“For any technology with a percentage market penetration of X, protecting a benefit/resource with a relative worth of Y, and possessing a relative security strength of Z, the probability that said technology will eventually be compromised is X + Y.”
Brian Huisman
Below is a list of resources I dug up that illustrate that CAPTCHA isn’t the security silver bullet people think they are. Included below are news stories as well as direct links to software and services to bypass CAPTCHA. I include these not as an endorsement of these products and services but to show how easy it is for someone to find & purchase such things. Some of these are out of date. Some of the methods discussed may no longer work. The point is, however, that there is a constant battle going on against bad guys who want to gain illegitimate access to others’ systems and that CAPTCHA is not an instant cure.
- Breaking a Visual CAPTCHA
- Breaking CAPTCHA without OCR
- Breaking the Paypal.com CAPTCHA
- Breaking e-banking CAPTCHAS
- Breaking the ASP Security Image Generator
- PWNtcha – CAPTCHA Decoder
- aiCaptcha – Using AI to beat CAPTCHA and post comment spam
- Arstechnica – Gone in 60 seconds: Spambot cracks Live Hotmail CAPTCHA
- Slashdot – Yahoo CAPTCHA Hacked
- Slashdot Gmail CAPTCHA Cracked
- Slashdot – Google’s Audio CAPTCHA Falls to Automated Attack
- Computerworld – How CAPTCHA got trashed
- How Spam is Improving AI discusses that even photo-based CAPTCHA is being cracked
- Spammers’ bot cracks Microsoft’s CAPTCHA: (possibly reporting duplicate info from #8)
- NY Times: Spammers Pay Others to Answer Security Tests
- BeatCAPTCHAS.com – a service which solves CAPTCHAs for you at a rate of $8.00 per 1000 CAPTCHAs solved
- CAPTCHA Cracker site which sells a program to beat CAPTCHAs
- CAPTCHA Sniper program to solve CAPTCHAs
- Decaptcha beats CAPTCHAs
- Death By CAPTCHA (bypass service, has API for use. $1.39 for 1000 solved CAPTCHAs
- Stanford researchers crack CAPTCHA codes
- Decaptcha: Breaking 75% of eBay audio CAPTCHAs
- Breaking Weak CAPTCHA in 26 Lines of Code
- Machine Learning Attacks Against the Asirra CAPTCHA
- PC Mag: Deep-Sixing CAPTCHA
- Breaking CAPTCHA with automated humans
- Breaking Audio CAPTCHAs [PDF]
- Computerworld.com: Repetition Breaks Google Audio CAPTCHA