4 ms·
This isn't a huge problem for security people. Indeed, at most academic security conferences, by the time you present your work it has usually already been brok
by barik 14y ago
This isn't a huge problem for security people. Indeed, at most academic security conferences, by the time you present your work it has usually already been broken and/or countered.
To goal of good research (and one that differentiates researchers from criminals) is to present a proof of concept and to advance the state of security. The fact that security is a perpetual arms race is incidental.
Well, at least that's what security researchers tell themselves anyway to avoid going mad. :)
- JackC 14y agoWhat makes it funny is that the bulk of the article isn't "here's how we did it and what we learned," but "here's what you need to do to get our code running on Ubuntu." Then you get to the footnote: "PS: It's pointless to get our code running on Ubuntu." I spent the whole article wondering why they were so interested not only in presenting a proof of concept, but in getting as many people as possible actively breaking captchas. Then I got to the end and switched to wondering whether the whole thing is an elaborate prank.
- barik 14y agoYes, I thought this particular link was perhaps not the best way to present the work, mainly because the interesting part is actually this: "We accomplished this with a combination of Machine Learning, hashing methods, keyspace reduction tactics, and taking advantage of an overall limited number of captchas. Specifically, Stiltwalker goes head to head against reCAPTCHA'S audio captcha system and defeats all but a sliver of it's challenges." On the other hand, it looks like they provide a corpus (http://www.dc949.org/projects/stiltwalker/stiltwalker-corpus.tar http://www.dc949.org/projects/stiltwalker/stiltwalker-corpus...) [1.5 GB!] that you can still use to run the program.