[01:01.170 --> 01:04.890] All right, welcome everyone for the next talk in this track. [01:05.770 --> 01:09.190] H-CAPTCHA profits over people as the CAPTCHA dead by Steven Presser. [01:09.730 --> 01:12.010] So before we begin the talk, just a couple of pieces of business. [01:12.510 --> 01:15.090] Please make sure your phone is on mute while you're in session. [01:15.270 --> 01:16.850] It's important not to interrupt the speakers. [01:17.650 --> 01:19.590] Be sure to stay hydrated throughout the show. [01:19.750 --> 01:24.050] It's very important that we don't have any medical emergencies because you didn't have enough water to drink. [01:24.890 --> 01:28.230] HOPE policy is that please keep your masks on when you're inside the building. [01:28.730 --> 01:31.130] If you need to take it off for a while, just step outside. [01:31.130 --> 01:33.070] You can take it off anywhere outside the building. [01:33.250 --> 01:38.650] But we just like to try and keep everyone convinced that we're doing our best to follow our policy of keeping everyone safe. [01:39.350 --> 01:42.970] There's a fourth unscheduled track that is in the coffee house. [01:42.970 --> 01:48.890] If you want to do a little speech or you want to give a little talk, you can sign up at the information desk. [01:49.230 --> 01:55.690] And they'll give you a time slot and you can go get a little unplanned talk at the coffee house. [01:56.490 --> 01:59.470] Hacker Karaoke tonight is tonight at 10 p.m. [01:59.750 --> 02:00.410] in track one. [02:00.630 --> 02:03.830] So that will be upstairs on the fourth floor in DAC416. [02:04.990 --> 02:06.430] Please join if you can. [02:06.690 --> 02:07.910] I'm sure it will be a lot of fun. [02:08.110 --> 02:10.850] I personally won't be singing, but that's for the best. [02:11.430 --> 02:12.890] And volunteers are welcome. [02:13.110 --> 02:20.770] You know, if you want to volunteer and participate in helping with the organization, the rest of the conference for the next two days, please do. [02:21.070 --> 02:23.210] You can go stop by room 301 to sign up. [02:23.770 --> 02:25.510] We'd really appreciate any help you have. [02:26.150 --> 02:28.990] So with that, we'll move over to Stephen. [02:31.430 --> 02:32.350] So here's Stephen. [02:33.570 --> 02:36.710] He's going to do the talk, Age Captcha, Profits Over People, Is the Captcha Dead? [02:37.050 --> 02:39.210] We will be doing a Q&A session at the end. [02:39.490 --> 02:41.050] We're going to try and find some time for Q&A. [02:41.630 --> 02:42.390] Stephen is remote. [02:42.530 --> 02:44.170] He can't hear you and he can't see you. [02:44.250 --> 02:50.530] So when we get the Q&A session, we're going to turn the mic around and you can just come up and ask questions directly to the mic so he can hear you and interact with you. [02:50.790 --> 02:55.090] We'll also be taking questions through the chat room for this talk. [02:55.790 --> 03:00.110] And the chat room will persist indefinitely and dedicate to this talk. [03:00.290 --> 03:01.590] So with that, over to Stephen. [03:04.070 --> 03:04.350] All right. [03:04.690 --> 03:05.010] Thank you. [03:06.090 --> 03:13.270] So, before we get started, slides with image descriptions and notes are online at pressers.name slash anewhope. [03:13.450 --> 03:18.310] That's P-R-E-S-S-E-R-S dot N-A-M-E slash anewhope. [03:18.730 --> 03:21.830] Other than the dot and the slash, there is nothing in there but letters. [03:23.530 --> 03:24.070] All right. [03:24.350 --> 03:33.290] So, would you believe me if I told you that 15% of the Internet is behind or was behind a capture that couldn't tell a bot from a human? [03:34.230 --> 03:37.070] And what on earth does accessibility have to do with security? [03:37.710 --> 03:40.370] The rest of this talk should start to answer those questions. [03:41.310 --> 03:45.650] However, before I get started and before we really start to dig in, I've got to make a title change. [03:46.530 --> 03:50.570] I've presented part of this work, the part on a product called HCAPTCHA before. [03:51.590 --> 03:56.590] Recently, a high-level technical manager from HCAPTCHA reached out to me and wanted to talk. [03:56.850 --> 03:58.350] I spoke with that person on Monday. [03:58.910 --> 04:02.150] And honestly, it changed some of my views on the company and on the product. [04:02.930 --> 04:04.690] Can't stand behind that old title anymore. [04:04.690 --> 04:08.070] So, I'm changing the title of this talk to, Is the Captcha Dead? [04:08.910 --> 04:12.010] Like all rhetorical questions as titles, the answer is no. [04:12.550 --> 04:16.970] But I really want to convince you that the answer is no, not