<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Defeating Digg&#8217;s CAPTCHA</title>
	<atom:link href="http://bhiv.com/defeating-diggs-captcha/feed/" rel="self" type="application/rss+xml" />
	<link>http://bhiv.com/defeating-diggs-captcha/</link>
	<description></description>
	<pubDate>Wed, 19 Nov 2008 23:45:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: T=Machine &#187; Austin GDC: Vote for your conference</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-2952</link>
		<dc:creator>T=Machine &#187; Austin GDC: Vote for your conference</dc:creator>
		<pubDate>Mon, 16 Jul 2007 19:03:53 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-2952</guid>
		<description>[...] case, the only question is “can we pass step 3?”. “But email providers have captchas, that stop automated account creation!” I hear you cry. Ahem. Even if they did (stop you automatically creating email addresses) the [...]</description>
		<content:encoded><![CDATA[<p>[...] case, the only question is “can we pass step 3?”. “But email providers have captchas, that stop automated account creation!” I hear you cry. Ahem. Even if they did (stop you automatically creating email addresses) the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh's Query</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-2399</link>
		<dc:creator>Josh's Query</dc:creator>
		<pubDate>Fri, 01 Jun 2007 23:31:10 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-2399</guid>
		<description>Greetings &#38; thanks for writing this article ...  it was an excellent read.  It's sad to see how easily captcha security can be defeated.

I just spent an afternoon or so writing an animated gif captcha (check the web site).  I am assuming that decoding a series of pictures would be more difficult than just a flat one, but I don't know that for sure.  

Any chance on getting you to take a look at it from a security perspective and pointing out some of my weak points.  Source is included just in case you need to look around for a break-in point.

Thanks in advance</description>
		<content:encoded><![CDATA[<p>Greetings &amp; thanks for writing this article &#8230;  it was an excellent read.  It&#8217;s sad to see how easily captcha security can be defeated.</p>
<p>I just spent an afternoon or so writing an animated gif captcha (check the web site).  I am assuming that decoding a series of pictures would be more difficult than just a flat one, but I don&#8217;t know that for sure.  </p>
<p>Any chance on getting you to take a look at it from a security perspective and pointing out some of my weak points.  Source is included just in case you need to look around for a break-in point.</p>
<p>Thanks in advance</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: someone</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-346</link>
		<dc:creator>someone</dc:creator>
		<pubDate>Wed, 14 Mar 2007 01:59:24 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-346</guid>
		<description>Actually a better thing to do is ask questions, such as "What is the 3rd letter in this sentance" or "Write the following word below 'y'"

These are harder to defeat by bots (since you can personalise them) as well as being solveable by people who are blind and require a screen reader.</description>
		<content:encoded><![CDATA[<p>Actually a better thing to do is ask questions, such as &#8220;What is the 3rd letter in this sentance&#8221; or &#8220;Write the following word below &#8216;y&#8217;&#8221;</p>
<p>These are harder to defeat by bots (since you can personalise them) as well as being solveable by people who are blind and require a screen reader.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-266</link>
		<dc:creator>Brent</dc:creator>
		<pubDate>Fri, 19 Jan 2007 14:29:47 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-266</guid>
		<description>Zork,

This wasn't about feeling all big, this was to showcase one method someone might go about cracking a CAPTCHA. Hopefully providing some insight on how to design better CAPTCHAs.</description>
		<content:encoded><![CDATA[<p>Zork,</p>
<p>This wasn&#8217;t about feeling all big, this was to showcase one method someone might go about cracking a CAPTCHA. Hopefully providing some insight on how to design better CAPTCHAs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zork</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-259</link>
		<dc:creator>Zork</dc:creator>
		<pubDate>Thu, 04 Jan 2007 21:44:31 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-259</guid>
		<description>You guys don't get it.  Spend this time writing a better CAPTCHA or something else that will provide the same functionality.  I see no talent here in cracking an existing one.  Help out a little and build something usefull, instead of feeling all big because you can crack something you know is obviously crackable.</description>
		<content:encoded><![CDATA[<p>You guys don&#8217;t get it.  Spend this time writing a better CAPTCHA or something else that will provide the same functionality.  I see no talent here in cracking an existing one.  Help out a little and build something usefull, instead of feeling all big because you can crack something you know is obviously crackable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-244</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Wed, 29 Nov 2006 19:54:35 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-244</guid>
		<description>sorry...

http://www.animierte-captcha.de</description>
		<content:encoded><![CDATA[<p>sorry&#8230;</p>
<p><a href="http://www.animierte-captcha.de" rel="nofollow">http://www.animierte-captcha.de</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-243</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Wed, 29 Nov 2006 19:54:10 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-243</guid>
		<description>Look at this captcha - its animated. The whole code is not visible - only a part of it. A visitor can solve the captcha - but no robot.</description>
		<content:encoded><![CDATA[<p>Look at this captcha - its animated. The whole code is not visible - only a part of it. A visitor can solve the captcha - but no robot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Wilkins</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-91</link>
		<dc:creator>Tim Wilkins</dc:creator>
		<pubDate>Sun, 10 Sep 2006 10:23:22 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-91</guid>
		<description>Interesting article, I hope these CAPTCHAs go out of fashion soon, they are a real nusciance.</description>
		<content:encoded><![CDATA[<p>Interesting article, I hope these CAPTCHAs go out of fashion soon, they are a real nusciance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WaltDe</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-85</link>
		<dc:creator>WaltDe</dc:creator>
		<pubDate>Fri, 01 Sep 2006 14:58:07 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-85</guid>
		<description>Very good reading. Peace until next time.
WaltDe</description>
		<content:encoded><![CDATA[<p>Very good reading. Peace until next time.<br />
WaltDe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonymous</title>
		<link>http://bhiv.com/defeating-diggs-captcha/#comment-40</link>
		<dc:creator>anonymous</dc:creator>
		<pubDate>Wed, 19 Jul 2006 21:19:37 +0000</pubDate>
		<guid isPermaLink="false">http://bhiv.com/?p=7#comment-40</guid>
		<description>Quite correct, Brent.  Several organizations use and modify GPL'd software internally, e. g. the US Dept. of Defense.  They don't release their code outside of the organization.  That's one of the freedoms that the GPL provides:  the keeping of your tweaks to yourself if you want.

Thank you for presenting this article.  Security through obscurity is not security at all, and as the Microsofts and Apples of the world continue to prove again and again, it never has been.  The more that we share information, the better armed we all are to defend ourselves against the baddies out there.  The OpenBSD team's work is an excellent example of this, as is the book "Applied Cryptography".  You did a good thing here.</description>
		<content:encoded><![CDATA[<p>Quite correct, Brent.  Several organizations use and modify GPL&#8217;d software internally, e. g. the US Dept. of Defense.  They don&#8217;t release their code outside of the organization.  That&#8217;s one of the freedoms that the GPL provides:  the keeping of your tweaks to yourself if you want.</p>
<p>Thank you for presenting this article.  Security through obscurity is not security at all, and as the Microsofts and Apples of the world continue to prove again and again, it never has been.  The more that we share information, the better armed we all are to defend ourselves against the baddies out there.  The OpenBSD team&#8217;s work is an excellent example of this, as is the book &#8220;Applied Cryptography&#8221;.  You did a good thing here.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
