5 ms·
> Serious question: who has a decent plan to create proof-of-human systems that are not only CAPTCHA based? > We will soon need this, and I feel government wil
by x-complexity 3y ago
> Serious question: who has a decent plan to create proof-of-human systems that are not only CAPTCHA based?
> We will soon need this, and I feel government will gladly present a solution: provide your ID when you connect to the Internet, and we will guarantee you are a human.'
I'm extremely hesitant to give any State the ability to track an individual user's online activity that intensely. It's been extensively documented that any State will fully utilize its size to violate an individual's personal privacy, with this often being done on a grand scale.
> Who's actually working on this and has released papers I can study? Because all this AI nonsense will only accelerate us towards this total control of the Internet because the spam and AI bots have made it worse for everyone.
The alternative is relatively straightforward: Utilize compute-intensive & memory-intensive tasks in CAPTCHAs.
https://github.com/mCaptcha/mCaptcha https://github.com/mCaptcha/mCaptcha
What would only take a few seconds for a single user would take hours for anyone seeking to establish a bot network spanning thousands of pseudo-users. With such tasks, it adds additional friction to the bots at minimal frustration to the user. these can be placed as periodic silent challenges when trying to watch an episode, taking up only a few seconds at the user's end where they wouldn't notice.
https://news.ycombinator.com/item?id=32339902 https://news.ycombinator.com/item?id=32339902
- notatoad 3y agothis is the second plug i've seen today for mCaptcha. and i can see the utility, i've actually got a spot where it would be perfect and plan to implement it. but it's absolutely not a captcha: it is not a test to tell humans and computers apart. it's a test that can only be completed by a computer. its only utility is to be expensive. it's not a test to determine if there's a human behind the computer, it's only a test to determine if the computer has more resources than it currently needs, and can tolerate wasting some of them for a while.
- hedora 3y ago> What would only take a few seconds for a single user would take hours for anyone seeking to establish a bot network spanning thousands of pseudo-users. The claims on the mCaptcha site contradict this. They say it takes about 2 seconds worst case for a computer to do the work, which is hashing sha 256. Looking around, an unaccelerated celron is about 1/20th the speed of a single ryzen core, and gpus are much faster. Assuming the attacker has an 8 core ryzen with no gpu, they can hash 160 times faster than the person with an older machine. Assuming the 2 sec upper bound is correct, this means a sub $1000 desktop can create 80 accounts per second, or 4800 accounts per minute. If they are operating a botnet, then they presumably have access to more than one machine.
- userbinator 3y agoUtilize compute-intensive & memory-intensive tasks in CAPTCHAs. One look at what happened with cryptocurrencies tells me that isn't going to work.
- sph 3y agomCaptcha doesn't prove you're a human, it only proves you're not a spamming bot. What I am asking for is a reverse Turing test. Because there will come a time that any single site will need you to prove you are a human to do any action, i.e. post a reply or create an account. We need a better plan than CAPTCHA that takes minutes to solve every time someone needs that type of proof. I know government ID schemes are awful for privacy, but that is the only decent solution I can think of. If we, the computer people, do not have a better solution, the government will solve it for us, big tech will adopt it, and we have opened the doors to total surveillance.
- danpalmer 3y ago> I'm extremely hesitant to give any State the ability to track an individual user's online activity that intensely. The U.K. government developed something called GOV.UK Verify for exactly this. It’s sort of like OAuth via a stateless gateway I think. The promise is that the entity doing the auth doesn’t know what you’re using it for, and the entity receiving the auth doesn’t know how you proved auth and only gets the level of detail about you they asked for (and you agreed to). For example, if a govt website wants to know whether I’m eligible for something based on my local council, I could authenticate with my bank, who would say where I live with only that granularity, not my full address, and my bank wouldn’t know what service I’m trying to use. I’m not sure how much of this got put into practice but all the ideas were pretty smart and showed there are good approaches to this sort of stuff.
- danpalmer 3y agoI once suggested to a PM from the GOV.UK Verify team that if the UK wants to do age verification for porn, which it has threatened many times over the last decade, that Verify would be the perfect tech for it as content sites would only find out you're over 18, and auth providers would only know they're proving basic details about you. The PM did not like the idea of the government being the porn passport for the whole country.
- x-complexity 3y ago> I once suggested to a PM from the GOV.UK Verify team that if the UK wants to do age verification for porn, which it has threatened many times over the last decade, that Verify would be the perfect tech for it as content sites would only find out you're over 18, and auth providers would only know they're proving basic details about you. To me, that's still *way too much*. Just from that, the government now immediately knows what site you've been to (via the token that you've given to the service), and what said site has access to, as well as when you've accessed it. On a long enough timescale, the government can build a daily profile of your life, that when coupled with geo-location data, can be used to see what & where an activity's happening in real time.
- Semaphor 3y ago> I'm extremely hesitant to give any State the ability to track an individual user's online activity that intensely. It's been extensively documented that any State will fully utilize its size to violate an individual's personal privacy, with this often being done on a grand scale. I think our (Germany) national IDs would theoretically have that option using certificates. I didn’t look too much into their online features as I never encountered anything supporting them, but my understanding is that I can prove some fact about myself (age, name, or simply being a citizen/resident), without either the government knowing I did it, nor the company knowing more than what I asked to show.
- rapnie 3y agoI posted about mCaptcha yesterday, and a major discussion followed: https://news.ycombinator.com/item?id=36110952 https://news.ycombinator.com/item?id=36110952
- tetromino_ 3y ago> The alternative is relatively straightforward: Utilize compute-intensive & memory-intensive tasks in CAPTCHAs. Visitor A is a legitimate human being from a poor country using a bargain brand Chinese phone with hardware that could be charitably described as "slow as molasses". Visitor B is a troll for hire with a rack of used crypto mining machines in his basement, running hundreds of Chrome processes proxied through hundreds of hacked residential IP addresses. Your approach would make the website unusable for human visitor A, while being the tiniest bit inconvenient for visitor B's hundreds of alts.