yet. [04:17.570 --> 04:18.830] But it's going that way. [04:23.450 --> 04:25.590] So, I think that... [04:25.590 --> 04:29.110] And I apologize for some of the roughness around revisions that I've had to do in last week. [04:29.970 --> 04:37.370] After talking with HCAPTCHA, I really do believe that they're trying to strike the best balance they can between a lot of complex requirements in a complex environment. [04:38.730 --> 04:43.830] I can't stand behind Broken because I don't believe I'm in a place to evaluate that anymore, at least not completely. [04:44.490 --> 04:49.870] But I do still want to tell you about some of the work I did with the security of HCAPTCHA in the last year. [04:50.790 --> 04:52.210] So, here's our roadmap. [04:52.570 --> 04:55.950] I'm going to start with some background, mostly on assistive technology and on captchas. [04:56.510 --> 04:59.210] Then I'm going to talk about the work I did on HCAPTCHA itself. [04:59.610 --> 05:05.390] And I'm going to finish with a look at the future, both of HCAPTCHA and of CAPTCHAs as a whole. [05:06.310 --> 05:08.270] So, let's jump into assistive technology. [05:09.470 --> 05:12.930] Disability and assistive technology are going to play a large part here. [05:13.150 --> 05:17.790] So, for those of you who aren't already familiar with assistive technology, let's begin by looking at some. [05:18.570 --> 05:20.910] The use of assistive technology is actually really common. [05:21.250 --> 05:24.490] Many of us are already using assistive technology right now. [05:24.490 --> 05:26.830] You know, your eyeglasses or contact lenses. [05:27.790 --> 05:32.350] However, as useful as these things are, they don't really have a bearing on how we interact with a computer. [05:32.730 --> 05:36.030] So, I want to focus on some assistive technology that does. [05:36.250 --> 05:37.890] Some input and output devices. [05:39.430 --> 05:40.450] Let's start with this. [05:40.690 --> 05:44.830] This is a refreshable braille display with a Perkins-style brailler keyboard. [05:45.070 --> 05:46.930] It's a big mouthful of a name. [05:47.650 --> 05:53.410] This could be used by someone who is blind or visually impaired instead of or in addition to a keyboard and monitor. [05:53.850 --> 06:00.690] So, the paddles at the top are part of the braille input keyboard, while the white dots in the middle are there for reading text. [06:02.330 --> 06:05.170] Another example is a foot-operated keyboard and mouse. [06:05.530 --> 06:09.030] It could be used by anyone who has limited or no ability to use their hands to type. [06:09.230 --> 06:11.090] Somebody who has really severe carpal tunnel. [06:11.430 --> 06:16.910] Someone who has lost a hand for whatever reason, or just doesn't have fine motor skills with their hands. [06:18.590 --> 06:26.350] And next up, there's something called a puff and sip device, which is used by typically someone who is quadriplegic and has no fine motor control. [06:26.870 --> 06:29.850] It can also be used to replace a keyboard and mouse. [06:31.770 --> 06:35.990] And the last piece of assistive technology I want to talk about is called a screen reader. [06:36.570 --> 06:45.790] Screen readers are software used by people who are print disabled, which typically is blind, visually impaired, severely dyslexic, or any of a number of other things. [06:46.730 --> 06:53.410] It outputs on-screen text as speech, as audio, and allows users to navigate just the keyboard if they should choose to do so. [06:54.930 --> 06:59.930] Before we go any further, I want to show you just how different using assistive technology can be. [07:00.150 --> 07:03.590] So what I'm about to play for you is a recording of someone using a screen reader. [07:04.010 --> 07:06.990] I'm first going to play it without the video, and then with the video. [07:07.430 --> 07:08.630] Google dash Google Chrome. [07:08.830 --> 07:09.610] Google document. [07:09.830 --> 07:10.590] Search landmark. [07:11.110 --> 07:13.610] Search combo box has auto-complete editable search blank. [07:19.410 --> 07:20.250] HCAPTCHA. [07:20.250 --> 07:21.090] Accessibility. [07:25.220 --> 07:27.440] Heading level one accessibility links. [07:27.940 --> 07:29.440] Link skip to main content. [07:31.040 --> 07:38.460] Main landmark clickable accessibility dash HCAPTCHA heading level three HTTPS colon slash slash www.captcha.com exit. [07:39.240 --> 07:40.200] Document busy blank. [07:41.660 --> 07:52.060] All right, so before I play that with the video, I want you to think to yourself, if I were using a computer that way, would I know what the user was actually, what the interaction with the computer actually