Bruce Schneier

 
 

Schneier on Security

A blog covering security and security technology.

« Securing iPads for Exams | Main | Friday Squid Blogging: Squid's Beard »

February 10, 2012

Captchas

Funny.

Posted on February 10, 2012 at 2:08 PM11 Comments

To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter.

Comments

kaellinn18February 10, 2012 2:35 PM

For full effect, read the article in GlaDOS' voice.


Natanael LFebruary 10, 2012 2:54 PM

@kaellinn18: Why not the space core's voice?


Ben RosengartFebruary 10, 2012 3:26 PM

XKCD did it better, IMHO:

http://xkcd.com/632/


ChristianOFebruary 10, 2012 3:36 PM

When you start with xkcd.. there are at least two more captcah comics there..
http://xkcd.com/233/
and
http://xkcd.com/810/


best captcha to date is imho:
http://random.irb.hr/signup.php

I am wondering if it wouldn't be perfect to any forum for computer science courses. I am just afraid to many students would fail.


Carl 'SAI' MitchellFebruary 10, 2012 3:56 PM

Or HAL 9000's voice, depending on your preference.

The whole thing is rather accurate. Especially the security questions that everyone knows the answers to.


GodelFebruary 10, 2012 6:41 PM

Or how about the captcha for this charity web site.

http://www.woordendaad.nl/gratis-doneren

You get the impression that they're not really trying.


Dan LinderFebruary 10, 2012 9:19 PM

Suprise someone didn't mention the waving flag captcha shown here:
http://www.stagemanagers.org/index.php?...

I think it's easier to read, but no frame has all the characters visible at once so AI has a harder time.

(Next up on AI challenges, add persistence of vision feature...)


HiTechHiTouchFebruary 10, 2012 10:11 PM

I though the classic XKCD was xkcd.com/565/ -- real Internet police!


SnagoFebruary 11, 2012 7:36 AM

The best captcha comic of them all:
http://myapokalips.com/show/23


mjkFebruary 12, 2012 3:53 PM

I once had a spam-bot problem on a site I ran, and as an interim measure, I added a static "captcha" that simply said "Foo" in plain, easy-to-read letters.

It worked for quite a while.


JonadabFebruary 14, 2012 7:47 AM

> I once had a spam-bot problem on a
> site I ran, and as an interim measure,
> I added a static "captcha" that simply
> said "Foo" in plain, easy-to-read letters.

That (or even using the text of the page to tell the user what to type) is good enough to defeat a lot of the simple generic bots that crawl the web posting spam on a lot of different sites, because they're designed to pick off the low-hanging fruit, and there are a lot of sites out there with, for whatever reason, no CAPTCHA at all. Even attempting to post the message on moderated blogs, like on Blogger, gets a decent ROI for these bots, because it's dead easy and usually gets *one* person (the blog owner) to see the message.

However, if you run a site that's going to get targeted specifically (like any really popular forum or wiki or webmail service) then you're going to have to deal with bots that can do at least basic OCR and maybe more.


Post a comment




E-mail is optional and will not be displayed on the site.


Remember Me?


Allowed HTML: <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre>

Powered by Movable Type. Photo at top by Geoffrey Stone.

Schneier.com is a personal website. Opinions expressed are not necessarily those of BT.

 
Bruce Schneier