I have found out about the new no-captcha. How does it sense the application/relationship it is served in, and set the correct security level? The security level, and acceptable bot activity, is depending on application. For example: A signup form: Then it does not matter if a bot succeed to register 5-10 accounts, because those accounts can be cleaned off easly (banned or removed). A post form: Same here. A search form: Here it does not matter if a bot successfully launch 100 of searches, but 10 000 does matter to the load of the server. But the most sensitive application: A LOGIN form. Here its dangerous if even one single bot request slinks through, because the captcha is there most of the time to prevent CSRF, XSS, Bruteforce attacks, session stealing and Active sniffing and "race" attacks. I guess No-captcha uses some sort of "hash-cash" scheme where the client is asked to computationally solve a challenge, combined with a rate-limiting system, where the No-captcha application checks if theres successful or failed solves from the same IP-adress previously in a short time, and upon this information, decides if it should present a real captcha or not. I guess that a bot can successfully, with a high rate of success (90%+) pass the first No-captcha given a specific set of credentials (IP, Cookies, UserAgent and so on)? Are im right? But subsuquent requests become harder and harder due to the rates kicking in and displaying a real captcha? Or how does the No-captcha weed out the first bot request ever? Lets say a client IP that No-captcha never seen, it bears normal google cookies, and it does have a sensible useragent matching lets say 50% of the population. And this client is a bot. What does prevent a bot from checking the checkbox and then solving the computationally hard challenge (hashcash) which would take 5 seconds to solve, but would be solved with 100% of certainly? -- You received this message because you are subscribed to the Google Groups "reCAPTCHA" group. To unsubscribe from this group and stop receiving emails from it, send an email to recaptcha+unsubscribe@googlegroups.com. To post to this group, send email to recaptcha@googlegroups.com. Visit this group at http://bit.ly/1dkFnYd. For more options, visit http://bit.ly/P65DvS.
Send Voicemail | EnAcCiOn
Contact me using vCita | EnAcCiOn
Contact Form & Online Scheduling by vCita
Contact me using vCita | EnAcCiOn
Meeting Scheduler Powered by vCita
Suscribirse a:
Enviar comentarios (Atom)
EnAcCiOn
Contador Web | EnAcCiOn
EnAcCiOn
-
shows de baile de la colombiana laura en el kilombo (huacho) | EnAcCiOn.Tk ░░░░░░░░░░░░▄▄░░░░░░░░█░█░█░░█░█▀▀░▀█▀░█▀▀ ░░░░░░░░░░░█░░█░░░░...
-
C-C-C CIUCCIA CAZZI DI CAVALLO PAOLO BARRAI DI WMO E BSI ITALIA SRL, UNA VOLTA CACCIATO (E FATTO CONDANNARE A GALERA) DA CITIBANK, PRIMA DI ...
-
Hello, My code works fine a few days ago, but no, I have this problem. Code Example: $(function(){ widgetnu = grecaptcha.render('c...
-
Hi,I have resized it by transform:scale and all seems good until I get the pop-up bubble with pictures (napr.: "choose all cakes" ...
-
Any thoughts on this would be really helpful. Same issue posted in StackOverflow doesn't seem to get a response: I am trying to get Goog...
-
░░░░░░░░░░░░▄▄░░░░░░░░█░█░█░░█░█▀▀░▀█▀░█▀▀ ░░░░░░░░░░░█░░█░░░░░░░█░█░██░█░█▀░░░█░░█▀░ ░░░░░░░░░░░█░░█░░░░░░░▀▄▀░█░▀█░█▄▄░░█░░█▄▄ ░░░░░░░...
-
EL PAÃS compartió una publicación. VÃdeo | Aunque en las pelÃculas no da resultado, se ve que los mensajes en la arena funcionan en la ...
-
Diario El Comercio compartió una publicación. #YouTube Descubren a pedófilo en experimento de niña perdida [#VIDEO] ►http://bit.ly/1h8Up Pe...
EnAcCiOn
EnAcCiOn
Blog Archive | EnAcCiOn
-
►
2013
(1429)
- ► septiembre (156)
-
▼
2014
(1220)
- ► septiembre (43)
No hay comentarios:
Publicar un comentario