Dev Shed Lounge
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOtherDev Shed Lounge

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stay one step ahead of the competition. Evaluate and give feedback on some of the hottest web development tools on the market today. Make your opinion heard! Click Here
  #1  
Old April 15th, 2008, 04:20 PM
f'lar's Avatar
f'lar f'lar is offline
Senior WeyrLeader
Dev Shed Expert (3500 - 3999 posts)
 
Join Date: Aug 2003
Location: WI
Posts: 3,767 f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level)f'lar User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 3 Days 17 h 12 m 26 sec
Reputation Power: 675
Send a message via Google Talk to f'lar
Captchas

I just saw an article saying that the captcha for hotmail (excuse me: windows live mail ) has been defeated. This follows on the heels of defeats for Google and Yahoo as well.

The story makes the point that a single zombie machine can now create about 1440 accounts per day, with a success rate of 10-15%. What in the world!?!

First of all, that number seems inflated. How many zombie computers run 24/7, or can devote their full processing power to a task without alerting the user to the presence of zombie software?

Secondly, you'd think they could keep a look-up table of IP address separating residential (fewer than 5 machines) from corporate (many more) and limit the residential machines to say 5 new accounts per day. For the corporate IPs, limit the number of failed attempts to a reasonable amount (say, 1000) before cutting off that IP as well. That would stop the vast majority of bad accounts, enough that it might not be profitable to the spammer any more.

I haven't heard of anyone doing that, and it seems an obvious enough solution that I'm wondering where the flaw in my process is?
__________________
Primary Forums: .Net Development, MS-SQL, C Programming
VB.Net: It's not your father's Visual Basic.

[Moving to ASP.Net] | [.Net Dos and Don't for VB6 Programmers]

Last edited by f'lar : April 15th, 2008 at 04:27 PM.

Reply With Quote
  #2  
Old April 15th, 2008, 04:36 PM
Kravvitz's Avatar
Kravvitz Kravvitz is offline
CSS & JS/DOM Adept
Click here for more information.
 
Join Date: Jul 2004
Location: USA
Posts: 15,773 Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level)Kravvitz User rank is General 7th Grade (Above 100000 Reputation Level) 
Time spent in forums: 3 Months 3 Weeks 3 Days 3 h 20 m 15 sec
Reputation Power: 1474
I had a feeling this was inevitable. Computers just keep gettin' smarter, which is both a good and a bad thing.

IP address blocking is obsolete. So many people are using NAT/PAT that you can't tell how many users there might be on the private network behind the router(s) using it.
__________________
Spreading knowledge, one newbie at a time.

Learn CSS. | PHP includes | X/HTML Validator | CSS validator | Dynamic Site Solutions

IE7: the generation 7 browser new in a world of generation 8 browsers.
Design/program for Firefox (and/or Opera), apply fixes for IE, not the other way around.

Reply With Quote
  #3  
Old April 15th, 2008, 04:58 PM
misterdanny's Avatar
misterdanny misterdanny is offline
Null Pointer Exception
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Mar 2006
Location: america
Posts: 2,086 misterdanny User rank is Captain (20000 - 30000 Reputation Level)misterdanny User rank is Captain (20000 - 30000 Reputation Level)misterdanny User rank is Captain (20000 - 30000 Reputation Level)misterdanny User rank is Captain (20000 - 30000 Reputation Level)misterdanny User rank is Captain (20000 - 30000 Reputation Level)misterdanny User rank is Captain (20000 - 30000 Reputation Level)misterdanny User rank is Captain (20000 - 30000 Reputation Level)misterdanny User rank is Captain (20000 - 30000 Reputation Level)misterdanny User rank is Captain (20000 - 30000 Reputation Level) 
Time spent in forums: 2 Weeks 2 Days 1 h 47 m 43 sec
Reputation Power: 217
yeh I didn't think the graphic captchas were very good, its only seemed to have been a matter of time that someone spends enough time to write a program to "crack" it. (and it was)

Now I just wonder, what the next step is to stop bots? There are a lot of captchas I can't even read, and now that bots can read them. What comes next?

