3 ms·
I don’t think this actually provides “defense-in-depth” as they claim. At the end of the day, whatever signals they determine mean “bot” or not are the actual c
by bennyg 3y ago
I don’t think this actually provides “defense-in-depth” as they claim. At the end of the day, whatever signals they determine mean “bot” or not are the actual critical defense. I’m assuming their PoW system doesn’t scale the work for human-classified requests, such that if there’s some unintended loop humans aren’t affected while bots would be. That again means that seeking a “human” designation is the important piece that bad actors will attack. The same goes for the UI challenge - these are becoming notoriously easy to ML your way to victory as a bad actor or to use actual humans to solve for cheaper than the value they get from beating the CAPTCHA.
An actual defense-in-depth strategy would be one that uses a tool like this for generic browser/device level signal interrogation AND domain/product-specific behavioral analysis. That would be 2 different layers — depth.
- protonmail 3y agoThere has been a trend recently in computation proof of work only CAPTCHAs, e.g. mCAPTCHA, or Friendly CAPTCHA (https://proton.me/blog/captchas https://proton.me/blog/captchas), but our own data shows that these are not sufficient to stop attackers due to compromises made to make PoW work for real users with slow devices. Adding the visual challenge has been essential in stopping these attackers. The combination of computational proof of work and human proof of work does in our experience provide defense in depth. However it's not perfect. One of the differentiators of ProtonCAPTCHA is that we've built this system with the expectation that someone will break it. So, as you've alluded to, in the event that someone or some thing is able to navigate these challenges either through automated mechanisms, or via third party solvers, we have defenses against such attacks/automations. That is a third hidden level of defense -> however, you will understand that for obvious reasons we do not divulge how this is done.