3 ms·
We can change the hashing algorithm at will which is different from cryptocurrencies (potentially even on a timer). By changing here I don't even mean swapping
by protoduction 6y ago
We can change the hashing algorithm at will which is different from cryptocurrencies (potentially even on a timer). By changing here I don't even mean swapping out entirely, but even randomly changing the operations inside the hashing function - which will make it a moving target for any ASIC or even GPU implementations.
Right now we use standard blake2b as nobody has repurposed a miner to solve hashes for spamming yet.
The thing is, a determined spammer will be able to attack any CAPTCHA - even in labeling tasks there is always the fallback to human-in-the-loop which is cheap at scale (or even free if these are MITM'd users..).
Any (new) CAPTCHA system will have flaws and break in some way at scale, we're open to ideas and of course will try to address any (future) concerns. We are trying to provide a viable alternative to ReCAPTCHA that respects the user - and we will iterate on these problems as we go. Without some new thinking and openness to new approaches we'll be stuck with ReCAPTCHA.
Small nit: the difficulty is set to require around 2.5 million hashes, not 115 thousand. Your point still stands though.