I think they really need to find a way to make spam truly ineffective and not worth the time. Rather than trying to stop the spammers, there needs to be a way to make it a costly endeavor on the spammers part, and to weaken the benefits of people who can afford to do this. So in this way they will eventually have to call it quits when they run out of funding.

Of course how can this be done? who knows!

Reply With Quote
  #4  
Old April 15th, 2008, 05:13 PM
sizablegrin's Avatar
sizablegrin sizablegrin is online now
Stubborn ol' L'User
Click here for more information.
 
Join Date: Jun 2005
Posts: 3,036 sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 23 h 49 m 33 sec
Reputation Power: 1440
Computers haven't gotten smarter. Programmers have gotten smarter and computers have gotten fast enough to execute their long-drawn-out plans for exploits.

I have never thought that captchas were particularly worth a ****. Mabye that's because I began in OCR back in the mid-80s.

The proponents of captcha believe in distorting an image to the extent that it is barely recognizable by a human, knowing that human brains have analysis abilities that are superior to those of machines (only because no one understands those abilities enough to replicate the process with a machine).

The secret to a good captcha is not to distort it, but to place it with other intruding elements, and background noise. These techniques will defeat the OCR of today. Check back tomorrow for the next step, as the opponents will always improve.
__________________
C/C++ pointers (Original in the "Commonly Asked Questions" thread).

Reply With Quote
  #5  
Old April 15th, 2008, 09:19 PM
disablek disablek is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2008
Posts: 38 disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 22 h 9 m 10 sec
Reputation Power: 9
i've often wondered why they didn't just reduce the kerning on the letters and mash them tightly to each other.

Reply With Quote
  #6  
Old April 15th, 2008, 10:44 PM
sizablegrin's Avatar
sizablegrin sizablegrin is online now
Stubborn ol' L'User
Click here for more information.
 
Join Date: Jun 2005
Posts: 3,036 sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level)sizablegrin User rank is General 7th Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 23 h 49 m 33 sec
Reputation Power: 1440
Then you probably need to think about it some more. A computer ain't you, bubba, regardless of its perceived superiority.

Reply With Quote
  #7  
Old April 15th, 2008, 10:58 PM
disablek disablek is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2008
Posts: 38 disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 22 h 9 m 10 sec
Reputation Power: 9
what are you going on about now ....
Comments on this post
sizablegrin disagrees: You can't know if you can't think.
Arty Ziff agrees!

Reply With Quote
  #8  
Old April 15th, 2008, 11:26 PM
jwdonahue jwdonahue is offline
Bellevue WA, USA
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: May 2004
Location: Bellevue Washington, USA
Posts: 1,038 jwdonahue User rank is Second Lieutenant (5000 - 10000 Reputation Level)jwdonahue User rank is Second Lieutenant (5000 - 10000 Reputation Level)jwdonahue User rank is Second Lieutenant (5000 - 10000 Reputation Level)jwdonahue User rank is Second Lieutenant (5000 - 10000 Reputation Level)jwdonahue User rank is Second Lieutenant (5000 - 10000 Reputation Level)jwdonahue User rank is Second Lieutenant (5000 - 10000 Reputation Level)jwdonahue User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 6 Days 23 h 14 m 51 sec
Reputation Power: 66
Quote:
Originally Posted by msterdanny
I think they really need to find a way to make spam truly ineffective and not worth the time.


When senders carry the burden of the cost of email, rather than the receivers, it will alleviate this problem considerably.

http://homepages.tesco.net/J.deBoyn...oposals/IM2000/
__________________
It's not always a matter of what you can do with a language, but whether you should. [JwD]

Reply With Quote
  #9  
Old April 17th, 2008, 02:06 PM
Arty Ziff Arty Ziff is offline
अज्ञात कॉवर्ड
Click here for more information.
 
