📜 ⬆️ ⬇️

Researchers pass ReCAPTCHA using Google services



“Prove you are not a robot” checks annoy a lot. Yes, ReCAPTCHA and other similar tools help cut off a lot of bots and spammers, but ordinary users lose time and spend nerve cells on these tests. Therefore, information security experts from all over the world are trying to find an alternative, in addition, some experts are learning how to bypass a captcha.

Scientists from the University of Maryland do it better than others. They called their method unCaptcha, it allows you to bypass Google's ReCAPTCHA using the services of Google itself. The percentage of successful attempts exceeds 90%. It is worth recalling that ReCAPTCHA works on thousands of sites, the service is more popular than many others. Therefore, having learned to bypass it, experts receive extensive opportunities.


An example of ReCAPTCHA with the ability to listen to the information required to solve a captcha for people who cannot, for one reason or another, take tests with photos or symbols
')
The detour was made possible by working with the voice to text conversion service from Google. The principle is quite simple. UnCaptcha loads the audio file ReCAPTCHA (audio is intended for those users who for one reason or another cannot work with captcha images). Next, the audio is divided into elements - spoken letters and numbers. Items are saved and loaded onto various voice recognition and voice-to-text services.

Among other services, a tool from Google is used, as described above. Then the elements recognized and transformed into text are gathered together again and entered into the recognition field of the captcha itself. In addition, the method uses automatic recognition of spoken phrases, which increases the number of successful attempts to bypass the captcha.



Google representatives are aware of the work of scientists - according to the latter, they keep contact with the company for about six months. The corporation is not particularly worried about the captcha and its circumvention, so it did not prevent the publication of the results of the work of specialists.

A year earlier, researchers developed an AI, which learned to bypass captcha in 66% of cases. For this, scientists used non-learning neural networks with the help of millions of captcha images, as in the usual case. Instead, the neural network was taught to determine the shape and shape of characters, which allowed the AI ​​to begin to “understand” the captcha.


If you train the AI ​​on the example of the usual captcha, then yes, you can achieve high accuracy in the course of this work. Successful recognition comes to 89.9%. But it is necessary only to slightly change the style of images, and the recognition accuracy immediately drops, and quite significantly.

Somehow even a captcha was created, which is designed to sift people. It is called Humans Not Invited, and a person can take the test only if there is luck and luck.



Above is a picture with images of just such a captcha, where you need to find all the elements with a selfie stick. Instead of clear pictures, we see pieces of photos that are blurred, where nothing can be disassembled. In a special way, the programmed bot handles this task without any problems. But no matter how you teach a man, nothing will be recognized.

As for the letter captchas, full- convolutional neural networks, where there is no fully connected layer, can best cope with them. All this works so well that the use of symbols simply loses its meaning, since the neural network is easily tested. Perhaps in the near future, captcha will be rejected altogether, and some other method of protection against bots will replace it. But it will not happen soon, now the captcha continues to fulfill its purpose quite well.

Source: https://habr.com/ru/post/435196/


All Articles