10 ms·
I built an alternative[0] that takes a proof of work approach. As a site owner you set the difficulty that makes sense for you: so perhaps you would want 20 sec
by protoduction 6y ago
I built an alternative[0] that takes a proof of work approach. As a site owner you set the difficulty that makes sense for you: so perhaps you would want 20 seconds of computation before you can submit. The nice thing is that this can happen entirely in the background while the user fills in the form.
Also with multiple requests from the same IP in a short timespan, the difficulty increases.
There are downsides to to any captcha, but in my opinion make a much better tradeoff. Accessibility and privacy are respected, and there are no annoying tasks.
[0]: https://friendlycaptcha.com https://friendlycaptcha.com
- lowlevellimbo 6y ago> FriendlyCaptcha will prevent 99.9% of spam For someone who has little expertise in this specific field, how are you calculating this?
- protoduction 6y agoAdmittedly it's not calculated so it may be a stretch, it's based on the assumption that the vast majority of spam out there just looks for forms to submit without smarts (which is also why honeypots can be pretty effective, especially if you have a small website that nobody will take the effort to work around it.) I've seen people report that they have reduced spam to near nothing already with just a honeypot, but of course I can't verify those claims.
- protoduction 6y agoJudging by the downvotes (despite answering the question truthfully), I see it's not a good way to present ourselves, and frankly we don't have to make that claim. It's hard to estimate the real percentage, our customers are happy but measuring what is no longer there is tricky in the real world. I will change the wording on the website and remove the percentage.
- tehjoker 6y agoPeople take quantitative claims seriously. I wouldn't make them without being able to defend them in an intellectually rigorous way.
- Aeolun 6y agoIt should be fairly easy to set up two open wordpress blogs, one with the captcha and one without. After a few months you check how much spam arrived at either and get your number?
- gaelian 6y ago> I've seen people report that they have reduced spam to near nothing already with just a honeypot, but of course I can't verify those claims. Can verify from personal experience. I once implemented a simple honeypot approach on a small blog site. It immediately cut down automated "drive by" comment spam to almost nothing. I never tried to quantify it, but it was the difference between dozens of spam comments a day and maybe one or two a week (which I assumed were probably manual submissions). Most spam bots are pretty unsophisticated it seems, and do not pay any attention to a honeypot field being hidden either by CSS or JS.
- smittywerben 6y agoAs a counter-point, the uncaptcha[0] research project used Google's free Speech-to-Text service to solve reCAPTCHA at a reported 85% success rate. I'm convinced CAPTCHA are no better than fake/dummy security cameras. [0] https://github.com/ecthros/uncaptcha https://github.com/ecthros/uncaptcha
- withinboredom 6y agoHow do handle low-end devices? Do you reduce the difficulty for them and can this be abused by pretending to be a low-end device that really isn't?
- protoduction 6y agoEverybody gets the same difficulty initially which you determine as a site admin, so one should base this on their audience (e.g. Gitlab would have a different device profile from a government website). The solving can be a few times slower on a low end device which you should keep in mind. To aid with this when setting the difficulty for your website it shows you an estimate for various device types. This is indeed a downside of PoW approaches. There is one factor that helps: you can start solving as soon as the form loads, so as the user enters their details/comment it can start solving - I have a hunch that people on mobile devices are inherently slower at entering their data which should help a bit.. Anyway - if you set the difficulty quite high and the solving takes 30 seconds, it takes the user 15 seconds to enter the form - the user would still have to wait 15 seconds. That's not very different from the time to solve image captchas (it's actually lower and doesn't come with a 2MB payload download which isn't great on phones either, and they can keep their privacy + sanity). You could give the user something to do that makes sense for your website (ask them for feedback?).
- 10000truths 6y agoWhy bother with a proof of work scheme when you can just rate-limit directly? It accomplishes the same thing, while eating way fewer CPU cycles, doesn’t require JavaScript, and guarantees uniform cost between all client types.
