Research shows hCaptcha is useless(researchgate.net)
researchgate.net
Research shows hCaptcha is useless
https://www.researchgate.net/publication/350358315_A_Low-Cost_Attack_against_the_hCaptcha_System
3 comments
Our system is indeed designed not to leak detections in real-time. By contrast, with reCAPTCHA you can simply sign up and get a bot score, which makes it trivial to break.
This limits options for the free version they tested, as by design it will not completely prevent all detected automation from passing.
Instead, one of the tools it relies on is frequently changing the classes and types of challenges. However, it also has “anti-drain” protections to avoid leaking these.
Thus, our response to them after looking through the paper was that in fact the anti-drain protections were working as designed, based on the other details reported.
disclosure: work there.
This limits options for the free version they tested, as by design it will not completely prevent all detected automation from passing.
Instead, one of the tools it relies on is frequently changing the classes and types of challenges. However, it also has “anti-drain” protections to avoid leaking these.
Thus, our response to them after looking through the paper was that in fact the anti-drain protections were working as designed, based on the other details reported.
disclosure: work there.
> This limits options for the free version they tested, as by design it will not completely prevent all detected automation from passing.
"Not completely prevent all" seems to mean "prevent about 5%", which is cold comfort for users who expected better. If they had paid for the service, would they have gotten better results (i.e. fewer successful bot sign-ups)?
"Not completely prevent all" seems to mean "prevent about 5%", which is cold comfort for users who expected better. If they had paid for the service, would they have gotten better results (i.e. fewer successful bot sign-ups)?
"We design and develop a low-cost, end-to-end system to break hCaptcha service.
• We evaluate our system against 270 live hCaptcha challenges and achieve the success rate of attack over 95% with the system taking less than 19 seconds to crack a challenge on average.
• We provide a preliminary security analysis of the hCaptcha system. Our analysis shows that the hCaptcha service employs minimal to no mechanism to resist automated abuses other than asking users to solve a simple image recognition task."
The most amusing part, though, is the gaslighting by the hCAPTCHA team and the denial they live in lol
"We reported our attack and countermeasures to the hCaptcha security team to help them make the system more robust to automated attacks. They responded that their system would have been pretty confident that our traffic was automated based on the techniques we used, and we would never have observed additional countermeasures. However, we did not notice any measures preventing our bot from passing the image CAPTCHA tests during our experiment. "
The most amusing part, though, is the gaslighting by the hCAPTCHA team and the denial they live in lol
"We reported our attack and countermeasures to the hCaptcha security team to help them make the system more robust to automated attacks. They responded that their system would have been pretty confident that our traffic was automated based on the techniques we used, and we would never have observed additional countermeasures. However, we did not notice any measures preventing our bot from passing the image CAPTCHA tests during our experiment. "
From the guidelines https://news.ycombinator.com/newsguidelines.html
> Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize.