and entered guilty pleas[1]. The EFF and others were pretty dismayed with this, and felt it should have been a civil, and not criminal matter. Since that time, Congress also passed a "Bots Law" that specifically spells out gaming online tickets as "treated as unfair or deceptive acts or practices under the Federal Trade Commission Act." [2] I suspect this opens a door for larger fines as well. [1] https://www.wired.com/2010/11/wiseguys-plead-guilty/ https://www.wired.com/2010/11/wiseguys-plead-guilty/ [2] https://www.congress.gov/bill/114th-congress/senate-bill/3183 https://www.congress.gov/bill/114th-congress/senate-bill/318...
- appsec1485 10y agoIt was already prooved in 2012: https://arstechnica.com/security/2012/05/google-recaptcha-brought-to-its-knees/ https://arstechnica.com/security/2012/05/google-recaptcha-br... But, it is not exploitable - when Google identified high volvume attacks, the voice captcha is changed into a more complex voice which cannot be identified via this tool. A Proof of Concept was already created by AppSec Labs, in Sep 2016: https://www.youtube.com/watch?v=4yec-vxN0BY https://www.youtube.com/watch?v=4yec-vxN0BY
- appsec1485 10y agoIt was already prooved in 2012: https://arstechnica.com/security/2012/05/google-recaptcha-brought-to-its-knees/ https://arstechnica.com/security/2012/05/google-recaptcha-br... But, it is not exploitable - when Google identified high volvume attacks, the voice captcha is changed into a more complex voice which cannot be identified via this tool. A Proof of Concept was already created by AppSec Labs, in Sep 2016: https://www.youtube.com/watch?v=4yec-vxN0BY https://www.youtube.com/watch?v=4yec-vxN0BY