CAPTCHAs Are Becoming Security Theater

Google doesn't even need us to prove our humanity anymore, which is a good thing, because they can simulate it now.

CAPTCHAs are a time-worn way for humans to tell computers that we are human. They are those little boxes filled with distorted text that we've been told humans can decipher, but computers—the bad guys' computers—cannot. So, Watson-be-damned, we enter the letters and gain access to whatever is behind the veil, leaving the bad bots steaming outside the pearly, CAPTCHA'd gates. As Google's ReCAPTCHA website puts it: "Tough on bots, easy on humans."

It is a satisfying display of human superiority built into the daily experience of the web. And, BONUS, you're often helping do optical character recognition on old books at the same time. Take that, Machines, you don't even have any books.

But then along comes Google today noting, in a showily short and breezy blog post, that their machines can beat ReCAPTCHAs 99% of the time

"Turns out that this new algorithm can also be used to read CAPTCHA puzzles—we found that it can decipher the hardest distorted text puzzles from reCAPTCHA with over 99 percent accuracy," writes Google product manager Vinay Shet. "This shows that the act of typing in the answer to a distorted image should not be the only factor when it comes to determining a human versus a machine."

But that's not even the most galling thing. That's reserved for the next paragraph.

"Last year, we announced that we’ve significantly reduced our dependence on text distortions as the main differentiator between human and machine," Shet continues, "and instead perform advanced risk analysis."

So, we've been proudly typing away the whole time, proving we were human, and Google knew that all along.

In an earlier post, Shet described their process in general terms: Google has begun "actively considering the user’s entire engagement with the CAPTCHA—before, during and after they interact with it. That means that today the distorted letters serve less as a test of humanity and more as a medium of engagement to elicit a broad range of cues that characterize humans and bots." 

Now, we go on typing into the box, but our evolved visual systems—some of the most sophisticated in the animal kingdom—are no longer all that necessary.

What we once did to assure Google that we were still human has become security theater. The only audience that we need to perform our humanity for is ourselves. 

 

Presented by

How to Cook Spaghetti Squash (and Why)

Cooking for yourself is one of the surest ways to eat well. Bestselling author Mark Bittman teaches James Hamblin the recipe that everyone is Googling.

Join the Discussion

After you comment, click Post. If you’re not already logged in you will be asked to log in or register.

blog comments powered by Disqus

Video

How to Cook Spaghetti Squash (and Why)

Cooking for yourself is one of the surest ways to eat well.

Video

Before Tinder, a Tree

Looking for your soulmate? Write a letter to the "Bridegroom's Oak" in Germany.

Video

The Health Benefits of Going Outside

People spend too much time indoors. One solution: ecotherapy.

Video

Where High Tech Meets the 1950s

Why did Green Bank, West Virginia, ban wireless signals? For science.

Video

Yes, Quidditch Is Real

How J.K. Rowling's magical sport spread from Hogwarts to college campuses

Video

Would You Live in a Treehouse?

A treehouse can be an ideal office space, vacation rental, and way of reconnecting with your youth.

More in Technology

Just In