On CBS MoneyWatch: 29 Fees We Hate to Pay
BNET Business Network:
BNET
TechRepublic
ZDNet

September 16th, 2009

Google + reCAPTCHA could raise bar in anti-bot, anti-spam battle

Posted by Ryan Naraine @ 12:54 pm

Categories: Anti Virus, Botnets, Browsers, Data theft, Denial of Service (DoS), Google, Hackers, Malware, Patch Watch, Phishing, Research, Vulnerability research, Web 2.0

Tags: CAPTCHA, Google Inc., Anti-spam, Bot, Ryan Naraine

Locked in a cat-and-mouse game with spammers who use bots to defeat anti-fraud mechanisms and create fake accounts, Google today announced a deal to acquire reCAPTCHA, a company that provides those squiggly words at login screens (see image at right).

The ReCAPTCHA deal isn’t exactly a security transaction.  Strategically, it gives Google an excellent crowd-sourcing tool to beef up its already impressive machine-vision algorithms (think book-scanning and maps) but, in the long run, the ability to use CAPTCHAs that are near-impossible for bots to decipher allows Google to raise the bar significantly in the fight against bots and spam.

According to Adam O’Donnell, director of emerging technologies at anti-spam firm Cloudmark, believes this is a very smart purchase by Google.

“Google already has the best computer-vision techniques.  The way ReCAPTCHA works, this means that Google will only be presenting CAPTCHA words that are very difficult for a bot to defeat,” O’Donnell explained.

“By pushing up that boundary, it will make CAPTCHA technology much better.”

The words presented by the ReCAPTCHA service come from scanned printed material (archival newspapers and old books).   As Google explains here, computers find it hard to recognize these words because the ink and paper have degraded over time, but by typing them in as a CAPTCHA, crowds teach computers to read the scanned text.

In this way, reCAPTCHA’s unique technology improves the process that converts scanned images into plain text, known as Optical Character Recognition (OCR). This technology also powers large scale text scanning projects like Google Books and Google News Archive Search. Having the text version of documents is important because plain text can be searched, easily rendered on mobile devices and displayed to visually impaired users. So we’ll be applying the technology within Google not only to increase fraud and spam protection for Google products but also to improve our books and newspaper scanning process.

CAPTCHAs have served to slow down spammers and phishers but in many cases, they are easily defeated by bots or humans hired to manually solve text in the squiggly-lined images.

[ Dancho Danchev: Google's CAPTCHA experiment and the human factor ]

Earlier this year, Researchers at Google recently released a paper detailing a new CAPTCHA system consisting of correct image rotation (Socially Adjusted CAPTCHAs) whose main purpose is to make it easier for humans, and much harder for bots to recognize them.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 69 Talkback(s)
That sounds more expensive than captcha
What you propose might work, but someone could hire cheap labor to go and solve the answers and keep track of the questions. You would need to have hundreds of thousands, maybe millions, of questions ... (Read the rest)
Posted by: K B Posted on: 10/09/09 You are currently: a Guest | | Terms of Use
What about for the deaf-blind?  Grayson Peddie | 09/16/09
Well what are other options?  storm14k | 09/16/09
Hidden Text Boxes Only Visible To Bots  Grayson Peddie | 09/16/09
The bot can learn which boxes cause a failure.  T1Oracle | 09/17/09
True, but maybe a hidden-field submission could serve-up a fake "reward"...  arwalden | 09/17/09
Good idea but...  jrbeaman | 09/18/09
hidden fields  Bucky24 | 09/23/09
You are wrong.  jrbeaman | 09/18/09
Another option to captcha is easier, cheaper, better.  jrbeaman | 09/18/09
I like your thinking but?  clareJ | 09/21/09
But reCaptcha fails in too many ways.  jrbeaman | 09/18/09
reCaptcha has an audio feature. nt  T1Oracle | 09/17/09
Add deafness to blindness and no audio.  Grayson Peddie | 09/17/09
Well what's your answer?  Wintel BSOD | 09/17/09
The answer is too easy.  jrbeaman | 09/18/09
And it gives the answer. FAIL nt  jrbeaman | 09/18/09
Not to be cynical  rolf.ernst@... | 09/17/09
do the Helen Keller  ilyab | 09/17/09
Exactly my point  gammaworld@... | 09/17/09
Simple Solution  gammaworld@... | 09/17/09
OK this is getting STUPID  GAXXIS | 09/17/09
Stupid is as Stupid does.  jrbeaman | 09/18/09
Know whats next for the hackers?  jrbeaman | 09/18/09
Another failure for an answer...  jrbeaman | 09/18/09
We Need A Better Way  STBA2009 | 09/16/09
What do YOU really hate about it?  Shmuel | 09/17/09
Too hard to see  mswift@... | 09/17/09
Good idea, but try to do that with braille, or sound only.  jrbeaman | 09/18/09
Asirra Dogs vs Cats  rpayne@... | 09/17/09
I like your method  gammaworld@... | 09/17/09
Yu mean we don't need to cater to the idiots any more?  jrbeaman | 09/18/09
Excellent suggestion.  jrbeaman | 09/18/09
Google is not the only company in the OCR Game. happy  John3k | 09/16/09
Your post looks more like spam than an honest comment.  jrbeaman | 09/18/09
$1/year for an account.  CobraA1 | 09/17/09
Failure  T1Oracle | 09/17/09
Require ISP email addresses  Stan57 | 09/17/09
Whose ISP?  cgarrett | 09/17/09
Library mail servers?  mswift@... | 09/17/09
I think you're confused  cgarrett | 09/17/09
My thoughts exactly  SkaldedKat | 09/17/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  Alro | 09/17/09
Is this a good enough argument?...  Shmuel | 09/17/09
Classic hacker way to bypass almost any captcha.  magallanes | 09/17/09
Doesn't work  gammaworld@... | 09/17/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  BaltimoreBarry | 09/17/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  thekman58 | 09/17/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  K4KEP | 09/17/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  infocomp | 09/17/09
CAPTCHA is overkill.  jrbeaman | 09/18/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  SquareD277 | 09/17/09
Agreed. Just be happy with what you have  gammaworld@... | 09/17/09
Eventually they will have permanant accounts  gammaworld@... | 09/17/09
You aren't thinking this through  jrbeaman | 09/18/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  JD_Mortal | 09/17/09
Not to mention...  jrbeaman | 09/18/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  JD_Mortal | 09/17/09
dyslexia.  gproze | 09/17/09
dsl lower than dialup  satovey@... | 09/18/09
SPAMMER War  esale | 09/17/09
what sites monitor and provide block lists  Dave Ladely | 09/17/09
Your punishment...  jrbeaman | 09/18/09
The answer is too easy, and you all missed it.  jrbeaman | 09/18/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  ccfman2004 | 09/17/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  jenny1930 | 09/17/09
CAPTCHA is a FAIL! - Here is the answer!  jrbeaman | 09/18/09
That sounds more expensive than captcha  K B | 10/09/09
RE: Google reCAPTCHA could raise bar in anti-bot, anti-spam battle  OKWHEN | 09/18/09
Very simple solution for the impaired  jpdemers@... | 09/20/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here