Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Do you have any response to claims that your product is easily broken? https://hackertimes.com/item?id=4025791

I'm skeptical of your efforts to distinguish humans from bots by mouse movements and other inputs. Anything you can infer can be modeled. It's unreasonable to expect a smart captcha cracker to resemble a zero reaction time Counter Strike aimbot.



Thanks for asking. First, our main focus is on making something more usable for people. We also think captchas are only part of the solution and should be employed with other things (rate limiting, keyword filtering, etc)

That being said, we don't just ignore security. There are a lot of captcha alternatives out there that survive on just obscurity, if they were widely adopted, they wouldn't take much to get around (like a slide to unlock captcha). We analyze mouse movement and other behavior, to avoid this.

To test our algorithms, we write our own bots to break our game (as well as working with the AI lab at the university of michigan) and use that data in our machine learning algorithms. We're always tweaking the bot to see how we can beat it and then looking for new features from the data that we can use.

The main point being, that as people do write bots, we can learn from that and incorporate it. We can also adjust the threshold. Some of our customers care much more about usability and just want a minimum level of protection, other's want the threshold a little higher and accept the risk that humans might fail more often.


> our main focus is on making something more usable for people

Considering that your games can be played by a random number generator with something like 10% success rate, you can just skip the captcha completely. Much more user friendly.

The other things you look at to increase security, like detecting patterns and behaviors that indicates bots can be done without a captcha.


I'm note sure you can get a 10% success rate, if you have let us know, we'd love to hear about it. Note that our demo page has the threshold set to almost nothing and other security features disabled.

Totally agree that we could detect patterns and behaviors without the captcha. Baby steps, though. We'll get there.


And it still identified my as a bot in one out of three tries. And now I shall put the food in the refrigerator when the only items left are a microphone, a stapler and a bottle of household cleaner.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: