CAPTCHA stands for "Completely Automated Public Turing test to tell Computers and Humans Apart", an acronym coined by Luis von Ahn (Carnegie Mellon University), Manuel Blum, Nicholas J. Hopper (Carnegie Mellon University) and John Langford (IBM) in 2000. CAPTCHAs were used initially by web email services to prevent spammers from automating account creation but are now used by a variety of web applications and are also leveraged as a control to prevent Cross Site Request Forgery (CSRF) attacks. In plain English, CAPTCHAs are those truly annoying, psychedelic images of words and phrases which end users are supposed to be able to easily interpret while computers can't. The problem - they don't work - on either front.
Now I like to think of myself as a reasonably intelligent person. After all, I made it through school and can even complete the first level of Super Monkey Ball. That alone has to place me above average in the gene pool, right? However, when it comes to CAPTCHAs, I'm definitely CAPTCHA impaired. I can't tell you the number of times that I've failed a CAPTCHA test, but forget about me, I'm not the average web surfer anyway. My test for the user friendliness of any good security control in simple - will it be transparent for my Mom? Keep in mind that this is a woman who still owns a VCR which continues to flash '12:00' in her living room. Let's look at few CAPTCHAs to see if Mom will be able to handle them.
Ticketmaster
Now this one isn't too bad. I can read the words 'views wells mr and' but does capitalization count? What about that period before the word 'and'?Verdict: Mom will ultimately get this one, but only after a phone call to me and that's long distance, so that's unacceptable.
Gmail

Hmmmm....could be 'malcurun', 'malairim' or something in between. Let's go to the dictionary...oh wait, whatever it is, it's a made up word, no help there.
Verdict: This one will definitely throw Mom for a loop.
Windows Live
Is that a 'K' or an 'I' dating a pregnant 'L'?Verdict: Not gonna happen.
Whoa. I'm not even going to guess at that first word.Verdict: There's no way that Mom's going to get this one either but she (and I) shouldn't be using Facebook anyway so we'll give this one a pass.
Now if visual CAPTCHAs aren't you're forte, or if you're visually impaired, the propeller heads behind this user friendly security control also have audio CAPTCHAs. For example, since I didn't like the Ticketmaster CAPTCHA above, Ticketmaster also made available, an audio file. Now I don't know about you, but that sounds to me like a crew of monotone people partying in a tunnel and randomly throwing out numbers - not much better.
Now I've argued why CAPTCHAs fail in their goal to be user friendly, but they also fail in preventing and detecting automation. An article published yesterday by MIT's Technology Review discusses how CAPTCHAs are improving AI as researchers continually work be beat various CAPTCHA schemes. I'm not sure that CATCHAs can take credit for assisting our leap into the future but it does illustrate the arms race that will continue. No matter what CAPTCHA scheme is devised, it will ultimately be defeated. Microsoft, Google and Yahoo! have all been forced to change their CAPTCHA technologies after it was revealed that automated attacks had broken their schemes. However, this arms race is rather pointless so long as economics allow for a profit to be made by employing workers in third world countries to interpret CAPTCHAs. It's a bit depressing to learn that uneducated workers are apparently not CAPTCHA impaired.
Alternative Approaches
There are other, user friendly ways to gain confidence that human beings are sending requests as opposed to computer scripts and the answer isn't building a better mouse trap. Variations of CAPTCHAs such as audio files, puzzles, photos, animation, etc. are just as flawed. They aren't user friendly and they too will ultimately be broken. So what can you do?
Take it offline
If your goal is to gain assurance that a human being is involved in the process, take the challenge/response offline. Require that the user respond to an email message, text message or if you really want to be sure, a phone call.
Ask Questions
Ask a question that the user should know but an automated script wouldn't have the intelligence to respond to.
Nonce Values
If you're using CAPTCHAs to prevent CSRF, stop it. CAPTCHAs, beyond all of my previous arguments, rely on human beings, the weakest link in any security chain. Just because you throw a CAPTCHA at a person to ensure that they intervene before doing something stupid like transferring funds, doesn't mean that they won't do it. After all, we've been trained to (try to) answer CAPTCHAs when they're presented. CAPTCHAs have turned us into the digital equivalent of Pavlov's dog. A better alternative is to inject nonce, or a one time value into web forms so that receiving pages can confirm that the request came from the appropriate web form, not from pre-populated values in a spam email link. OWASP projects such as J2EE CSRFGuard, .Net CSRFGuard and the OWASP Enterprise Security API can assist with this.
Can the aforementioned alternatives be bypassed? Of course, but let's keep our goal in mind. Security, especially in services targeted to the general public, must remain as transparent as possible. There is no such thing as bullet proof security, only security that mitigates risk to an appropriate level. Is security an appropriate argument for driving customers away? I don't think so.
It's time for CAPTCHAs to die. If for no other reason, it will make me (and my Mom) happy.
- michael
2 comments:
Dear Michael
Please let me quote you: "Ask Questions: Ask a question that the user should know but an automated script wouldn't have the intelligence to respond to.". This is CAPTCHA by definition.
Another question: you are using moderation in the comments section, protected with a CAPTCHA (?).
Ok, I believe you are right in several things. For instance, CAPTCHAs are annoying! An the more complex the CAPTCHA goes, it is worse for the user. But this a problem of usability, still they are lacking of.
However, saying that they will be defeated anyway makes no sense to me. All IT security meassures are defeated with time and resources, you know you are in the field of the sword and the shield (you on the shield side).
I believe the right path is keep on researching on how to improve them, still they are another line of defense against abuser.
Thank you
I think that souds great and I wish you can do it successfully!
Post a Comment