- __s 6y agoThis sibling comment was responding to you: https://news.ycombinator.com/item?id=25215024 https://news.ycombinator.com/item?id=25215024
- withinboredom 6y ago
- dastx 6y agoIt doesn't work for me, comes back with the error: Verification failed: Background worker error undefined I'm using latest Firefox on GNU/Linux. Admittedly I've got a lot stuff blocking all sorts of things, and I'm not really sure what's kicking to block background workers, but I'm glad it's blocked. Anyway, after disabled literally all blocking tools that I have, it still refuses to load.
- protoduction 6y agoThat's not good, could you maybe provide more details in the Github repo [0]? The widget is open source, hopefully we can figure out what is blocking it here. We test the captcha in browsers up to 8 years old and on many devices, do you perhaps have background workers disabled entirely? Here is a link to the widget on its own [1], does that have the same behavior? How about a minimal worker example [2]? [0]: https://github.com/FriendlyCaptcha/friendly-challenge https://github.com/FriendlyCaptcha/friendly-challenge [1]: https://unpkg.com/friendly-challenge@0.6.1/index.html https://unpkg.com/friendly-challenge@0.6.1/index.html [2]: https://jsfiddle.net/christopheviau/90syrp0q/ https://jsfiddle.net/christopheviau/90syrp0q/
- OvermindDL1 6y agoDidn't try the other links but the jsfiddle link just says Preparing worker in Firefox here and neither button ever does anything.
- mNovak 6y agoCurious why it wouldn't start 'verifying' immediately on load? The fact that it runs in the background is really key--I'd hate to fill out an entire form, click the button at the end, and still have to wait around to submit.
- protoduction 6y agoYou can change this behavior of the widget (data-start="auto" instead of default data-start="focus"), or you can start it programmatically. The reason you wouldn't always want to start it in the background is if the user may not intend to submit the form (perhaps it's a form that is in your footer of every page and only a small percentage of users intend on sending it). Starting it on focus of the form is a good default.
- technofiend 6y agoFirst one to make this mine an altcoin for proof-of-work wins. But seriously I like the idea, although it seems trivial for someone to attack a protected site by exhausting its subscription level? Are there any protections against that?
- protoduction 6y agoWe don't disable the service if a protected site goes over their limit. Right now we manually look at the limits and are reasonable with overages - also we can see how many captchas were unsolved.
- lambdaloop 6y agoWow, this is an awesome idea. I can imagine this could be extended to solve tasks to mine cryptocurrency. If you get attacked by a botnet, you would actually make a profit!
- peterhunt 6y agoproof of work really doesn't work well in practice. spammers have huge farms of compute, often on residential ips, and legit users are accessing the service from a device that is often power-constrained (like a phone). you end up either hugely penalizing legitimate users, or having to employ many of the standard antispam techniques (IP/ISP reputation, captcha, rate limiting etc) on top, so the proof of work adds a lot less incremental value.
- protoduction 6y agoIt's not perfect, and you are right about the downsides. These resources that spammers have can be applied as easily to re/hcaptcha (either through ML or clickfarms). No CAPTCHA will actually lock out targeted attacks. The difficulty increase per IP can be seen as a form of soft rate limiting, it's shared between all websites (which is where it's different from ordinary rate limiting). In the future we may use IP reputation lists to guide the initial difficulty too - but we haven't implemented that yet. I think that no perfect captcha can exist, which is inherent to the problem. Proof of work makes different fradeoffs, and perhaps it is cheaper to attack still - I think it's a much more friendly solution for users though (accessibility, privacy, simplicity, fairness, UX). Maybe in the future the solution would be something like this: a long PoW-based captcha that runs in the background as well as a vision task for the user, whichever gets solved first.
- sitkack 6y agoI get re-captcha'ed all the time from the same IP. And if I don't use Chrome, the captcha count is like 4x-5x higher just for using Firefox.
- MeatBro 6y agoThat's why I have even stopped using google services. If I literally have to get another browser to use your snowflake site, then why would I use your service anyway?
- sxt 6y agoThis reminds me of a similar solution I saw on PH last year, I think it's a great alternative for smaller websites that are less likely to be targets for spams/bots But say, there's a website and it's a likely target, you implement IP protection, fine, the user uses residential proxies. Now your best bet is to go off fingerprinting, but there are marketplaces which sell those too in bulk. Maybe I'm wrong, but wouldn't the best approach be to stick to human interaction puzzles, which are hard and don't have a set way to solve by a machine(for now)?
