I was browsing dark Reading today and came across an article they published 4 days ago. A researcher has broken reCAPTCHA, that is a CAPTCHA software tool that many websites use to tell the difference between a human and a computer. It is designed to prevent automated program from creating mass accounts which, in most cases, is intended to abuse a particular service.
A researcher earlier this month demonstrated how he solved Google's reCAPTCHA program even after recent improvements made to the anti-bot and anti-spam tool by the search engine giant. Chad Houck, an independent researcher, also released the algorithms he wrote to crack reCAPTCHA. Houck had published a white paper on the hack prior to presenting his research at Defcon in Las Vegas, and says that Google made several fixes to reCAPTCHA that defeated several of his algorithms before he was scheduled to give his presentation. He then quickly came up with a few additional approaches with his algorithms, and says he was able to beat the updated reCAPTCHA 30 percent of the time. "[ReCAPTCHA] has never been wholly secure. There are always ways to crack it," says Houck, whose algorithms have been available online since Defcon. "The information [about the research] is out there. Google still hasn't changed it, which kind of surprises me." Google, however, thus far has not seen any signs of this being actively used in the wild. … ReCAPTCHA, which was originally created by Carnegie Mellon University and later purchased by Google, basically protects websites from bots and spam by generating distorted text or words that humans can read, but software or optical character readers cannot. The words used by the reCAPTCHA program come from books that are being digitized. The program, which runs on many major websites as a way to validate that the user on the site is a human and not an automated bot or spammer, presents the user with two real words to type into a box, one of which is for verification and the other for digitization purposes. … Just how difficult would it be for a bad guy to exploit this? "As long as you know how to program well enough, it would take a day to implement my algorithms," he says.
A researcher earlier this month demonstrated how he solved Google's reCAPTCHA program even after recent improvements made to the anti-bot and anti-spam tool by the search engine giant.
Chad Houck, an independent researcher, also released the algorithms he wrote to crack reCAPTCHA. Houck had published a white paper on the hack prior to presenting his research at Defcon in Las Vegas, and says that Google made several fixes to reCAPTCHA that defeated several of his algorithms before he was scheduled to give his presentation. He then quickly came up with a few additional approaches with his algorithms, and says he was able to beat the updated reCAPTCHA 30 percent of the time.
"[ReCAPTCHA] has never been wholly secure. There are always ways to crack it," says Houck, whose algorithms have been available online since Defcon. "The information [about the research] is out there. Google still hasn't changed it, which kind of surprises me." Google, however, thus far has not seen any signs of this being actively used in the wild.
…
ReCAPTCHA, which was originally created by Carnegie Mellon University and later purchased by Google, basically protects websites from bots and spam by generating distorted text or words that humans can read, but software or optical character readers cannot. The words used by the reCAPTCHA program come from books that are being digitized. The program, which runs on many major websites as a way to validate that the user on the site is a human and not an automated bot or spammer, presents the user with two real words to type into a box, one of which is for verification and the other for digitization purposes.
… Just how difficult would it be for a bad guy to exploit this? "As long as you know how to program well enough, it would take a day to implement my algorithms," he says.
I would say that this somewhat qualifies as news. On the one hand, reCAPTCHA nicely dovetails with Google’s mission to digitize all of the world’s books (that the publishers will let them). While people are busy solving these CAPTCHAs, at the same time they are putting books into digital format which assists in their redistribution. In essence, Google is killing two birds with one stone – they are preventing abuse of their systems, and at the same time capturing information in preparation for its dispersal to everyone else (or as one Objectivist put it, the only resource that requires redistribution is knowledge).
ReCAPTCHA has become very popular and a lot of sites use it because it is free and it is (was) secure. However, on the flip side, the fact that a CAPTCHA is broken doesn’t really qualify as news. We have known for years that CAPTCHAs are broken and this has been accomplished by a couple of different methods:
So, I take issue that this is news in the sense that it is “new”, or that we haven’t seen this before. What makes this newsworthy is that a service that was supposed to serve the dual purpose of implementing security + saving the world might not be able to serve a dual role after all.
Bruno Targhetta es un hijo de ***
brunotarghetta.blogspot.com
that would be me
http://www.anti-recaptcha.com
omg thank you this really works
works with the new google captchas well done