was? [07:53.800 --> 07:55.360] Now let's see it with the video. [07:55.840 --> 07:56.560] Google search [07:59.740 --> 08:02.000] combo box has auto-complete editable search blank. [08:29.200 --> 08:31.480] All right, so think to yourself. [08:32.000 --> 08:33.450] Is that what I thought was going on? [08:34.760 --> 08:42.820] So I also want to emphasize that what I've shown is really only a very small selection of the assistive technology available, and that there are many more options. [08:43.690 --> 08:47.780] Each of the alternative methods has its own various advantages and disadvantages. [08:48.300 --> 08:53.980] For example, a screen reader is really hard to use to skim text, but typing input is really fast. [08:54.500 --> 08:59.380] In contrast, a puff and sip may allow someone to skim quickly, but might be very slow to type. [09:00.340 --> 09:08.120] Assistive technology is really tuned to the person it is assisting and to that person's abilities. [09:08.450 --> 09:14.240] So it's as variable as disability itself, which really is to say very extremely. [09:14.900 --> 09:22.190] Two people with the same capabilities may use entirely different assistive technology because that's just what works for them. [09:23.280 --> 09:28.190] All right, so let's continue background with CAPTCHAs. [09:29.690 --> 09:33.430] CAPTCHAs are small puzzles that are simple for humans to solve and hard for computers. [09:33.790 --> 09:36.380] This is often called AI-hard, human-easy. [09:37.140 --> 09:44.290] They're used to ensure that... or often they're used to ensure that a request for something comes from a human and not any kind of automation or bot. [09:44.840 --> 09:52.960] If you'll bear with me for a little bit of history, CAPTCHA... the term CAPTCHA is a backonym for completely automated public Turing tests to tell computers and humans apart. [09:53.660 --> 09:59.290] The name is from a paper called CAPTCHA using AI-hard problems for security, which was published in 2003. [10:00.240 --> 10:04.360] That paper led directly to ReCAPTCHA, the first version of what you see here. [10:05.000 --> 10:08.880] There were other things that weren't CAPTCHAs first, just they didn't have that name. [10:10.050 --> 10:14.550] ReCAPTCHA was one of the first, if not the first, to actually make CAPTCHAs do useful work. [10:14.980 --> 10:20.160] It got humans to label hard-to-read portions of text in order to train optical character recognition systems. [10:20.820 --> 10:25.120] So, what was particularly brilliant about ReCAPTCHA was how it aligned to diverse problems. [10:25.430 --> 10:31.520] In this case, websites and users wanted to eliminate automation, and the authors of OCR software needed better data. [10:32.320 --> 10:37.430] ReCAPTCHA took these two groups, put them together so they could solve each other's problems in a mutually beneficial way. [10:40.280 --> 10:42.900] ReCAPTCHA was bought by Google, who wanted better OCR. [10:43.520 --> 10:49.780] Eventually, however, machine OCR got to be as good or better than human, making it no longer an AI-hard problem. [10:50.720 --> 10:59.860] So, next, Google looked around for another AI-hard problem, and seems to have settled on object identification and street photography, possibly for their self-driving cars. [11:01.640 --> 11:06.880] And then they've revised ReCAPTCHA once again, into this now familiar, I'm-not-a-robot checkbox. [11:07.180 --> 11:15.060] This tracks the user's behavior on the page, it applies machine learning, and it uses that to make a very good guess about whether the user is human or automation. [11:16.040 --> 11:19.100] Users only ask to solve a puzzle if they look like automation. [11:19.340 --> 11:21.700] Otherwise, you check the box, and you move on with your life. [11:21.800 --> 11:22.740] No need to solve a puzzle. [11:23.560 --> 11:32.320] So, ReCAPTCHA isn't the only CAPTCHA out there, but it is probably one of the best known, and it has tended to be at the cutting edge of CAPTCHAs. [11:33.520 --> 11:39.120] So, with a little bit of history and a little bit of background on CAPTCHAs, let's talk about HCAPTCHA. [11:40.280 --> 11:52.500] HCAPTCHA is a commercial product put out by a company called Intuition Machines Incorporated, or IMI, and it's used to prevent automation on about 15% of the Internet, according to the latest numbers that I could find. [11:53.640 --> 12:00.840] As far as I can tell, mostly that is through their largest customer, Cloudflare, who picked them up around April 2020, which is actually how I heard about them. [12:02.060 --> 12:06.220] Intuition Machines is a blockchain-based data labeling and AI service