So my previous post here was just a single unique captcha which I've gone ahead and made some advancements too. I've now changed the look of the captcha and added 3 more captchas to the system.
Old captcha post: /post/02f7682a95550cf0b468
Each time you face a captcha theoretically will be a new one in rotation between the 4 captchas in the system. Each captcha has a very tight validation.
http://dumpliwoard5qsrrsroni7bdiishealhky4snigbzfmzcquwo3kml4id.onion/i/a8f790.png
http://dumpliwoard5qsrrsroni7bdiishealhky4snigbzfmzcquwo3kml4id.onion/i/323fe7.png
http://dumpliwoard5qsrrsroni7bdiishealhky4snigbzfmzcquwo3kml4id.onion/i/815db8.png
http://dumpliwoard5qsrrsroni7bdiishealhky4snigbzfmzcquwo3kml4id.onion/i/84a15e.png
There is a chance someone could face the same captcha 1-3 times in a row as it's literally set to random but the idea is to mitigate against OCR attacks and ability to abuse the system by automatic completion of any captchas. Not like these are basic or simple captchas so it would take someone with some knowledge to get passed the validation since there is some background checks that determine if it's a bot or not.
Hope you like these are much as you liked the single wordsearch captcha that is involved in this just changed design wise since as it's now in a popup instead.
Thanks,
M1000 :}
Wow you're really going into this aren't you
Some feedback:
1. Please don't use "slate" as a colour name. I'm a native English speaker and my first thought was "WTF is a slate square...? wait, the colour slate, like grey?". Just call it grey :)
2. I don't understand what needs to be done in the second one, with rotating shapes - I guess it'd be more obvious on the actual site? But just from the screenshot I am not sure what is going to be rotated or what I'm trying to match to what?
3. In the word search, will it accept any valid selection of the right letters? Because I can see two separate solutions for "SCANS" in that puzzle - I hope both will work?
4. In the fourth one, there aren't any broken red circles? One is orange, the other is pinky-yellowy? If you're going to use colours, I think it needs to be completely unambiguous. Also, remember that colour blind people exist
In general, I'm not sure what having four different kinds of captchas achieve? If none of them are (easily) bot solvable, then why do you need four different ones? If some are easily bot solvable but some aren't, just use the ones that aren't?
If you're trying to mitigate against the risk of one of them proving to be (more easily) bot solvable, then I'm not sure this achieves much? If I was attacking this system, I would focus my time and effort on breaking one of them. If I achieved that, I'd then throw away 75% of requests until I got the one I could break. This would slow down brute force efforts, but not really by much in the grand scheme of things.
My concern is you're going to end up with a site that gets a reputation for being a PITA for real users to log into. One challenging captcha type is bad enough, but if the user keeps getting a different kind and keeps having to re think about what the site is asking of them (bearing in mind they could well be stoned, half asleep, a moron, or most likely all three) it's going to increase the annoyance factor considerably.
Just my 2c, and speaking in general terms not as an expert in DN opsec
Some feedback:
1. Please don't use "slate" as a colour name. I'm a native English speaker and my first thought was "WTF is a slate square...? wait, the colour slate, like grey?". Just call it grey :)
2. I don't understand what needs to be done in the second one, with rotating shapes - I guess it'd be more obvious on the actual site? But just from the screenshot I am not sure what is going to be rotated or what I'm trying to match to what?
3. In the word search, will it accept any valid selection of the right letters? Because I can see two separate solutions for "SCANS" in that puzzle - I hope both will work?
4. In the fourth one, there aren't any broken red circles? One is orange, the other is pinky-yellowy? If you're going to use colours, I think it needs to be completely unambiguous. Also, remember that colour blind people exist
In general, I'm not sure what having four different kinds of captchas achieve? If none of them are (easily) bot solvable, then why do you need four different ones? If some are easily bot solvable but some aren't, just use the ones that aren't?
If you're trying to mitigate against the risk of one of them proving to be (more easily) bot solvable, then I'm not sure this achieves much? If I was attacking this system, I would focus my time and effort on breaking one of them. If I achieved that, I'd then throw away 75% of requests until I got the one I could break. This would slow down brute force efforts, but not really by much in the grand scheme of things.
My concern is you're going to end up with a site that gets a reputation for being a PITA for real users to log into. One challenging captcha type is bad enough, but if the user keeps getting a different kind and keeps having to re think about what the site is asking of them (bearing in mind they could well be stoned, half asleep, a moron, or most likely all three) it's going to increase the annoyance factor considerably.
