nanog mailing list archives

Re: Captchas on Cloudflare-Proxied Sites


From: Rich Kulawiec via NANOG <nanog () lists nanog org>
Date: Tue, 1 Jul 2025 17:43:22 -0400

This is especially ironic given that captchas were pretty much defeated
10-15 years ago, thoroughly defeated in the last 2-3 years, and are now
exclusively deployed by people who (a) haven't been paying attention and
(b) like to pretend that they still work.

Oh, citation needed?  Okay, here are a few.  Let's start in 2008:

        Gone in 60 seconds: Spambot cracks Live Hotmail CAPTCHA
        http://arstechnica.com/news.ars/post/20080415-gone-in-60-seconds-spambot-cracks-livehotmail-captcha.html

        Cheap CAPTCHA Solving Changes the Security Game
        https://freedom-to-tinker.com/blog/felten/cheap-captcha-solving-changes-security-game/

and 2011:

        Stanford researchers outsmart captcha codes
        http://www.physorg.com/news/2011-11-stanford-outsmart-captcha-codes.html

and 2012:

        How a trio of hackers brought Google's reCAPTCHA to its knees | Ars Technica
        http://arstechnica.com/security/2012/05/google-recaptcha-brought-to-its-knees/

        Troy Hunt: Breaking CAPTCHA with automated humans
        http://www.troyhunt.com/2012/01/breaking-captcha-with-automated-humans.html

and 2014:

        Snapchat account registration CAPTCHA defeated
        https://techienews.co.uk/snapchat-account-registration-captcha-defeated/

and 2017:

        Artificial Intelligence Beats CAPTCHA - IEEE Spectrum
        https://spectrum.ieee.org/artificial-intelligence-beats-captcha

        unCAPTCHA Breaks 450 ReCAPTCHAs in Under 6 Seconds
        https://www.bleepingcomputer.com/news/technology/uncaptcha-breaks-450-recaptchas-in-under-6-seconds/

and 2023:

        AI bots are better than humans at solving CAPTCHA puzzles
        https://qz.com/ai-bots-recaptcha-turing-test-websites-authenticity-1850734350

        [2307.12108] An Empirical Study &amp; Evaluation of Modern CAPTCHAs
        https://arxiv.org/abs/2307.12108

and 2024:

        AI researchers demonstrate 100% success rate in bypassing online CAPTCHAs
        
https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-researchers-demonstrate-100-success-rate-in-bypassing-online-captchas

        [2409.08831] Breaking reCAPTCHAv2</a>
        https://arxiv.org/abs/2409.08831

---rsk
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/4GS7V5O22YWC7WZ56JM3GYCMTF4XWZAQ/


Current thread: