Skip to main content

Stanford researchers crack CAPTCHA codes

Captcha-lead
Image used with permission by copyright holder

A pair of researchers at Stanford University have created a computer program capable of cracking CAPTCHA codes, the widespread security system used by websites to determine whether a user is actually human.

CAPTCHA actually stands for Completely Automated Public Turing Test to tell Computers and Humans Apart. Some would actually call CAPTCH a “reverse Turing test,” as it is a computer program meant to identify humans, as opposed to a traditional Turing test, which works the other way around.

Led by researchers Elie Bursztein and John C. Mitchell, the project tested 15 different types of CAPTCHA styles using their custom software dubbed DECAPTCHA. The CAPTCHA codes they tested came from a variety of popular websites, including Wikipedia, eBay, Visa’s Authorize.net, Reddit, Digg, CNN, and Slashdot, among others.

DECAPTCHA works by removing background images and noise, making it easier for the program to decipher the text characters indicated in a particular CAPTCHA code.

The DECAPTCHA script had varying success, depending on the style of CAPTCHA code used by a particular site. For example, DECAPTCHA was only able to crack Wikipedia’s CAPTCHA scheme 25 percent of the time, as were similar schemes from 12 other sites. EBay’s CAPTCHA scheme was cracked 43 percent of the time, the researchers found. And Authorize. net succumbed to DECAPTCHA a troubling 66 percent of the time.

The team found that CAPTCHA codes that use disorienting background images for greater security were not at all effective, and they suggest “using background only for cosmetic purposes.” The team found that using large lines, and a technique known as “collapsing,” a particular way of distorting the characters, “are the only two secure options currently.”

Only Google and reCAPTCHA codes were invulnerable to DECAPTCHA’s attacks. As PhysOrg reports, both Visa’s Authorize.net and Digg have switched to reCAPTCHA since the study was conducted.

View the full study here (pdf).

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
How to download a video from Facebook
An elderly person holding a phone.

Facebook is a great place for sharing photos, videos, and other media with friends and family. But what if you’d like to download a video to store offline? This means you’d be able to watch the clip on your PC or mobile device, without needing to be connected to the internet. Fortunately, there’s a way to download Facebook videos to your everyday gadgets, although it’s not as straightforward a process as it could be.

Read more
How to delete your Gmail account (and what you need to know)
The top corner of Gmail on a laptop screen.

Is it time to part ways with your Gmail account? Whether you’re moving onto greener email pastures, or you want to start fresh with a new Gmail address, deleting your old Gmail account is something anyone can do. Of course, we’re not just going to bid you farewell without a guide all our own. If you need to delete your Gmail account, we hope these step-by-step instructions will make the process even easier.

Read more
How to change margins in Google Docs
Laptop Working from Home

You may find that Google Docs has a UI that is almost too clean. It can be difficult to find basic things you're used to, such as margin settings. Don't worry, though, you can change margins in Google Docs just like with any other word processor through a couple of different means.

Read more