Google's reCAPTCHAv2 is just labor exploitation, boffins say • The Register (www.theregister.com)
from sabreW4K3@lazysoci.al to technology@beehaw.org on 24 Jul 2024 12:55
https://lazysoci.al/post/15908454

cross-posted from: lazysoci.al/post/15908451

I’ve been saying this and people keep arguing.

#technology

threaded - newest

theangriestbird@beehaw.org on 24 Jul 2024 14:22 next collapse

This seems like the critical part to me:

The paper, released in November 2023, notes that even back in 2016 researchers were able to defeat reCAPTCHA v2 image challenges 70 percent of the time. The reCAPTCHA v2 checkbox challenge is even more vulnerable – the researchers claim it can be defeated 100 percent of the time.

reCAPTCHA v3 has fared no better. In 2019, researchers devised a reinforcement learning attack that breaks reCAPTCHAv3’s behavior-based challenges 97 percent of the time.

So it isn’t even effective at deterring bots? Then what the hell was all this for?

Sneptaur@pawb.social on 24 Jul 2024 14:24 next collapse

For getting free labor, of course.

themurphy@lemmy.ml on 24 Jul 2024 14:44 collapse

We are basically training their models/bots for them.

Kichae@lemmy.ca on 24 Jul 2024 15:03 next collapse

It’s great for gaslighting people into thinking they don’t know what a bicycle looks like!

Cube6392@beehaw.org on 24 Jul 2024 20:30 collapse

I spent a huge amount of time last night clicking on motorcycles because I absolutely could not convince PayPal or Google I was a legitimate human who wanted to exchange currency for goods and services

saigot@lemmy.ca on 25 Jul 2024 15:49 collapse

I find if I trace a figure 8 in the screen with my mouse the captcha passes much more often. I think it probably reads the small variations in your mouse movement to sus out bots, so the figure 8 gives it more data to work with.

Cube6392@beehaw.org on 25 Jul 2024 15:54 collapse

I eventually gave up and decided to see if they were being hostile to my network and privacy settings. Lo and behold, I was able to log in when I adjusted the strictness of my VPN. Fortunately the service I was trying to exchange currency for was a better VPN with more security and privacy, so I was willing to take the L on that one interactions

prof@infosec.pub on 24 Jul 2024 19:31 collapse

Introducing a Captcha on a form on my website basically blocked bots 100% of the time. It’s arguably good enough from a practical standpoint.

If someone really wants to exploit my site, then they will find a way. You can only make it harder but never truly impossible if you don’t want to dispose of all convenience.

theangriestbird@beehaw.org on 24 Jul 2024 19:36 collapse

thank you for sharing your experience! Good to hear an anecdote to the contrary.

recursive_recursion@programming.dev on 24 Jul 2024 19:01 next collapse

Always has been

tempest@lemmy.ca on 24 Jul 2024 21:59 collapse

I mean that is true but there is some nuance.

At one time it was a cheap way to protect your site from drive by scripts and make your users help pay for that protection.

They still work in that way on say the comment section of a tiny WordPress blog because the cost to solve them isn’t worth what a random boner pill ad is worth.

The issue now (made worse recently by LLMs) is that more bots then ever are scraping any and every thing so people are putting captchas on every bit of every web app content they have. This increases the work of your users while it only slows down the bots. The hope is that the cost to solve is slightly higher than the value of the data.

recursive_recursion@programming.dev on 24 Jul 2024 22:20 collapse

that is 100% true👍

I just saw a good opportunity to use the meme here so I took it😆

reksas@sopuli.xyz on 24 Jul 2024 19:01 next collapse

there should be a plugin that autosolves these

underscores@lemmy.dbzer0.com on 24 Jul 2024 19:29 collapse
ReallyActuallyFrankenstein@lemmynsfw.com on 25 Jul 2024 11:38 next collapse

Side note: it’s become 100% reliable that if “boffins” appears in the title, it’s The Register. Damn, they love that word.

millie@beehaw.org on 25 Jul 2024 15:14 next collapse

Yeah it’s pretty clearly just getting people to manually train self-driving cars for a while now.

DAMunzy@lemmy.dbzer0.com on 25 Jul 2024 22:40 next collapse

Jokes on them. I randomly select extra or less boxes than are correct. Yes, it takes me more time but I’m doing my little part to stymy Skynet.

Truck_kun@beehaw.org on 28 Jul 2024 14:49 collapse

I did try to get literal with reCAPTCHA a while back, and it just never finished. “Select every image with a bicycle in it” or motorcycle or stop light. I would select the images that only had a WHOLE in it, not the broken up ones into several images. It doesn’t like it when you try to answer it’s question properly.

Anyways, there’s several other captcha and anti-bot services now days, really would recommend people use a different provider, I hate reCaptcha so much.