Apologies if this feels promotional - if you have any questions, I'd be happy to answer them. This is an area of web sec that we're, obviously, very dedicated to.
Hey all, this is a blog post that aims to simplify the findings from Egor Homakov in early December (http://homakov.blogspot.in/2014/12/the-no-captcha-problem.ht...). We've included a video (http://youtu.be/718EOIoWKAE) of a major exploit in action and chat about the implications of Mr. Homakov's findings. Hope you enjoy reading it as much as I enjoyed writing it. Any questions, fire away!
Oh wow, I had no idea this happened! And it's actually true? This isn't the typical "we've cured this" then "loljk here's why we haven't cured this" news piece?
That was my assumption. It appears Detroit could potentially be reliant on a wealthy entrepreneur to take a "leap of faith" or have a third party offer some sort of financial incentive to encourage businesses back. I'm not too well versed on US law but is the federal government able to help in this vein?
As I live in Australia, to see a city like this in such a state is saddening. Of course, everyone has heard stories of Detroit's issues but to see them so starkly pictured is pretty confronting. What's the current economic state of Detroit? Is it still in decline or is there reason to be optimistic?
Interesting perspective on the changes! Our lead designer actually had similar concerns (can read them here: https://www.funcaptcha.co/2014/12/04/killing-the-captcha-wit...). You both look to be drawing the same conclusions. What are your thoughts on the metaphorical 'black box' being implemented into the new reCAPTCHA?
We were actually just discussing the "what if I trip their filter" concern at our morning meeting. Full disclosure: my company (as the username implies) builds FunCaptcha, a CAPTCHA alternative. Your concern, to us, is a very valid one and has been a driving force behind our own design and mentality. Our lead designer is (understandably) passionate about this so he actually wrote a few words on the blog that dives pretty deeply into the topic, if you're inclined: https://www.funcaptcha.co/2014/12/04/killing-the-captcha-wit....
Full disclosure: I'm from the team behind a leading CAPTCHA alternative and our concerns are two-fold -- privacy and vulnerabilities.
a) New reCAPTCHA relying on a 'black box' to verify users is of course, naturally concerning privacy wise.
b) the technology that has been implemented to cater to this black box has actually opened the door to more vulnerabilities.
Our Design Director explains the reasoning behind the concern regarding the 'black box' here: http://www.funcaptcha.co/2014/12/04/killing-the-captcha-with...
And I myself go into more detail about Egor Homakov's findings regarding the new vulnerabilities here: http://www.funcaptcha.co/2014/12/04/killing-the-captcha-with...
Apologies if this feels promotional - if you have any questions, I'd be happy to answer them. This is an area of web sec that we're, obviously, very dedicated to.