7 ms·
GPT is such a softie haha. I wonder how CAPTCHA is going to evolve though to combat this long term. A finger prick to take a blood sample to confirm humanity?
by adocomplete 3y ago
GPT is such a softie haha.
I wonder how CAPTCHA is going to evolve though to combat this long term. A finger prick to take a blood sample to confirm humanity?
- paulpauper 3y agoThey will just keep making them harder, more steps, etc. Also, the rise of phone verification.
- deleted 3y ago[deleted]
- AnthonyMouse 3y agoPhone verification wouldn't work at scale, the more services use it the more profitable and common it is to have sites that let people receive SMS to a random phone number over the internet etc. It's also likely to lead to some kind of privacy laws in various countries (or may already violate some) because a primary reason services use it now is so they can snatch your phone number and use it to correlate you across different services. Which for the same reason makes honest users wary of it, especially as it becomes increasingly common knowledge why services ask for it. A good solution might be some kind of anonymous payments system, so you can make a nominal refundable deposit to create an account which is forfeit for abuse, and then sites can fund more expensive or manual abuse-detection systems from the forfeited deposits in proportion to how much abuse they encounter.
- EGreg 3y agoCan’t AI simply carry on a complete phone conversation in your voice, trained on all your emails and transcribed zoom calls? Oh, we are trusting the corps won’t train in that and won’t fine tune on our personal data. Ok! Things can get really wild when AIs can open lots of fake accounts all over the place. Most banks ask me verification stuff that has probably been stolen many times by now.
- AnthonyMouse 3y agoThe point of the phone verification isn't that the AI can't impersonate you, it's that you have to give them a phone number. Which they mostly want so they can track you, but in theory phone numbers cost money and provide a rate limit. The problem with this theory is that phone numbers are actually just bits in a phone company's computer and gaining access to them in bulk will become both cheaper and more common the more demand there is for it.
- mminer237 3y agoI've never had a VoIP number work for phone verification. Providers seem very diligent in blocking such services to prevent their usefulness from degrading. Very large companies like Google, Meta, and Valve already are quite successful at requiring a phone number for verification at scale.
- AnthonyMouse 3y agoThe services don't have to use VoIP numbers. Nothing stops them from buying cheap prepaid SIM cards in bulk and putting them in a bank of devices connected to their servers. Scale here is not the size of the service, it's the number of services that use this verification method. When you have 1000 phone numbers and one service requires this, you can use them to create 1000 accounts on that service. When you have 1000 phone numbers and 100 services do this, you can use them to create 1000 accounts on each of them, i.e. 100,000 accounts. So the value of each number increases but its cost stays the same. There will no doubt be some cat and mouse game where they try to detect the numbers being used for this and block them, but that's not going to work too well since a prepaid SIM card is cheap and as soon as they're done with it, it goes back to the carrier to be assigned to an ordinary customer.
- BenjiWiebe 3y agoChase Bank allows Google Voice numbers. In fact I'd say around 95% of the services I use which require SMS work with Google Voice.
- wincy 3y agoHow are blind or deaf people supposed to ever interact with the world we’ve created?
- jdietrich 3y agoAn ADA-compliant phone verification service should offer the choice of an SMS or a voice call. If you're deaf and blind to the extent that you can neither hear nor read a six digit number with the benefit of assistive technology, then the accessibility barrier posed by verification step is academic.
- Qwertious 3y agoSMS clients aren't inherently visual; there's almost certainly a braille device that can be interfaced to an SMS client, no hearing nor (visually) reading required.
- knoebber 3y agoPlease drink a verification can
- eep_social 3y agoIdent-I-Eeze [1] probably. Password managers are part of the way there and the use of biometrics is slowly but surely expanding. Just a matter of time before I can have a card that presents the data from a blood sample to save me the hassle of actually bleeding. [1] https://scifi.stackexchange.com/questions/92738/what-is-the-name-of-the-id-card-in-mostly-harmless/92742#92742 https://scifi.stackexchange.com/questions/92738/what-is-the-...
- kuratkull 3y agoSo that's what the robots were using humans for in The Matrix!
