Skip to main content

Stanford researchers crack CAPTCHA codes

Captcha-lead
Image used with permission by copyright holder

A pair of researchers at Stanford University have created a computer program capable of cracking CAPTCHA codes, the widespread security system used by websites to determine whether a user is actually human.

CAPTCHA actually stands for Completely Automated Public Turing Test to tell Computers and Humans Apart. Some would actually call CAPTCH a “reverse Turing test,” as it is a computer program meant to identify humans, as opposed to a traditional Turing test, which works the other way around.

Led by researchers Elie Bursztein and John C. Mitchell, the project tested 15 different types of CAPTCHA styles using their custom software dubbed DECAPTCHA. The CAPTCHA codes they tested came from a variety of popular websites, including Wikipedia, eBay, Visa’s Authorize.net, Reddit, Digg, CNN, and Slashdot, among others.

DECAPTCHA works by removing background images and noise, making it easier for the program to decipher the text characters indicated in a particular CAPTCHA code.

The DECAPTCHA script had varying success, depending on the style of CAPTCHA code used by a particular site. For example, DECAPTCHA was only able to crack Wikipedia’s CAPTCHA scheme 25 percent of the time, as were similar schemes from 12 other sites. EBay’s CAPTCHA scheme was cracked 43 percent of the time, the researchers found. And Authorize. net succumbed to DECAPTCHA a troubling 66 percent of the time.

The team found that CAPTCHA codes that use disorienting background images for greater security were not at all effective, and they suggest “using background only for cosmetic purposes.” The team found that using large lines, and a technique known as “collapsing,” a particular way of distorting the characters, “are the only two secure options currently.”

Only Google and reCAPTCHA codes were invulnerable to DECAPTCHA’s attacks. As PhysOrg reports, both Visa’s Authorize.net and Digg have switched to reCAPTCHA since the study was conducted.

View the full study here (pdf).

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
How to create a Subreddit on desktop and mobile
Laptop Working from Home

Few social media sites are as popular as Reddit. Regardless of what you're interested in, there's probably a thriving community for you to interact with on the platform. Known as subreddits, these communities are home to topics like gaming, world news, science, movies, and more. If you can't find a subreddit with your particular interest, Reddit makes it easy to create your own Reddit community.

Running a successful Reddit community isn't easy – but the process of starting one only takes a few minutes. Keep in mind that you'll want to keep a close eye on your subreddit to prevent it from being shut down or turning into a wasteland with no users, but running a subreddit can be a lot of fun when done properly. If you prefer, you can also create a private community that only your friends can join, giving you a place to hang out beyond Twitter and TikTok.

Read more
How to download music from YouTube on desktop and mobile
A woman sitting on a couch, wearing airpods and holding and looking at a smartphone.

Downloading music from YouTube is a fairly common practice, and the demand for making the process easier has inspired the creation of countless websites and software.

But not every service can be considered safe. In fact, some of these services may infect your computer with malware or produce poor-quality audio files. When downloading music from YouTube, you’ll need to first make sure that the websites or apps you use for doing so won’t hurt your device. For this guide our team has found two methods to make the process safer and easier.

Read more
How to clear your browser cache in Chrome, Edge, or Firefox
The Firefox iPhone app.

A stocked computer cache may be convenient for logging into and out of go-to sites in seconds flat, but a major buildup of these tracking codes could significantly impact your PC’s performance. If you’ve noticed that your PC has been running rather slow of late, or you’re using a new browser and don’t know how to clear its cache, we’ve got you covered with the following guide.

Read more