company. [12:06.540 --> 12:16.340] So, if you're a researcher who has a large set of pictures of modes of transport, and you want to get them labeled with what type of transport is in each picture, you can pay Intuition Machines to get labels attached to each picture. [12:16.940 --> 12:19.720] Intuition Machines crowdsources this via HCAPTCHA. [12:20.640 --> 12:27.700] Theoretically, website owners get paid for running HCAPTCHA, and somehow there's a blockchain in the middle that's entirely not relevant to this talk. [12:29.120 --> 12:33.540] So, Intuition Machines claims on their homepage that HCAPTCHA is three things. [12:33.880 --> 12:36.020] Private, as in they don't track or sell your data. [12:36.740 --> 12:40.080] Secure, as in it keeps out automation and makes sure the user's human. [12:40.620 --> 12:43.320] And faster and lower friction, as in easy for users. [12:46.560 --> 12:48.820] So, how does using HCAPTCHA work? [12:49.980 --> 12:53.040] Let's start by walking through their visual-timed workflow. [12:54.260 --> 13:00.060] I want to emphasize that everything I'm about to talk about about this stuff is how it stood a year ago when I did this work. [13:01.180 --> 13:03.180] There have been some changes to date. [13:03.340 --> 13:05.200] I will be trying to call those out as I go. [13:05.400 --> 13:08.760] I also have a section later on where I will explicitly call those out as changes. [13:10.320 --> 13:12.320] So, you end up on a website. [13:13.020 --> 13:14.620] You start out by filling out the form. [13:14.860 --> 13:16.480] You check the box labeled, I am human. [13:17.260 --> 13:24.920] At this point, the software looks at some criteria and takes a guess about whether or not you might be a bot. [13:25.600 --> 13:37.240] The criteria that the system looks at are an Intuition Machines secret, but there might be things like your IP address, if it's been able to put cookies in your browser before, your behavior on the page, and so on and so forth. [13:37.940 --> 13:40.540] If you look like automation, you get shown a challenge. [13:41.760 --> 13:53.960] My personal experience across HCAPTCHA's website, eBay, again, a year ago when I was doing this, Cloudflare, and some other sites where I've run into it, is that when I see HCAPTCHA, I get a challenge. [13:57.220 --> 13:59.740] HCAPTCHA, at least in part, exists to get data labeled. [13:59.740 --> 14:04.440] So there's something of an incentive to show as many photos as possible to as many users as possible. [14:05.240 --> 14:09.900] Of course, it's also possible that something about my profile is just inherently suspicious. [14:11.100 --> 14:13.460] So, let's continue with this visual-timed workflow. [14:14.520 --> 14:16.440] You'd then be presented a challenge like this. [14:16.620 --> 14:18.280] Select all the images that contain a boat. [14:18.540 --> 14:20.200] You click them, you click Next. [14:20.740 --> 14:23.760] You repeat for a new set of images, you click Verify. [14:23.760 --> 14:31.120] And finally, that modal dialog goes away, box checks, you're certified as human by HCAPTCHA, and on you go. [14:34.050 --> 14:36.890] So, let's say you can't use that visual-timed workflow. [14:37.310 --> 14:39.470] Perhaps you're blind and you can't identify images. [14:39.730 --> 14:42.970] Or you're quadriplegic and you can't select the images quickly enough. [14:43.390 --> 14:45.390] How do you get through HCAPTCHA's challenge? [14:47.010 --> 14:48.950] You use their accessible workflow. [14:48.950 --> 14:53.410] So, let's start walking through that, again, as it stood a year ago. [14:54.290 --> 14:58.070] It starts in the same place, with a form to fill out and the item human box to check. [14:58.310 --> 14:59.330] So, you check the box. [15:00.150 --> 15:01.310] And up pops a challenge. [15:01.650 --> 15:02.890] Well, you can't do it. [15:03.550 --> 15:09.290] If you're lucky, you don't spend a lot of time trying, and instead you start looking for any kind of accessible option. [15:10.610 --> 15:17.030] Eventually, you might find the burger menu in the bottom left-hand corner of that modal dialog, and from there, there's an accessibility menu item. [15:17.270 --> 15:18.030] You click on that. [15:18.830 --> 15:22.290] Brings you to a page where you can put in your email to sign up for accessibility access. [15:22.690 --> 15:23.570] Submit that form. [15:24.210 --> 15:25.650] It says it's going to send you an email. [15:26.150 --> 15:27.290] So, you go check your email. [15:27.650 --> 15:29.630] Eventually, an email that looks like this shows up. [15:30.630 --> 15:31.610] Calling out a change. [15:32.070 --> 15:33.790] There's that thing that