4 ms·
> Bad spoofing detection harms legitimate users and is inefficient against capable actors. On a somewhat related note: I used to write sneaker buying bots and
by kfichter 5y ago
> Bad spoofing detection harms legitimate users and is inefficient against capable actors.
On a somewhat related note: I used to write sneaker buying bots and captcha was one of the best things to happen to the bot industry.
Captcha was easily "bypassed" by services that had humans sitting at computers generating tokens. Recaptcha tokens are valid for two minutes by default, so you'd be able to generate tokens up to two minutes in advance and have dozens of tokens available when the product in question became available for purchase. Real buyers had to wait for drop and then spend 15s+ filling out the captcha. Bots would take most of the stock in less than a second. I always felt like this was a fantastic example of a bot prevention mechanism that actually actively harmed "legitimate" users.
- paulpauper 5y agoIf the landing page generates unique captachaa that are random how does this help unless the hashes are valid globally
- rapsey 5y agoRecaptcha sends the same image to multiple browsers at the same time and it gets solved by consensus I think.
- colejohnson66 5y agoYou’re thinking of reCaptcha “v2”. That was when it was about digitizing books. One distorted photo of a word had a known spelling, and the other didn’t. If you spelled the known one right, it let you through. If enough people spelled the unknown one the same way, it would “learn” how to OCR that word (of sorts). If you had time to spare/waste, you could spell the first one right, and put garbage for the second one. About half the time, it would let you through. Not sure how reCaptcha “v3” (the photos of streets one) works. It could work the same way, but just with more known and unknown (unclassified) pictures? It’s also a lot more harsh if you get it wrong: artificial delays, switching to the “click until no more remain” mode (with more delays), and more. Sometimes, it just refuses to let you through no matter what: https://youtu.be/zGW7TRtcDeQ https://youtu.be/zGW7TRtcDeQ It’s extremely frustrating.
- rdtwo 5y agoSome capcha has this vulnerability. In general bots solve capcha faster than humans now
- aledalgrande 5y agoEven things like hCaptcha?
- rdtwo 5y agoI think balko bot can solve in 2-3 sec now. It absolutely destroys Shopify.
- minitoar 5y agoPresumably it’s something like N headless browsers all waiting to click “checkout” on a cart with a decoy item in it, then when the drop happens they all update their carts with the new item and then post checkout with your precreated captcha token.
- uniqueuid 5y agoThanks, this is an excellent example. You could actually call this a symbiotic lock-in. I once read an excellent post on how SEO (despite being a gray area for search engines) entrenches Google's market share because many SEO practitioners specialize in it. If your ecosystem has become so specialized that most well-adapted users are bots, you have a problem (or not, if you can monetize bots).
- rdtwo 5y agoYeah I find that very interesting, on many sites the Anti bot software prevents humans from checking out at all. All the footlocker sites make it impossible for people to checkout. Yeezy supply is basically impossible as well. The only thing that somewhat works is the Apple Pay shortcut for sites with Apple Pay enabled. Can I ask why you quit the Bot industry? It seems super lucrative right now.
- kfichter 5y agoIt was definitely lucrative (sort of, I never broke $100k/yr but I have plenty of friends who did) but it was never particularly satisfying. I'm a competitive person but I love the collaboration of open source software. I tried creating a few open source bot projects but the economics of the bot industry just doesn't have room for projects like that. You also can't do well in the sneaker industry without making it your entire life. At the end of the day, money alone can't satisfy the soul. And I didn't care enough about sneakers. C'est la vie.
- slugiscool99 5y agoFascinating. You'd think the captcha would have implemented a check to ensure it was completed out on the same device.
- KirillPanov 5y agoThe captcha-solving services reverse-proxy requests from the human-for-hire through the botmaster's headless browser. In other words, all the javascript runs on the botmaster's machine. Only the images (or screenshots) are sent to the human-for-hire, and clicks/screenshots are sent back from the human-for-hire to the botmaster. This is the whole point of this article: device detection is generally a false sense of security.
- toast0 5y agoThese sorts of things increase the cost (you had to pay humans to do captchas and to setup the system), which can help. It really depends on what the benefits of bypassing the detection are and if those benefits can be had elsewhere at lower cost. For ticket sales or limited run product sales or similar things, the benefits of buying (and presumbably reselling) the limited item is high, and there's a limit to what you can do to detect humans (and as you've described it can be counter productive). For spam prevention, making it cost more to spam means spammers are encouraged to find somewhere else to spam, which is good for your users (while using your product anyway). But it won't stop everything, some people are going to manually type their spams, and some people will build robots to tap out their spams more like a person; and if you ruin the experience for users (especially new users) that doesn't work either; a network with zero messages is spam free, but doesn't help anyone.