- dannyphantom 3y ago> A finger prick to take a blood sample to confirm humanity? Funny enough - I actually wrote a [cathartic] short essay on that very concept a few months ago when I was being buried alive by captchas. I called it 'Blood for Access: An Alternative Approach to Circumvent Captchas'. Here is an excerpt from the final paragraph: In conclusion, the current state of captchas deployed across the internet can be frustrating and exclusionary for many users. My proposal for a blood-based authentication approach aims to highlight the absurdity of captchas and advocate for a more user-friendly and inclusive internet experience. While there may be challenges in implementing this approach, the potential benefits in terms of improved user experience and inclusivity make it worthy of consideration. It's time to explore alternative methods that prioritize user accessibility and convenience while maintaining security, and blood-based authentication could be a step towards a more inclusive internet for all users.
- tyingq 3y agoAlso featured in the movie Gattaca for access to the workplace.
- tapotatonumber9 3y agoFinally! A use for Theranos.
- chihuahua 3y agoAll it needs to measure is whether it's fresh human blood. Maybe their groundbreaking technology can handle that.
- msm_ 3y agoMost CAPTCHAs are already solvable automatically. Usually there's a rate limitter as a second line of defense, and also some heuristics that detect bot-like behaviour (user keeps upvoting posts of certain users without even reading them and uses API in a otherwise non-standard way? Hmmm, throw more CAPTCHas at them and ultimately ban them). Finally, recaptcha and (probably cloudflare's captcha?) tracks wayy more than just how correct you are in recognising street signs, and correlates this to your overall network activity. You can't rely on just CAPTCHAs anyway, because mechanical Turks are too cheap compared to the damage they can do.
- bentcorner 3y agoMaybe we end up taking the problem to a deeper level - for some accounts the true test if they are human is if they fail a captcha test.
- follower 3y ago...or if they refuse to dance like a monkey and close the window instead.
- danenania 3y agoI think captchas are facing a battle that is unwinnable in the long run. It's not going to be possible to reliably differentiate between a human and AI for much longer in a way that scales and is cost effective. It could mean the end of free accounts for many kinds of services.
- makeitdouble 3y agoCaptchas have never been reliable, the whole point was just to have a mechanism that costs more to decrypt than to produce. I think we're still there as the cost of running the models stays high, though it's subsided at this point. And I don't if we'll ever hit a point where decrypting and encrypting costs reverse.
- december456 3y agoI see two futures ahead: one with "free" content (data harvesting) remaining alive through remote attestation, physical key verification, phone verification etc. and one with completely paid and exclusive communities scattered around with only a few percent being able to access a meaningful amount of information. Maybe both. But things dont seem to be as bright as some AI lovers make it to be. Hopefully im just being unrealistically pessimistic and open governance prevails, somehow.
- xp84 3y agoI would be thrilled about the end of free accounts. Things that don’t seem to cost that much to run can charge token amounts, and things that cost more like say, Gmail, should just cost money. Right now the existence of the shitty, ad-supported version of everything drives out anything good. Why build and innovate in any consumer software product when Google is there offering a free ad-based one that will always get 90+% of the users?
- PeterisP 3y agoCaptchas are used to distinguish between anonymous humans and scripts trying to impersonate a large quantity of unrelated humans. The other way of preventing someone from impersonating many fake people with a script is requiring actual verification of identity - that's a higher barrier of entry and (for now) requires country-specific solutions and so is harder to internationalize/globalize, but this seems the direction the world is moving towards.
- jdietrich 3y ago>I wonder how CAPTCHA is going to evolve though to combat this long term. CAPTCHA is really just a proof-of-work system, it just happens to use problems that are easy for humans but hard for computers. It has never proved that the request is a genuine human request, it just proves that a human was in the loop somewhere; that human can just as easily be a Bangladeshi employee of a CAPTCHA-solving-as-a-service provider who is accessed via an API call. If we run out of problems that are easy for humans but hard for computers, we can fall back on the infinite set of problems that are just hard.
- hackernewds 3y agoThat will crash inevitably into the 'lets make the trash can tough for bears. oops we also made the trashcan tough for 10% of humans'. (is there a name for this phenomenon?) it's an optimization problem, with context dependent levels of true negative, false positive acceptance criteria
- hackernewds 3y agosurely you cannot have a million Bangladeshi humans reading captcha via API due to the realities of eligible population / cost at scale, so it still does function for most use cases that want to leverage such "automation".
- lotsofpulp 3y agoI assume it will be verified human by hardware certified by Apple/Google/Microsoft.
- mrshadowgoose 3y agoRemote attestation mostly solves this: https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/ https://blog.cloudflare.com/eliminating-captchas-on-iphones-... The downside is that this will quicken the normalization of consumer devices that we don't really own/control. Using an Android device without passing SafetyNet checks is already a painful experience.