Join Date: Apr 2005
Posts: 3,851 Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level)Arty Ziff User rank is General 1st Grade (Above 100000 Reputation Level) 
Time spent in forums: 2 Months 2 Weeks 5 Days 11 h 13 m 46 sec
Reputation Power: 1017
Quote:
Originally Posted by jwdonahue
When senders carry the burden of the cost of email, rather than the receivers, it will alleviate this problem considerably.
When people refuse to be drawn into Nigerian scams, penis pill scams, stock scams and porn scams, spam will go away. Which is never.

The best approach is active filtering on the backbones and at the ISP level to kill spam at the gateway.

Reply With Quote
  #10  
Old April 17th, 2008, 02:14 PM
LyonHaert's Avatar
LyonHaert LyonHaert is offline
Arcane Scribbler
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Jun 2005
Location: Indianapolis, IN
Posts: 1,569 LyonHaert User rank is Major (30000 - 40000 Reputation Level)LyonHaert User rank is Major (30000 - 40000 Reputation Level)LyonHaert User rank is Major (30000 - 40000 Reputation Level)LyonHaert User rank is Major (30000 - 40000 Reputation Level)LyonHaert User rank is Major (30000 - 40000 Reputation Level)LyonHaert User rank is Major (30000 - 40000 Reputation Level)LyonHaert User rank is Major (30000 - 40000 Reputation Level)LyonHaert User rank is Major (30000 - 40000 Reputation Level)LyonHaert User rank is Major (30000 - 40000 Reputation Level)LyonHaert User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 3 h 1 m 13 sec
Reputation Power: 364
Captchas are still effective in the right places. For a blog, a simple captcha on the comments form is quite effective, and it doesn't even have to be randomly generated.

I'm not surprised at all that so much effort was spent to break the captchas of such big sites.
Comments on this post
f'lar agrees: 'Orange' anyone?
__________________
Joel B Fant - LyonHaert.net

2 + 2 is... 10... in base 4

Reply With Quote
  #11  
Old April 17th, 2008, 02:27 PM
Hammer65's Avatar
Hammer65 Hammer65 is offline
Web Developer/Musician
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Nov 2004
Location: Lincoln Nebraska
Posts: 2,036 Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level)Hammer65 User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 3 Weeks 1 Day 22 h 36 m 15 sec
Reputation Power: 577
Send a message via AIM to Hammer65
I have always told new coders to take the security measures that are appropriate for what you have to protect. That of curse includes the server and the network that the site is on.

CAPTCHA's will probably still be effective for run of the mill sites for a while yet. Grin is right, if you introduce some noise and perhaps even some animation into the process, it makes it much harder. I vary the font and the background for mine, and try to introduce as much random noise as possible in the background. The text itself can still be readable. The key is to make it hard for software to pick the text out of a complex background, not mangle the text to the point of un-readability.
Comments on this post
sizablegrin agrees!
codergeek42 agrees!
__________________
"Strange women lying in ponds distributing swords is no basis for a system of government. Supreme executive power derives from a mandate from the masses, not from some farcical aquatic ceremony! Well, but you can't expect to wield supreme executive power just 'cause some watery tart threw a sword at you! I mean, if I went 'round saying I was an emperor just because some moistened bint had lobbed a scimitar at me, they'd put me away!"

Reply With Quote
  #12  
Old April 17th, 2008, 03:00 PM
disablek disablek is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2008
Posts: 38 disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level)disablek User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 22 h 9 m 10 sec
Reputation Power: 9
So, like i said wouldn't reducing the kerning on the characters such that it's in the negative ranges plus the usual rotation, distortion, skew, noise make it more difficult for computer recognition? I don't see much of that around.

Also doesn't having different font sizes for each character make it a little easier to detect when they intersect with each other.

Reply With Quote