4 ms·
I built FriendlyCaptcha [1], it's a proof of work based alternative to reCaptcha that is accessible. While it's not the perfect captcha either (which I think i
by protoduction 6y ago
I built FriendlyCaptcha [1], it's a proof of work based alternative to reCaptcha that is accessible.
While it's not the perfect captcha either (which I think is impossible), it makes a better tradeoff in terms of UX, price and privacy.
[1]: https://friendlycaptcha.com https://friendlycaptcha.com
- bo1024 6y agoI think this is a great solution! I have been thinking over the problems with captchas and also came to the conclusion that a proof-of-work puzzle is a fair, private, and hopefully-effective solution. You can look around for "useful" work, similar to how recaptcha was originally about transcription. If you can find some problems of the right difficulty that people want solved (e.g. I dunno, protein folding or something), then the electricity isn't wasted and you might even be able to sell the solutions.
- gruez 6y ago>The problem with other CAPTCHAs > It's broken >Tasks that are easy for all humans but difficult for computers may no longer exist. >Using machine learning or even browser plugins one can solve ReCAPTCHA in under a second. There are even CAPTCHA solving companies that offer thousands of solves for $1. This is probably a bad argument when your proof of work captcha can be solved for much cheaper. Your site says "Solving it will take a few seconds on a desktop computer", which I'll interpret as 5 seconds. The spot price for a c5a.2xlarge instance (8 thread zen2 CPU) is 21.6 cents/hr. That works out to 0.03 cents per solve, an order of magnitude less than the 0.1 cents per solve for commercial recaptcha solving services. It probably gets even cheaper if you get your compute through non-cloud providers, or through GPUs.
- snazz 6y agoThe FriendlyCaptcha demo takes less than a second on my machine (i5-7400, RX 560). A c5a.2xlarge is far more powerful.
- deleted 6y ago[deleted]
- protoduction 6y agoYou're right that it won't stop determined attackers, there was some prior discussion here [1]. The idea is that it's good enough - while not punishing your users as much. The difficulty can be scaled in a predictable way - it's similar to rate limiting but less all or nothing. We're about to release automatic difficulty scaling per IP, so if many CAPTCHAs are requested/submitted from a single IP the difficulty increases exponentially. Also being able to set the initial difficulty for your usecase and audience is something that should help. Aside from that there's some more measures on the roadmap: using lists of known-to-be-datacenter IPs, and reputation lists such as [2], as hints to increase the difficulty. But you're right - it will still be affordable to attack any CAPTCHA, FriendlyCaptcha is no exception. Proof of work approaches have downsides too. The main ideas behind FriendlyCaptcha vs ReCAPTCHA: * The user experience is superior. It can happen in the background while the user is doing something else. There is no labeling task. * We don't have any incentive to collect user data or track users (GDPR compliant, no tracking cookies etc) * It's as easy to add as ReCAPTCHA to your website. The API is a near copy of ReCAPTCHA's API. You can host the JS code yourself, or even bundle it. With recaptcha it must be third party. * It works in any browser less than 8 years old (IE>=11), although of course it's much slower in old browsers that don't support WebAssembly. * It doesn't have inherent accessibility problems (poor eyesight/hearing doesn't matter). * Open source at its core [3], the SaaS wrapper is not open source. [1]: https://news.ycombinator.com/item?id=24921288 https://news.ycombinator.com/item?id=24921288 [2]: https://www.stopforumspam.com/ https://www.stopforumspam.com/ [3]: https://github.com/friendlycaptcha/ https://github.com/friendlycaptcha/
- saddlerustle 6y agoIP reputation doesn't work for anti-abuse at scale. Traffic on NAT'd broadband and mobile networks can be purchased for cents per gigabyte. All those upsides are not compelling if it doesn't effectively stop abuse.
- 0df8dkdf 6y agowhat about hCaptcha https://www.hcaptcha.com https://www.hcaptcha.com?
- 0df8dkdf 6y agobut yeah. rCaptcha is horrible. And you know google is making money of you when you use it, and some times it takes 10 - 15 minutes to finish one thing. I hope the site owner are getting paid for my work, not just google.
- dmix 6y agoThe idea that 1) Google is using it to train modelling stuff (I still think is true?:) for free AND 2) on top of that is also charging small startups money for it AND 3) it's annoying as hell as a customer just makes me angerier. A trifecta of doing evil from Google (well at least two out of three, 1 should cover for 2). And I say that as a relatively pro-capitalist with no problem charging money for services but I'm also pro-privacy and don't like training their AI models for free with them charging the hosts on top of it.
- tyingq 6y agoCurious how spam bots react to Friendly Captcha. If it's just gobbling a bit of cpu time, I assume they mostly don't notice.
- 0df8dkdf 6y agointeresting project. However, couldn't what they are doing be simply solved by applying bcrypt or scrypt in JS?