- cross-posted to:
- technology@lemmy.zip
- technology@lemmy.world
- cross-posted to:
- technology@lemmy.zip
- technology@lemmy.world
Anyone who has been surfing the web for a while is probably used to clicking through a CAPTCHA grid of street images, identifying everyday objects to prove that they’re a human and not an automated bot. Now, though, new research claims that locally run bots using specially trained image-recognition models can match human-level performance in this style of CAPTCHA, achieving a 100 percent success rate despite being decidedly not human.
ETH Zurich PhD student Andreas Plesner and his colleagues’ new research, available as a pre-print paper, focuses on Google’s ReCAPTCHA v2, which challenges users to identify which street images in a grid contain items like bicycles, crosswalks, mountains, stairs, or traffic lights. Google began phasing that system out years ago in favor of an “invisible” reCAPTCHA v3 that analyzes user interactions rather than offering an explicit challenge.
Despite this, the older reCAPTCHA v2 is still used by millions of websites. And even sites that use the updated reCAPTCHA v3 will sometimes use reCAPTCHA v2 as a fallback when the updated system gives a user a low “human” confidence rating.
Aren’t these Captchas designed to get training data for AI models anyway?
“System does what it was designed to do” doesn’t feel that surprising…
Aren’t these Captchas designed to get training data for AI models anyway?
Yes and no, the captchas are just meant to be hard for computers to solve but easier for humans. People saw that, and thought that “if we’re making people do this might as well have them do something useful” not meant to be malevolent- and the purpose is still stopping bots, training them is a side-effect.
No, you’re wrong, the Traffic Light examples ARE specifically to gather data to train models. Being a good Captcha was just a byproduct of that. If people just wanted a good captcha they wouldn’t need hundreds of millions of photos of street lights and bicycles.
No, you’re wrong, the Traffic Light examples ARE specifically to gather data to train models.
No you’re wrong, because the sites that embed those captchas on their page are not doing that to help good.
If people just wanted a good captcha they wouldn’t need hundreds of millions of photos of street lights and bicycles.
Yes, they are getting something productive out of the human labor that would be done anyways. Trust me as a web developer, and web scraper, some kind of captcha is necessary for many free services to be useful/economically viable. The core of a good captcha is just making it marginally more expensive for the scraper/bot than it is for you.
The sites don’t create the captcha, you yourself just said it was embedded there.
They embed for a reason… And the captchas wouldn’t exist if they weren’t embedded anywhere
Finitebanjo is right. Yes they are used to fight spam and bots but they way they do it us is picked intentionally to train ai.
https://medium.com/@yennhi95zz/how-google-trains-ai-with-your-help-through-captcha-876cb4eb4d01
Also from the Wikipedia article “Google profits from reCAPTCHA users as free workers to improve its AI research.” https://en.m.wikipedia.org/wiki/ReCAPTCHA
they do it us is picked intentionally to train ai.
Yes like I said, the challenges were picked to be useful. But some form of challenge would’ve been chosen regardless.
I fucking hate these. I’ve seen old people that don’t know any better get stuck on these for at least 30 minutes.
it’s super ableist. if someone has poor vision or colorblindness chances are they’re going to miss things.
I have regular everything and I still fuck them up. “click the ones with a fire hydrant”. But a tiny piece of fire hydrant is spilling into another box. Does it count? Does it not count? Good luck!!
I had one the other day that was deep fried jpegs to the max. Like, what the fuck am I supposed to do.
Sprinkle powdered sugar on them. Delicious deep fried jpegs.
Spillovers into other boxes definitely count…
I don’t want to do this next part but I can’t resist…
Just ask my girlfriend…
Ba dum tiss
FYI as someone that’s colorblind these captcha’s don’t seem to have anything specially relevant to being colorblind in them.
Now if they start showing me a dozen traffic cones and asking me to pick the green one, we might have a problem.
They offer a sound option right below.
a hard to see option, aptly enough
Same. That’s why Buster is my most recent must-have browser extension, alongside such greats as ublock and sponsorblock.
And yet I can’t beat the CAPTCHAs because reCAPTCHA doesn’t like VPNs lol
Captcha these days isn’t even really a CAPTCHA in the traditional sense since most of the work it does is based on filtering of IP and browser fingerprinting, with a certain level of gamification because the goal is not just to keep out the people they fight against, but to waste their time, would work great if it didn’t waste normal people’s time, while real bad actors have easy ways to get around it.
I was going to say I’ve straight up just left whatever website I was trying to access because I was stuck in some endless loop of clicking on street crossings, buses, bikes, and street lights.
The capchas getting really bad on Mullvad almost made me give up on using a VPN. But then I learned about Buster.
This is my third post in a row shilling for this browser extension lol, it’s so good.
