desirepath41 / visualCaptcha

visualCaptcha's Main Repo. This is a collection of all the different versions/repos of visualCaptcha.
https://emotionloop.github.io/visualCaptcha-demo/
406 stars 43 forks source link

Too easy to crack #8

Closed ghost closed 10 years ago

ghost commented 10 years ago

Sorry guys but your captcha very easy to crack 1/10.

First need create database on your images:

lamers

This is some kind of joke ?

BrunoBernardino commented 10 years ago

Closing because this is being discussed over at #2.

  1. You're forgetting the point of the images/audio being custom per website.
  2. Making a database per website being "attacked" is not a "minor cost".

Finally, visualCaptcha is about improving the UX for the people using your application, without diminishing security considerably, not targeted at things like google.com or apple.com where there are obviously other implications to take under consideration.

Thanks for your feedback anyway!

CrazyPython commented 8 years ago

@BrunoBernardino A hacker with four hours could break your security y downloading something like ConvNetJS and using it to recognize images. No GPU required.

BrunoBernardino commented 8 years ago

I can imagine that's possible for the default install everyone sees. I'd recommend those people use something like reCaptcha.