- asutekku 6y agoSo your solution is to technically waste electricity to replace captcha? It's for sure an interesting concept, the first point and low-end devices requiring 20+ seconds to pass are not a very good points to sell your service.
- protoduction 6y agoYou're right that there is an electricity cost to solving this type of captcha - the same as there is an electricity cost to loading 2MB of JS+images and clicking the pictures with the fire hydrants (and the infrastructure behind that). It's hard to estimate how they compare (and what value you assign to the human labor performed and privacy loss). 20 seconds would be a fairly high difficulty. It's up to the site owner to decide what makes sense for them. If anybody comes up with a useful computational task with a small bundle size that can be verified cheaply that would be the holy grail - until then the computation is only there as a form of hashcash.
- olliej 6y ago20s doesn’t matter when it’s someone else’s hardware (eg spammers using malware installed on victim machines). It’s also nonsense to compare the computational cost of N seconds of sustained, maxed out useless computation to the milliseconds of compute time needed to decode an image, or the minimal power usage of waiting on network data.
- olliej 6y agoRight? I think they’re describing those crypto mining scripts people were being inflicted with a while back :)
- Aeolun 6y agoElectricity is a lot cheaper than my time.
- lights0123 6y agoAnd Cloudflare already does that—that's what the "Checking your browser before accessing xyz—Please allow up to 5 seconds" message means. It's clearly not enough for them though, because they then go to also require CAPTCHAs.
- seirim 6y agoThis is very interesting. Can you change the questions in the form? Those questions seem too personal and are offputting.
- eatbots 6y agoProof of work by itself is nearly useless, unfortunately. Compute is cheaper than people. This is one reason why CAPTCHA services will likely be with us always. As someone working in the field, I also doubt your claim "will prevent 99.9% of spam" is based on real data. Modern headless browser spambots are not deterred by this kind of approach. (Edit: looks like the poster admitted this number was entirely made up later in the thread.)
- sim_card_map 6y agoThis looks very interesting and clean. Well done!
- hansvm 6y agoIgnoring the other criticisms because they generally seem valid, to everyone saying that proof of work doesn't matter because bots can just use more machines, that depends a lot on the economics of any specific automation project. I scrape a little data here and there, and a reliable proof of work system costing ~20s on a commodity core would make some of my personal projects cost tens of thousands of dollars monthly. Maybe that's worth it to someone (e.g. if they have an army of hacked machines without anything better to do), but I think it'd keep a lot of the riffraff out.
- capableweb 6y agoI just tried loading the demo of Friendly Captcha in 8 browser windows, and click the verify button, refresh the window and on repeat for about 3 minutes. Not once did it tell me that I'm a robot so seems your alternative fails the most basic of captcha functionality, limiting people/machines to spam functionality that the website owner wants to be limited. Maybe not everyone but a lot of people use captcha services to prevent automation from being used to extract/insert data. I know as a developer that there is always a chance of bypassing this, even with Google's reCaptcha, but your service seems to make this trivial, so many won't even go beyond your demo.
- theon144 6y ago>Not once did it tell me that I'm a robot Right, unfortunately you've completely misunderstood the point of Friendly Captcha, a question which is answered right there on its main page. >>How does FriendlyCaptcha tell apart bots from humans? >>It doesn't, FriendlyCaptcha adds a small cost and complexity for spammers that becomes large at scale.
- capableweb 6y agoRight, I guess it's time for you to upgrade the UI of your tool then, as when it's inactive it says "Anti-Robot Verification" and once the challenge is done it says "I'm not a robot", while in reality, none of those things are true, as you said yourself. You might also want to rebrand to use a different word than "Captcha" as you're not actually telling robots and humans apart, you're simply adding PoW to an action, nevermind if they are robots or humans. So instead of blaming users for misunderstanding your message, maybe try working on making your messaging a bit clearer so for the people who know what captcha is, don't get confused by your own definition of it.
- matteocontrini 6y agoActually the user you're replying to is not the author of the service, from what I can tell.