this post was submitted on 24 Aug 2024
222 points (100.0% liked)

Asklemmy

1454 readers
58 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy πŸ”

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~

founded 5 years ago
MODERATORS
 

The simplicity of it is logic defying. It used to be that you had to find crosswalks or move puzzle pieces or type blurred letters and numbers, but NOW all the sudden I can just click a box and HEY!, I'm human?

That's hardly the Turing Test I'd expected.

top 31 comments
sorted by: hot top controversial new old
[–] isolatedscotch@discuss.tchncs.de 35 points 2 months ago (1 children)

https://blog.cloudflare.com/turnstile-private-captcha-alternative/

TL:DR cloudflare made a new recaptcha which does some complex math and other stuff on your browser, which done once has no noticable effect but if someone were to scrape websites at an absurd speed it slows everything down significantly.

this is not only cool because you don't have to manually solve the captcha, but also because it allows for low-speed scraping to be feasible, with tools like flaresolverr

[–] zagaberoo 4 points 2 months ago

Oh, so it's Hashcash; cool to see that idea getting real use.

[–] communism@lemmy.ml 26 points 2 months ago (3 children)

I always fail Cloudflare captchas because I'm clicking it with Vimium-C lol. I hate captchas for making me reach for my mouse. It also seems like a genuine accessibility issue if people who cannot use a mouse can't pass a captcha.

I've found that Google's reCAPTCHA has also started rejecting me no matter what I do. I think it might be because my IP address is a VPN, but that's pretty stupid; if I can pass the test by clicking the squares why not let me in?

[–] Lemonculus@fedia.io 3 points 2 months ago

I've found that when Google decides to throw me a captcha, literally no amount of solving them will ever persuade them to let me in. I went through 10 in a row before I gave up.

Just seems like spite to me.

[–] Karyoplasma@discuss.tchncs.de 2 points 2 months ago* (last edited 2 months ago)

reCAPTCHA is a failed project. It was initially designed to lock out bots while being trivial for a human to solve but, over the years, captchas became more unintuitive and bots more sophisticated. Bots are now way better at solving captchas than humans and it's just a useless time sink.

[–] dutchkimble@lemy.lol 1 points 2 months ago

It’s those edges

[–] trustnoone@lemmy.sdf.org 25 points 2 months ago

Theres a few answrs to this

  1. It uses your movements before this to determine whether it feels like your a bot or not
  2. It makes you wait, the biggest issue with bots is they may try to log in say 50 different passwords for example, so if it takes 5 seconds to do each one it makes boting multiple acounts not worth it.
  3. Google uses catchphas with images to choose. They use this to train their own AI or data to sell
[–] wuphysics87@lemmy.ml 18 points 2 months ago (1 children)

Humans have mouse movement that, on August 8, 2024, are very hard to reproduce. But just like regular captchas we are just teaching computers to do the same thing.

[–] GiveOver@feddit.uk 9 points 2 months ago

Whoa what happened on the 9th?

[–] Mambert 15 points 2 months ago

Basically bots would automatically click on it, teleporting the cursor to the very center of the button. They will do this within exact milliseconds of the page loading.

Humans read something on the site, then find the banner, and move the cursor over to it, confirm that the cursor is somewhere on the button, and then click it.

It's not just the button, it's the before the button that determines you're a bot or not.

[–] FiskFisk33@startrek.website 15 points 2 months ago (1 children)

it also sees your mouse movements on your way to that box.

[–] SuspiciousCatThing@pawb.social 2 points 2 months ago (1 children)
[–] Hadriscus@lemm.ee 13 points 2 months ago (1 children)

Then it smells you from the microphone on your phone

[–] phorq@lemmy.ml 2 points 2 months ago

Damn, I thought I was being stealthy by farting silently like an assassin...

[–] Cephalotrocity@biglemmowski.win 14 points 2 months ago

I don't know for certain, but I think it is simply looking at what you do with your mouse. If the movement is erratic, imprecise, and delayed it goes 'yeah, that is either a cat that got lucky which is close enough or a human'. The reason I think this is that I've failed same site's checks if my mouse just happens to be hovering over the checkbox when the prompt appears. Retry, move the mouse, success.