looks like a button. [15:33.910 --> 15:34.690] It's actually a link. [15:34.830 --> 15:35.530] It's not a button. [15:36.030 --> 15:43.310] But now they are explicitly putting the text of the URL below it, so that if for whatever reason you can't click a link that looks like a button, you can still get through. [15:44.730 --> 15:46.950] So, it's labeled get accessibility cookie. [15:47.310 --> 15:47.910] You click that. [15:48.690 --> 15:50.470] Which means you do a page that looks like this. [15:50.890 --> 15:51.990] You click set cookie. [15:53.110 --> 15:55.510] And a little notification lets you know that the cookie is set. [15:55.930 --> 16:00.250] When I first tested this, it seemed like that cookie set announcement didn't work. [16:00.350 --> 16:01.270] I was to screen readers. [16:02.190 --> 16:05.950] When HCAPTCHA reached out to me, they told me that this is something that they regularly test. [16:06.530 --> 16:10.230] And now, this week, I have been able to go back and re-verify. [16:10.230 --> 16:10.290] And that's fine. [16:10.550 --> 16:11.770] Today, this works. [16:12.030 --> 16:18.110] The cookie set text announces for your screen reader or browser, you know, whatever software you're using. [16:18.350 --> 16:19.850] At least as far as I was able to test. [16:20.790 --> 16:25.610] So, whatever else may be the case, HCAPTCHA does test for and fix accessibility issues. [16:27.910 --> 16:29.450] Anyway, you have a cookie. [16:29.730 --> 16:32.730] You go back to the form you were working on, which has probably timed out. [16:32.730 --> 16:34.170] So, you fill it in again. [16:34.570 --> 16:35.770] You check the item human box. [16:36.030 --> 16:37.330] And this time, it just works. [16:38.250 --> 16:40.790] This actually seems like a pretty reasonable process, right? [16:41.030 --> 16:47.030] At least to cover the entire gamut of potential assistive technology and disabilities that might have trouble with the visual timed workflow. [16:48.490 --> 16:53.510] The process is seven or eight steps, assuming everything works properly, some of which involve waiting. [16:54.090 --> 16:56.110] The visual timed workflow is three steps. [16:56.590 --> 17:04.690] That's a pretty huge difference, especially in comparison to other captchas, which have accessible challenges that add one or no extra steps. [17:06.050 --> 17:09.370] However, I also need to point out that this is only the first-time workflow. [17:09.670 --> 17:11.110] It does not always take so long. [17:11.750 --> 17:16.810] That cookie is good for some days, once set, so you only have to deal with that dashboard rarely. [17:17.670 --> 17:19.710] In the past, I believe it was 24 hours. [17:19.950 --> 17:22.150] I've been informed by HCAPTCHA that that's not correct. [17:22.970 --> 17:30.230] Once you have that HCAPTCHA email that we talked about earlier, you can always use that to get back to the dashboard, so you get to skip the sign-up process. [17:30.650 --> 17:34.530] That makes this process a lot less painful the second and subsequent times through. [17:36.350 --> 17:38.050] Still, it's pretty painful. [17:39.090 --> 17:47.550] So, let's go back to what HCAPTCHA said it is and mark that it's faster or lower friction, except for people with disabilities. [17:48.950 --> 17:56.790] Now, I've been told by HCAPTCHA that they want to reduce the step count in this workflow, but they didn't really have any specifics about that that they wanted to share with me. [17:58.250 --> 18:03.590] Some other things that they have proposed are very interesting, but I will get to that later on when we talk about the future. [18:05.310 --> 18:10.050] So, there's two big problems in how this workflow works, at least compared to the visual-timed workflow. [18:10.810 --> 18:12.830] We're going to call the first one the privacy problem. [18:14.250 --> 18:17.130] This is a screenshot of HCAPTCHA's accessibility dashboard. [18:17.650 --> 18:19.470] Where are you signing with that link that they send you? [18:20.310 --> 18:26.690] And in that upper right-hand corner, in a red circle, is at least part of the email that I used to sign up for accessibility. [18:28.070 --> 18:28.510] Yeah. [18:29.450 --> 18:31.710] That has some pretty significant privacy implications. [18:32.210 --> 18:39.470] It means that, at least theoretically, every cookie HCAPTCHA hands out via the accessible workflow, they could tie back to a specific email. [18:40.270 --> 18:43.710] Effectively, to a component of the permanent identity of an individual. [18:44.550 --> 18:49.770] Because HCAPTCHA embeds in so many places across the web, they can follow that cookie, and therefore that