CAPTCHA hacked
This story might interest some people here.
The Gmail CAPTCHA has been cracked—albeit not easily—raising new concerns about spammers' ability to abuse Google's e-mail services. Websense Security Labs pointed out the security breach late last week, noting that spammers have a lot to gain by being able to use bots to automatically sign up for new accounts.
Google's free e-mail services and a highly-desirable gmail.com domain—one that is unlikely to be blacklisted by anybody's spam filters—are just two of the features that induced spammers to crack the CAPTCHA and have bots do all the work. On the upside, it apparently wasn't easy—Websense says that it required two bot hosts to crack instead of just the one that recently cracked Windows Live Mail's CAPTCHA (Websense believes that the same group was involved with both). It also believes that the two hosts are required because the first host may fail at cracking the code the first time around (and possibly time out), but the second host may also be required to check the work of the first. Additionally, only one in every five CAPTCHA-breaking requests on Gmail succeeded. Still, a 20 percent success rate is relatively high when you consider that spambots are trying to register hundreds (or thousands) of e-mail addresses at a time.
The CAPTCHA test—Completely Automated Public Turing test to tell Computers and Humans Apart—is one we're all familiar with. When signing up for new services, we are often asked to decipher a series of letters and numbers embedded in an image that is supposed to be difficult for computers to read. But, while the CAPTCHA has worked well in the past, hackers are getting better at programming computers with the ability to read them.
That's why there has been some attention focused on creating stronger, harder-to-break CAPTCHAs. There are, of course, audio-based ones that read something aloud and require the user to enter it back into a text box. But there's also a more complex image-based CAPTCHA that requires the user to select a number of similar images before proceeding.
Of course, neither of these options are perfect, as the former doesn't take into account hard-of-hearing computer users, and the latter makes it all but impossible for blind users to sign up without assistance. But for now, there are few other options to block spammers from getting through while the traditional CAPTCHA continues to be cracked.
Further reading:
- Found via The Register: Spammers crack Gmail Captcha
- Google’s CAPTCHA busted in recent spammer tactics
Link
- Login to post comments
Are we surprised? When has benevolent technology ever been able to keep up with weapons tech? Better AI through hacking.
Atheism isn't a lot like religion at all. Unless by "religion" you mean "not religion". --Ciarin
http://hambydammit.wordpress.com/
Books about atheism
Google is already aware of even bigger flaws with captcha. Here's an interesting (not so much at first) Google tech talk by the actual designer of captcha that illustrates a huge problem:
http://video.google.com/videoplay?docid=-8246463980976635143
It's nearly an hour long, but worth the watch I think. If you don't have time, the part about captcha starts at about 04:30.
----
Faith is not a virtue.
Sweet, Thanks very much, I didn`t know google did these things.
Morte alla tyrannus et dei
Yeah, Google does lots of cool things. The Google tech talks are all on Google Video, and are really interesting if you're a computer geek; and sometimes even if you're not.
----
Faith is not a virtue.