[–] tilefan@lemm.ee 12 points 2 months ago (1 children)

I've been told that it's analyzing your behavior from right before you click the button

[–] xilliah 3 points 2 months ago
[–] Magnetic_dud@discuss.tchncs.de 11 points 2 months ago (2 children)

Cloudflare knows almost everything done from your IP address because they're used by the majority of websites. And some websites are using a cloudflare signed TLS certificate so if cloudflare wants, can see the content of the communication instead of an encrypted package

So they know if you have a human behavior (visiting many different websites at human speed and having rests during sleeping time) or if you have a bot behavior (sending millions of requests to the same endpoint at superhuman speeds)

[–] tranarchist@lemmy.ml 2 points 2 months ago
[–] kahdbrixk@feddit.org 2 points 2 months ago (1 children)

I'd argue that the certificate authority does not have the ability to decrypt your communication because of the nature of private and public key mechanism during the whole TLS certificate procedure. You do not send your web servers private key to cloudflare when requesting a certificate.

That would actually be pretty wild...

Other then that you're probably right.

[–] Magnetic_dud@discuss.tchncs.de 1 points 2 months ago (1 children)

There's a default setting that allows unencrypted communication between the server and cloudflare. So they receive unencrypted data, sign with their certificate. Or send with self signed certificate, they decrypt and reencrypt. Or for some reason can download and import on the server their own internal use certificate.

[–] kahdbrixk@feddit.org 1 points 2 months ago

You're right, forgot that you can just not encrypt on your servers end and use cloudflare to do that for you, especially when used as CDN

[–] davel@lemmy.ml 7 points 2 months ago* (last edited 2 months ago) (1 children)

01100011 01101100 01101111 01110101 01100100 01100110 01101100 01100001 01110010 01100101 00100000 01110000 01110101 01110100 01110011 00100000 01101101 01100101 00100000 01101001 01101110 00100000 01100001 01101110 00100000 01101001 01101110 01100110 01101001 01101110 01101001 01110100 01100101 00100000 01101100 01101111 01101111 01110000 00100000 01110011 01101111 01101101 01100101 01110100 01101001 01101101 01100101 01110011

Pretty much every time for me. I just close the page when this thing happens. It's not worth the headache.

[–] Lemjukes@lemm.ee 5 points 2 months ago

A side to this is that certain techniques will be deliberately obfuscated or simply omitted as a security measure in the hopes of slowing a bad actor’s eventual bypassing of the measure. It’s an arms race and if the intruder doesn’t know what all the locks even are, it takes longer to break or pick them.

[–] Empricorn@feddit.nl 4 points 2 months ago* (last edited 2 months ago) (1 children)

It's actually detecting you using emotion and aging. That's the real test...

[–] Melatonin@lemmy.dbzer0.com 2 points 2 months ago

Listening to me talk about that birding hat I want to buy, checking thru Amazon to see if it's on my wishlist.

[–] brian@programming.dev 3 points 2 months ago

some of them are also less bot detection and more spam limiting and mitigation. cloudflare's has more stuff built in I'm sure, but things like mCapcha are just proof of work, so if you're trying to make a bunch of accounts or whatever, it's really computationally expensive.

[–] interdimensionalmeme@lemmy.ml 2 points 2 months ago (1 children)

This all humans will be good for in the future, until they atrophy and become a mere appendage of machinegod.

[–] Melatonin@lemmy.dbzer0.com 1 points 2 months ago (1 children)

I saw the movie. Unhappy ending.

[–] interdimensionalmeme@lemmy.ml 2 points 2 months ago

Which movie is that ? While waiting your reply I asked chatgpt

Please write movie script where humans continue to evolve in an environment where their reproduction and evolution is mediated entirely by the solvibg of captchas. They have become one with machinegod, just a vestigial appendage so scratch an itch that the machine cannot satisfy any other way.

https://chatgpt.com/share/fae8c7fc-df78-462e-9922-9d976a182bd8