user. [18:50.670 --> 18:54.110] With most CAPTCHAs, if you don't want to be tracked, you can just wipe cookies. [18:54.930 --> 18:58.090] But not with the accessibility workflow for HCAPTCHA. [18:58.350 --> 19:02.070] Each cookie comes potentially pre-tied to a user identity. [19:03.370 --> 19:12.070] I have been personally assured by the person I spoke to at HCAPTCHA, who I do believe is in a position to know, that their infrastructure doesn't allow them to tie cookies to users. [19:13.010 --> 19:15.390] However, it's not something I can personally verify. [19:15.770 --> 19:23.210] It also doesn't rule out such a tie by third parties, or by them being compelled to tie cookies to identities by a government. [19:25.410 --> 19:27.550] So, let's go back to what they say they are. [19:27.790 --> 19:29.330] We're going to strike privacy. [19:29.330 --> 19:31.850] We're going to say private, except for people with disabilities. [19:32.150 --> 19:38.630] And we're going to put a big question mark after that to indicate that we've been told it's private, but that we are not yet able to verify that. [19:40.450 --> 19:41.750] I said there were two problems. [19:41.950 --> 19:42.730] That was privacy. [19:42.990 --> 19:43.950] Let's deal with security. [19:45.130 --> 19:46.930] I'm not the first person to look at security. [19:47.170 --> 19:56.450] There's a paper called a low-cost attack against the HCAPTCHA system, which used their images as training for machine learning, was able to pass with a 95% success rate. [19:57.830 --> 20:01.250] HCAPTCHA and CloudFlare both dispute the accuracy and methodology of the study. [20:01.590 --> 20:10.130] HCAPTCHA, in particular, say the researchers hit something they call an anti-drain capability, and that passing the CAPTCHA doesn't necessarily mean passing the evaluation of being human. [20:11.510 --> 20:21.690] Basically, what they're saying through their public statement here is that they detected the researchers' automation, they passed them through the CAPTCHA anyway, and that's supposed to work. [20:23.270 --> 20:27.110] As far as I'm aware, there's been no re-evaluation or repetition of this study. [20:28.810 --> 20:30.610] So, take it for what it's worth. [20:30.950 --> 20:32.690] I would call it disputed at this point. [20:34.990 --> 20:38.630] So, we'll go back to what they are, and we'll put a question mark next to secure. [20:39.230 --> 20:44.590] In my opinion, we as members of the public right now really don't have enough information to know the truth there. [20:47.190 --> 20:49.910] So, quick pop quiz before we go into the second problem. [20:50.630 --> 20:53.870] Where does the accessible workflow actually verify that the user is human? [20:54.090 --> 20:54.950] Show of hands, mom. [20:56.030 --> 20:56.850] Yeah, show of hands. [20:58.070 --> 21:00.910] For those...so, A, is it when the user clicks a button? [21:02.430 --> 21:04.530] B, when the user enters their email? [21:05.590 --> 21:08.110] C, when the user opens a link in an email? [21:08.110 --> 21:13.170] Or D, whenever you want, just check the user agent of the browser? [21:14.730 --> 21:18.670] I can't see the room, but those of you who didn't raise your hands were actually the most correct. [21:18.990 --> 21:23.710] There's no part of that process that actually does a verifiable check that you're human. [21:26.050 --> 21:29.630] That means that no part is AI hard, and no part is difficult to automate. [21:30.590 --> 21:36.510] So, this video that I'm about to talk over is of some quick automation I put together to prove that this process can be automated. [21:36.990 --> 21:38.930] It's not anything particularly fancy. [21:39.290 --> 21:43.590] It's just xdo tool, driving the mouse, a little custom Python to run a mail server. [21:44.450 --> 21:50.810] And, as you can see, or will see in a moment, it's perfectly capable of running through the entire accessibility workflow on its own. [21:52.230 --> 21:53.870] Putting this together is actually pretty darn interesting. [21:54.350 --> 22:00.170] When you hit a countermeasure, any part of the system simply kicks back a contact support error. [22:01.230 --> 22:06.490] Debugging without any feedback other than you hit a countermeasure but you can't know what it is is pretty fun. [22:10.810 --> 22:15.150] So, one other thing that was a challenge to me personally was handling this incoming email. [22:16.150 --> 22:19.230] I've never dealt with handling incoming email before in a programmatic way. [22:19.550 --> 22:24.510] And it was originally trying to set up an email server that would pipe the body of the email to a custom Python script. [22:24.790 --> 