Fellow vpn user here, it’s been really bad lately. I’m definitely installing this.
CAPTCHA doesn’t stop bots, and let us be honest, it never really did. It frustrated the hell out of people though, and caused people to waste time doing these challenges. Meanwhile even before AI bad actors and bots could get past it simply by using captcha solver services run by exploited humans solving captchas for the service.
It’s a display of security theater meant to make normies feel safe but in reality doesn’t stop most bad actors.
Meanwhile I sometimes fail those. I have been locked out of applications because I missed a square of a bus, or perhaps because I like to be efficient in my mouse cursor movements. I ducking hate CAPTCHAs.
the new ones suck so fucking much though
If I see the newer ones pop up at all I just skip what ever the task is that was requiring me to bother with it.
i love when websites (twitter is a really bad example) hit me with like 8 captchas, and then if i get my username/password wrong i have to do another 8. It’s just so obviously gaming for training data on shit lmao.
What is it actually training? Google owns captcha right?
i have no clue, but i would assume it’s native to twitter if they’re pushing it that hard, either that or someone is paying a lot of money for that captcha access lol.
Buster is awesome to get past recaptcha. I use it with my own Speech to Text API key since its free from Google. Using Google to beat Google.
It’s so funny that this exists. I’m going to check it out!!
If you’re using a personal api from google, is that a way that google can track you? Part of using a VPN, noscript and adblock for me is to prevent that kind of tracking.
Nothing is truly free with Google. So ya, most likely they are tracking. If you dont want to use Google, there are other options on their wiki
https://github.com/dessant/buster/wiki
If not, you can use a dummy account just for this.
I can see a future where the Internet is completely run by bots and AI to the point where no human actually uses the Internet anymore.
It’s like an island that gets overrun with rats - there are just too many to deal with so you leave.
Some believe this happened years ago. Check out Dead Internet Theory.
I’m already doing that now. If Lemmy starts showing signs of fuckery I’m out. I’ll switch back to magazines.
I already did… There’s some subscription stuff where you can read pretty much all available magazines and papers, it’s been a long time since I’ve been reading that much “news” and reports
I work in a place with no phones. I bring books and magazines into the shitter.
Basically Cyberpunk, people only interact with the night city intranet because the global internet has been taken over by AIs.
Yeah, I predict that in the future, you can’t expect that content on the internet is written by humans. If you go to the internet, then it will probably not be to connect to other humans. Maybe you want to know something that a bot can tell you or you have some administrative task to fulfill, like filing a form.
I fail more of those checks then these AI bots do. Surreal.
It seems like every other captcha I get has a picture of a moped and asks to click for a motorcycle. When I don’t click on the moped it says I’m wrong. Pisses me off.
than* these AI bots
Just be very general, don’t get stuck in the details.
It goes against my human nature to not overanalyze.
leaves plastic banana under your bed
You’ll find that, months from now, and you won’t know where it came from, or why it’s there.
Bots are answering them wrong. Google takes the most submitted answer as truth.
Greetings fellow human!
01001000 01101111 01110111 00100000 01100100 01101111 00100000 01111001 01101111 01110101 00100000 01100100 01101111 00111111
Technically the “correct” answer is set by the highest percentage of people choosing it. EG: 19 people select Box A and 1 selects Box B, then the machine decides Box A is in fact correct.
That means these AI could be selecting the wrong answers for all anybody knows, if enough of them are answering the prompts, and still passing.
Cool, so can Google shut it down now?
I just close the page usually if I see one of these ones, I don’t have the patience to click all the boxes and then it just sends you a different one.
Unfortunately they’re on pages that I absolutely need to get into because my money is stored behind them. I cannot stand them, and I generally agree with you, if some random site has me doing a captcha in leaving.
So…if CAPTCHA are already beaten by bots what’s the point if it still exists ? to mock our weakness ?
In the old days CAPTCHA could do its job, but nowadays nah…even crawler/scrapper/meta bots can bypass it easily.
The real question is why do we as real humans still often fail to beat CHAPTCHA? Are we less human? Are we really robots in CHAPTCHA perspective ?To train Google/Cloudflare’s AI tools, and to double check against DDOS. That’s it.
So now we’re going to have AI training other AIs
Wait, there’s a movie about this …
Just because it’s possible, doesn’t mean it’s common.
That’s suspicious - I can’t pass 100%. here’s a new captcha for you: make the user do 100 in a row
- 100% is ai
- <50% is dumb “ai”
- in between is a person
There is a Russian captcha solver bot called xevil that costs under $100 (I think, last time I looked) that has been able to solve nearly all captchas for years. You just have to supply it with relatively expensive proxy IP addresses because Google rate limits solve attempts.
So the title of this article has been true for a long long time. Capatchas are absolutely useless except against poor or uninformed script kiddies.