CAPTCHA, HACKEDCHA, GOTCHA
By Davey Winder in Editorial
Posted in Uncategorized on
The Completely Automated Public Turing test to tell Computers and Humans Apart security system, thankfully better known by the pseudo-acronym of CAPTCHA, has been well and truly cracked according to reports online. The system uses a set of alpha-numeric characters presented against a background which when combined make it all but impossible for a machine to decipher but easy enough for the human brain to be able to deal with. Or at least that was up until now if these reports are to be believed.
A Russian security ‘researcher’ going by the pseudonym of John Wane has claimed success in bypassing one of the toughest of CAPTCHA implementations, the one to be found at Yahoo! Wane has posted decoder system code online which is said to be accurate to around 35 percent. Now that might not sound significant, but when you are trying to keep the spammer bots at bay I can assure you that it is. As Wane himself says “It’s not necessary to achieve a high degree of accuracy when designing automated recognition software” especially when a spammer can easily hit a rate in excess of 100,000 attempts per day. If they were to manage anything like 30,000 successful account creations then the spam problem, for blogs, forums and the general email population, would rocket overnight.
Application vulnerability software specialists Fortify has warned us all to be vigilant, especially as far as message received from webmail systems are concerned in the light of this possible breach. Fortify Chief Scientist Brian Chess has gone on record to say that “any free email service that is using the CAPTCHA system - or a similar approach to prevent automated sign-ups - is engaged in a never-ending arms race with its attackers.”
It isn’t all bad news though, as CAPTCHA represents just the main gate as it were in the fight against spammers, and the likes of Yahoo! and Google have plenty of other tricks up their collective spam fighting sleeves to prevent an all out flood of malicious mail.
Comment by - January 26, 2008 on 4:21 am
I like the kitten captcha-equivalent that Microsoft came up with; not only is image analysis software harder to write than letter scrapers, but every use donates to animal shelters. In the long run, we have to have a robust identity and reputation system - and maybe an exam to prove you’re not stupid enough to buy from spammers before you get to use a service…
Comment by - January 27, 2008 on 2:08 pm
Yep, I was rather enamoured by the MS kittens thing myself. But as you say, ultimately we do have to address the problem of end users having a trailer trash mentality when it comes to spam and link clicking.
Comment by - April 2, 2008 on 5:58 pm
Captcha isn’t accessible and the MS kittens thing can only be worse. I find Akismet works pretty well for stopping comment spam. There must be a similar way that would limit the number of signups from a particular IP address.
And yes I know that just about everything can be forged and dynamic IP addresses complicate things.
Pingback by - February 18, 2009 on 12:12 am
[…] Public Turing test to tell Computers and Humans Apart (better known as CAPTCHA) is not foolproof. Yahoo! knows this, Google knows this, and now it would look like Microsoft knows it as […]
Comment by - October 28, 2009 on 5:41 am
Thanks for sharing such a nice information regarding captcha and Gotcha. I am wondering if I can share your article in the bookmarks of society.
Trackback by - June 11, 2011 on 2:52 pm
wordpress tema…
Wow, marvelous blog layout! How long have you been blogging for? you made blogging look easy. The overall look of your site is great, as well as the content!…
Trackback by - June 18, 2011 on 12:35 am
Hi…
Great site you got here. Good job with the entry as well. I found this related post that you may want to visit….
Trackback by - June 19, 2011 on 5:55 pm
facebook…
I like this specific post,I guess that that they having fun to learn this publish,they should take a very good site to create a information,many thanks for sharing this to me….
Trackback by - June 23, 2011 on 11:42 pm
ozoderm…
Thanks for taking the time to debate this, I feel strongly about it and love studying extra on this topic. If possible, as you acquire expertise, would you mind updating your blog with further information? It is extremely useful for me….
Trackback by - July 8, 2011 on 2:35 pm
Useful Links…
I saw this really great Website today, I would like to share it with you all….
Trackback by - July 28, 2011 on 3:04 pm
Recent Blogroll Additions……
[…]usually posts some very interesting stuff like this. If you’re new to this site[…]……
Trackback by - September 17, 2011 on 1:25 pm
……
Hi there. Very cool website!! Man .. Excellent .. Superb .. I will bookmark your blog and take the feeds also…I am happy to find numerous helpful information right here in the article. Thanks for sharing…..
Trackback by - February 9, 2012 on 5:35 am
will smith divorce jada…
[…]making it 13 victories from 13 races – explained of her decision[…]…
Trackback by - February 9, 2012 on 8:46 am
will smith twitter account…
[…]have a single of each and every pair” or even “I really feel not at the moment becoming my mouth place guard, I am particular that our canine […]…
Make a comment
Tag cloud
Archives
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
Most commented posts
- 80 percent of viruses love Windows 7
165 comments
- Has Microsoft gone mental?
- Has the US Army declared war on Windows 7?
- Cuil frozen out: market share drops to next to nothing
- Xbox 360 FAIL
- The 24GB RAM Desktop is born
- Use old version of Windows instead of Linux, says teacher
- Microsoft reveals time-based licensing model
- How Marblecake Hacked Time
- Nexus Two - The Next Generation
Highest Rated Blog Posts
- Why ecommerce fails (100%)
- Google Chrome stands alone at PWN2OWN (100%)
- Betting on Hubdub technology (100%)
- Has Google gone insane as GMail goes back to beta? (100%)
- Chinese whispers as government implicated in UK hack attacks (100%)
- Crimeware toolkit targets 10,000 trusted sites (100%)
- Black Hat risk to migrating VMs (100%)
- Tough on cyber crime, tough on the causes of cyber crime (100%)
- Firefox 3, Beta 4, Enhancements 900, Tested 5 (100%)
- Has the US Army declared war on Windows 7? (100%)