Just my 2c, and speaking in general terms not as an expert in DN opsec
1. Please don't use "slate" as a colour name. I'm a native English speaker and my first thought was "WTF is a slate square...? wait, the colour slate, like grey?". Just call it grey :)
> this is because I'm not native english :)
2. I don't understand what needs to be done in the second one, with rotating shapes - I guess it'd be more obvious on the actual site? But just from the screenshot I am not sure what is going to be rotated or what I'm trying to match to what?
> This will become clear when you rotate the sections for sure in an image it's not so clear.
3. In the word search, will it accept any valid selection of the right letters? Because I can see two separate solutions for "SCANS" in that puzzle - I hope both will work?
> There is only one "Scans" in that image on the select-able section mate, not sure what you are seeing it's a word search so they would have to be conjoined :}
4. In the fourth one, there aren't any broken red circles? One is orange, the other is pinky-yellowy? If you're going to use colours, I think it needs to be completely unambiguous. Also, remember that colour blind people exist
> I think it's due to degrading of the image, it's actually red if you look at it, or at-least for me anyway maybe I'm the color blind one who knows haha!
In general, I'm not sure what having four different kinds of captchas achieve? If none of them are (easily) bot solvable, then why do you need four different ones? If some are easily bot solvable but some aren't, just use the ones that aren't?
If you're trying to mitigate against the risk of one of them proving to be (more easily) bot solvable, then I'm not sure this achieves much? If I was attacking this system, I would focus my time and effort on breaking one of them. If I achieved that, I'd then throw away 75% of requests until I got the one I could break. This would slow down brute force efforts, but not really by much in the grand scheme of things.
> they are monitored for abuse, we can disable one, enable just a single captcha etc.
My concern is you're going to end up with a site that gets a reputation for being a PITA for real users to log into. One challenging captcha type is bad enough, but if the user keeps getting a different kind and keeps having to re think about what the site is asking of them (bearing in mind they could well be stoned, half asleep, a moron, or most likely all three) it's going to increase the annoyance factor considerably.
> valid but I'm not here to be like most if they have trouble I guess that is on them would just be one less competent person using the market, I'm not here to baby sit I know the majority of people will be able to access it's not rocket science and really is just a matter of getting use to it like everyone did on the other captchas.
But appreciate the feedback :}
> this is because I'm not native english :)
2. I don't understand what needs to be done in the second one, with rotating shapes - I guess it'd be more obvious on the actual site? But just from the screenshot I am not sure what is going to be rotated or what I'm trying to match to what?
> This will become clear when you rotate the sections for sure in an image it's not so clear.
3. In the word search, will it accept any valid selection of the right letters? Because I can see two separate solutions for "SCANS" in that puzzle - I hope both will work?
> There is only one "Scans" in that image on the select-able section mate, not sure what you are seeing it's a word search so they would have to be conjoined :}
4. In the fourth one, there aren't any broken red circles? One is orange, the other is pinky-yellowy? If you're going to use colours, I think it needs to be completely unambiguous. Also, remember that colour blind people exist
> I think it's due to degrading of the image, it's actually red if you look at it, or at-least for me anyway maybe I'm the color blind one who knows haha!
In general, I'm not sure what having four different kinds of captchas achieve? If none of them are (easily) bot solvable, then why do you need four different ones? If some are easily bot solvable but some aren't, just use the ones that aren't?
If you're trying to mitigate against the risk of one of them proving to be (more easily) bot solvable, then I'm not sure this achieves much? If I was attacking this system, I would focus my time and effort on breaking one of them. If I achieved that, I'd then throw away 75% of requests until I got the one I could break. This would slow down brute force efforts, but not really by much in the grand scheme of things.
> they are monitored for abuse, we can disable one, enable just a single captcha etc.
My concern is you're going to end up with a site that gets a reputation for being a PITA for real users to log into. One challenging captcha type is bad enough, but if the user keeps getting a different kind and keeps having to re think about what the site is asking of them (bearing in mind they could well be stoned, half asleep, a moron, or most likely all three) it's going to increase the annoyance factor considerably.
> valid but I'm not here to be like most if they have trouble I guess that is on them would just be one less competent person using the market, I'm not here to baby sit I know the majority of people will be able to access it's not rocket science and really is just a matter of getting use to it like everyone did on the other captchas.
But appreciate the feedback :}
Looks very nice!
Thank you.