Feeds

Google boffins unveil 'What's Up?' CAPTCHA

Arms race extended

High performance access to file storage

Attempting to take the upper hand in the battle against bots, researchers from Google have devised a new CAPTCHA system that uses a series of randomly rotated images to distinguish between human visitors and automated scripts.

The technique, detailed in a paper titled What's Up CAPTCHA? (PDF), presents people signing up for site accounts or performing other website tasks with several pictures that are identical except for one attribute: some of them are upside-down or sideways. To gain permission to create the account or post a comment, a user must successfully click on the image that is right-side up.

"The main advantages of our CAPTCHA technique over the traditional text recognition techniques are that it is language-independent, does not require text-entry (e.g. for a mobile device), and employs another domain for CAPTCHA generation beyond character obfuscation," the researchers wrote. "This CAPTCHA lends itself to rapid implementation and has an almost limitless supply of images."

Short for completely automated public Turing test to tell computers and humans apart, the CAPTCHA has fallen on hard times over the past few years. Advances in optical character recognition have allowed researchers and criminal cyber gangs to crack the Captcha systems employed by Google, Microsoft and other large online properties. In other cases, perps have circumvented CAPTCHAs by opening sweatshops of paid serfs to break the puzzles enmasse.

As CAPTCHAs have become easier to crack, engineers have responded by using increasingly distorted images and more cluttered backgrounds. That, in turn, has made them the scorn of countless human beings who find them harder and harder to decipher.

Researchers Rich Gossweiler, Maryam Kamvar and Shumeet Baluja said image orientation is something that's easy for humans to figure out but surprisingly hard for computers.

Maybe, but the new method may also have its drawbacks. For one, even if a script simply guesses, there's a one in 22 chance that it will pick the right image. What's more, because it relies on a set of pictures, a human being will be needed to "make a judgment call on what is the correct position," according to web security expert Robert Hansen, who details several other criticisms here.

Examples of images used in new CAPTCHA technique

A slide from the researchers' paper

A Google spokesman declined to say whether the company plans to fold the new CAPTCHA into any of its online properties. ®

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.