22:26.250] Which did not work out. [22:27.050 --> 22:34.570] But I can say that Python has a good module called the SNTPD that has got great callbacks for handling incoming email messages. [22:35.990 --> 22:36.550] All right. [22:36.750 --> 22:38.350] At this point, we're going to take another version. [22:38.770 --> 22:43.650] HCAPTCHA does have countermeasures to automation that appear at least to be mostly in the form of rate limiting. [22:44.610 --> 22:47.290] So, at least that I've been able to see and hit myself. [22:48.250 --> 22:52.350] Each cookie that you get from the accessibility workflow can only be used so many times. [22:52.630 --> 22:54.850] Each account only gets so many cookies per day. [22:55.350 --> 22:57.950] Each IP address can only sign up for so many accounts per day. [22:58.150 --> 23:00.390] And each domain can only sign up for so many accounts per day. [23:01.030 --> 23:02.150] But domains are cheap. [23:02.330 --> 23:03.710] Rotating IP addresses is easy. [23:03.710 --> 23:07.390] And so I can't verify how effective these are in the real world. [23:09.750 --> 23:13.050] So, we'll go back to what HCAPTCHA is or was a year ago. [23:13.410 --> 23:16.850] We're going to strike secure and say, except that it appears it can be automated. [23:18.570 --> 23:26.770] HCAPTCHA's initial written response to me, of course, said that I'd most likely been caught in a similar anti-drain capability and was being allowed to pass even though they detected my automation. [23:28.070 --> 23:32.070] This is a pretty convenient answer when researchers start poking your stuff. [23:32.070 --> 23:35.850] We detected you attacking us and we decided to let you believe that you were successful. [23:36.790 --> 23:41.630] As a security researcher, that means that I can't verify either way whether or not I had been successful or not. [23:42.350 --> 23:50.990] So, for now, we're saying it looks like the automation was successful and any true verification would have had to cross the line into real attacks on the system. [23:51.430 --> 23:53.590] Which we can't do as ethical researchers. [23:55.690 --> 24:01.930] So, by now, I hope I've convinced you that their accessibility workflow is or appears to be broken. [24:02.650 --> 24:05.110] All the work I did on it was under the bug bounty program. [24:05.370 --> 24:10.570] So, I've disclosed it to them and I've disclosed it to Cloudflare who run a second instance of the HCAPTCHA software. [24:11.850 --> 24:17.650] Both of them declared that it was not an issue due to the mitigations that they had and declined to disclose. [24:18.230 --> 24:22.610] Or it wasn't an issue due to resources required to circumvent the CAPTCHA. [24:23.950 --> 24:26.950] I'd actually like to give a positive shout out to Cloudflare here. [24:27.330 --> 24:28.470] It's not their software. [24:28.810 --> 24:34.110] They had a pretty well... and they had a very well-written reason for why it wasn't a security issue. [24:34.110 --> 24:36.370] But they still paid out on their bug bounty. [24:37.990 --> 24:39.370] So, I've alluded to it. [24:39.490 --> 24:46.170] But one big question that this raises that I'm not going to focus on is how should bug bounties deal with non-verifiable systems? [24:46.450 --> 24:50.170] Where there isn't a binary between it worked and it didn't work. [24:51.290 --> 24:58.490] And how should that be done, especially when the party responsible for the verification of the security issue is also the one that pays out on the bounty? [24:59.350 --> 25:01.490] This is not a criticism of HCAPTCHA. [25:01.490 --> 25:03.690] This is looking beyond it to the industry as a whole. [25:04.070 --> 25:06.170] So, please take it in that sense. [25:08.130 --> 25:11.550] So, let's talk about what's changed that I haven't already mentioned. [25:12.890 --> 25:17.150] One thing I was told about is something that HCAPTCHA calls their 99.9% mode. [25:17.370 --> 25:21.610] In this mode, the CAPTCHA is entirely invisible unless there's a reason to challenge you. [25:22.290 --> 25:26.950] The name comes from their goal of only challenging a tenth of a percent of legitimate users. [25:27.490 --> 25:29.570] So, when you see HCAPTCHA, congratulations! [25:30.110 --> 25:30.630] You're very lucky. [25:31.750 --> 25:39.610] Now, I haven't been able to verify anything about how well this works or anything like that beyond the text that's on their enterprise-level marketing page. [25:40.350 --> 25:46.570] If you know how to write browser extensions like a monitor for things like this, I'd love to hear from you because that's my next step with this work. [25:47.770 --> 25:54.610] Speaking of HCAPTCHA