3 ms·
Good ole stackoverflow - close topics that may bring new ideas for turing tests. The entire thread has a number of good ideas and relates to a thread you start
by cd34 16y ago
Good ole stackoverflow - close topics that may bring new ideas for turing tests.
The entire thread has a number of good ideas and relates to a thread you started the other day. http://news.ycombinator.com/item?id=2107972 http://news.ycombinator.com/item?id=2107972 Pity that it didn't get more traction.
- chrisbroadfoot 16y agoA lot of them are pretty bad ideas once you think about them for more than a few minutes. Mouse movements and clicks are easily emulated - just look at the mass of bots for online games. There's actually quite a large industry based around selling bots that can be used for goldfarming. Keyboard events are similarly easy. It's very easy to write a function that separates keypresses with human-like pauses. Also - many of these ideas have severe accessibility drawbacks. Touchscreens, for example, do not emit mouse move events like a mouse. Voice input will not act like a keyboard and may look like the user has pasted into the input box.
- cd34 16y agoAt least he's trying to solve a problem he faces. Imagine if he took a heatmap of all mouse movements during form submissions, ranked them as spam/ham, and then used that heatmap against new submissions to determine a confidence. Perhaps there is a pattern. It's difficult to know the answer to a question that isn't asked. Maybe during data entry, your analysis returns a fact that in human submissions, they press backspace at least once. Sure it doesn't work for mobile browsers/touchscreens, but, on low-confidence submissions, you present a harder, second challenge. Most recaptcha forms are solved by humans at $1/1000 from companies. You have caused them to use a human to solve it, which means your test worked. The fact that you still got a spam submission is a separate issue. Ensuring a human, non-spam response is something that needs to be done statistically, not through a rules based system. Shared inoculation like Akismet or Typepad help, but, often miss new trends. I don't think the real problem is determining if it is a human, I think the real problem is dealing with the contents of the form submission. I could care less if the form is automatically submitted, as long as I know whether to ignore that form. Captcha just erects a small barrier. One of the best things I ever did to combat spam on inbound mail was greylisting + dspam + tmda. If dspam has a high confidence that it is spam, tmda sends a challenge/response. While I've never given out my gmail address, the amount of spam it receives is ridiculous. My own solution, even the spam folder rarely sees more than a few messages a week. My personal blog, discounting trackback spam has had 71 spam posts in the last week. I use RPXnow (requires one of the shared auth providers or someone needs to create an account) and recaptcha with Akismet. It hasn't stopped the spam that is received, merely what gets automatically published. I do believe that every submission received on my blog comes from a human, or has at least had some human interaction. Captcha doesn't solve the problem, merely erects a small barrier and just makes sure the spam I get is more likely hand delivered.
- michael_dorfman 16y agoI know we're supposed to be all starry-eyed about "the wisdom of the crowds" and all that, but I have trouble to believe that a random bunch of Stack Overflowers are going to come up with anything truly interesting in a field that already has the serious attention of researchers at Google and Microsoft Research.
- cd34 16y agorecaptcha didn't originate at Google. There are smart people working outside the Google and Microsoft ecosystems. While I am not a real fan of Stack Overflow, they've had incredibly nebulous questions that have turned into wiki's before - this one somehow failed to meet their standards. First thing in a startup - solve someone's pain. Human Verification is a pain point for web data entry.