Re: Better captcha for WOT

Bert Massop <[email protected]>
Newsgroups gmane.network.freenet.devel
Message-ID <[email protected]>
On 20-07-16 17:05, dyners-ruvOiOuSH0dWk0Htik3J/[email protected] wrote:
> Google research declares the simple text captcha dead. They remain
> difficult for human beings, but machine learning can crack them 99.9% of
> the time.

While probably true, no captcha abuse on WoT has been documented so far.

> I propose a better captcha for WOT that works like:

Thank you for considering how WoT can be improved. Your proposal is not
immediately clear to me; I'll fire some questions and state some of my
doubts to get a better understanding.

> - The challenge to be solved: Add the numbers presented in the puzzle
> series that ONLY show trees.

I don't see what benefit having to add numbers brings over recognizing
characters. Digits are easier to recognize for computers (for there are
only 10 of them, compared to our 26 character alphabet), and addition is
a trivial task for computers as well.

> - It presents 5-10 puzzles. The legit puzzles randomly sprinkled throughout.

What do you mean by randomly sprinkled legit puzzles? All puzzles in WoT
are supposed to be legit. What purpose would a non-legit puzzle have? Or
do you envision a series of multiple "puzzles" within a single
captcha-like image?

> - What puzzles look like: A number is drawn across an image backdrop of
> trees and other objects.
> 
> 
> That should raise the bar and not be hard to switch to.

In my humble opinion, this statement is far from the truth.

Consider a finite set of "tree" and "non-tree" images that is to be
shipped with WoT. This reduces your proposal to a captcha with an
alphabet extended to the cardinality of the set of images, however
operating on image similarity (and known classification information on
whether the image is a tree or not) instead of character similarity.

The strength of captcha alternatives that are based on identification of
image contents, relies on the assumption that the image set (in other
words, the classification data) is kept private. This cannot be done for
WoT (the attacker could always download the source after all!), unless
each user would have to supply their own source of captcha images —
which would make setup unnecessarily hard.

Kind regards,
Bert

_______________________________________________
Devl mailing list
[email protected]
https://emu.freenetproject.org/cgi-bin/mailman/listinfo/devl
signature.asc (application/pgp-signature, 490 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.20 (GNU/Linux)

iQEcBAEBCgAGBQJXj5+4AAoJEDmbbkE9DzHhZmkH/1U/g0BKzxBCdMcorw1je1KQ
sgnQ1VOWZUd4Nct0ffI8uv3N0ohL39SJlRdOaah/B0jSamMhNWyHBEUN717lu6vc
uAaCf8i8MNaMG5beZ/TlvBzie//pCc3ub8uJZMw2OkBBYpgj0qPkwnjrJ5Kp8I1o
8K+HHevjqnps7Eow2MWsXzleYpapw7KAgJzVz+easzW9n919qKfgRDBc/Xjr5aDj
8Nb69fxEFMXyhmOB3DU+ge28IgA8cTUOamSz4veG68OYw65pUVohgZwfSBeURSdX
rN5JQuMYs9520bui/y5uUUai72oMcx5fulF+JLnB+Pu8py548g1Gg5cyVvgBehU=
=zfGk
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.