Dailydave mailing list archives

Re: confirming it's a person


From: "Stefan Wagner" <ffm.stefan () googlemail com>
Date: Wed, 26 Mar 2008 18:21:41 +0100

 I think we have already discussed this topic, and someone said we could
 use pictures of cats and other animals and ask the user to count the
 number of cats on the photos.

 Microsoft is working on this, it looks promising.

 http://research.microsoft.com/asirra/

I think a weak point may be that petfinder.com pictures are available
to the public too.

An Attacker could let some bots crawl petfinder.com by Category, grab
the thumbnails
(or the big pictures) and resize 'em to asirra thumbnail size (to
avoid the bottom text "petfinder.com"
Logo on asirra big pictures) and put some CRC of that into a DB (maybe
even make it b/w and
low-res, only take specified part(s) of the picture for the CRC and so
on). This sure won't be perfect, but
for some usable percentage i think it may currently work.

Regards,
 Stefan
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: