How NOT to do CAPTCHA Security

By Daniel Miessler on January 28th, 2008: Tagged as Information Security | Security
  • Bahamut

    Do you know how it was set up? If someone found a way to dump out the test in text-format but also not have it available in the source somewhere, it should work. If it’s rock-solid and works, why is it bad? And before you claim it can never work, real people also know that they shouldn’t be using absolutes for anything.

    How about not talking about something you never seen based on someone’s observation of something he probably didn’t know how it worked? How about not over generalizing people who develop and assuming that all developers are idiots? Researching before you blog about something? In. Sane.

  • Bahamut

    Do you know how it was set up? If someone found a way to dump out the test in text-format but also not have it available in the source somewhere, it should work. If it’s rock-solid and works, why is it bad? And before you claim it can never work, real people also know that they shouldn’t be using absolutes for anything.

    How about not talking about something you never seen based on someone’s observation of something he probably didn’t know how it worked? How about not over generalizing people who develop and assuming that all developers are idiots? Researching before you blog about something? In. Sane.

  • Matt

    Bahamut, his point was that it is not a Turing test. Even if you could not figure out how to the extract the text from the image, you can write a script to select the text and paste it into the box.

  • Matt

    Bahamut, his point was that it is not a Turing test. Even if you could not figure out how to the extract the text from the image, you can write a script to select the text and paste it into the box.

  • http://dmiessler.com/ Daniel Miessler

    @Bahamut

    Jesus help us if you weren’t joking.

    If you weren’t you basically heard about someone being stupid, watched me make fun of them for being stupid, then proceeded to not even grasp why it was stupid, and then follow up with assuming I was the one who missed something.

    You must be a developer, which means your comment is getting added to the coveted “most ironic comment” list. Nothing against you personally, but you just served as the example for the post. I couldn’t have made something up any better.

  • http://dmiessler.com Daniel Miessler

    @Bahamut

    Jesus help us if you weren’t joking.

    If you weren’t you basically heard about someone being stupid, watched me make fun of them for being stupid, then proceeded to not even grasp why it was stupid, and then follow up with assuming I was the one who missed something.

    You must be a developer, which means your comment is getting added to the coveted “most ironic comment” list. Nothing against you personally, but you just served as the example for the post. I couldn’t have made something up any better.

  • http://www.commonabnormality.com/ Hot Carl

    Man, Daniel, I wish you were joking but the sad part is that I know you’re not.

  • http://www.commonabnormality.com/ Hot Carl

    Man, Daniel, I wish you were joking but the sad part is that I know you’re not.


Top

Popular

Information Security / Technology

Politics

Philosophy & Religion

Technology & Science

Culture & Society

Miscellaneous

Arguments

Projects

Collections

Twitter

What I'm Reading

Favorite Books and Essays

Top Blog Categories

Inputs