being often invisible, I was talking about this work with a friend of mine who made a rather brilliant observation. [25:55.930 --> 26:04.970] With HCAPTCHA being invisible, except when it thinks that you're automation, it quickly becomes the annoying thing that always makes you do a stupid puzzle because you only see it when it makes you do a puzzle. [26:05.750 --> 26:15.630] In contrast, HCAPTCHA at least lets you know it's there, which means that when it makes you do a puzzle, it's a little more tolerable because you know that you've passed through it a few times before. [26:18.070 --> 26:23.370] So, other good things that I heard from them, but not being a company insider, can't verify. [26:24.910 --> 26:32.230] First thing that I heard, and I really hope this one is true, their training set for what is human includes users of various assistive technologies. [26:32.810 --> 26:39.490] This implies that these users are not getting picked out as automation, at least because of their assistive technology, I hope. [26:40.910 --> 26:53.030] I was also told that they do run manual testing of their entire system with some frequency, both in-house and via third-party accessibility testing services, though the person I was talking to didn't remember exactly how frequently. [26:55.350 --> 27:00.050] From the point of view of assuring more or less equal access, these are both really great things. [27:00.050 --> 27:08.150] This means that my largest criticism of HCAPTCHA at this moment is that their accessibility workflow is significantly longer than their visual-timed workflow. [27:10.770 --> 27:19.410] So, in the past, in checking some of this over again to see if things are still vulnerable, I thought that they'd shut down their automated registration because I couldn't sign up for accounts. [27:20.130 --> 27:23.490] I was able to run through an accessibility sign-up myself this week. [27:23.750 --> 27:24.550] It does still work. [27:25.290 --> 27:29.850] So, this is a place where I think I hit a countermeasure and was entirely unaware of it. [27:31.130 --> 27:36.830] However, hitting that countermeasure in the past did let me test a more manual process where you get in touch with their support. [27:37.470 --> 27:41.890] In that version, you have to email support and wait for a human support person to handle your ticket. [27:43.190 --> 27:51.170] When they do this, or when I did this, they asked for my IP address, my browser, what website I was on, and what about HCAPTCHA didn't work for me. [27:51.950 --> 27:57.530] As someone who wrote an email saying, hi, I need to sign up for an accessibility account, that aspect is particularly critical. [27:58.250 --> 28:01.970] It doesn't quite require disclosing a disability, but it does get pretty close. [28:02.750 --> 28:06.590] The thing I can't see the photos isn't the same as saying I'm blind, but it has the same effect. [28:07.710 --> 28:11.710] All that said, I've been told that this is a place that they are willing and trying to improve. [28:11.890 --> 28:17.770] I've been told that they have changed how they ask this question, and they have been asked for feedback on how to better ask the question. [28:18.350 --> 28:23.850] So, if you have thoughts on this, I would also love to hear those thoughts because I can convey them through to HCAPTCHA themselves. [28:25.990 --> 28:27.690] So, enough about HCAPTCHA. [28:28.070 --> 28:30.010] Let's take a step back and look at the bigger picture. [28:31.490 --> 28:34.470] How'd this design come to... well, okay, a little more about HCAPTCHA. [28:34.550 --> 28:35.470] How did this come to be? [28:36.110 --> 28:40.230] I want to be clear that this section is derived entirely from their public writings. [28:40.530 --> 28:47.190] Despite my opportunity to talk to them, I did not ask them about how to do... about their engineering process. [28:47.570 --> 28:48.990] No private information. [28:49.970 --> 28:51.790] So, HCAPTCHA is a data labeling service. [28:52.250 --> 28:53.570] They need data to label. [28:54.630 --> 29:00.090] Computers typically put out only audio and visuals, not so much for the other senses. [29:00.090 --> 29:04.570] So, CAPTCHAs will tend to be either audio or visual CAPTCHAs. [29:05.730 --> 29:13.470] Most CAPTCHA services that provide any kind of accessibility provide it as an alternative audio capture for those who cannot complete visual CAPTCHAs. [29:14.630 --> 29:27.470] Each CAPTCHA, or at least their support folks, believe, and this is a direct quote, that audio options provide virtually no security, end quote, and that Google's recapture disables audio CAPTCHAs if it believes traffic is suspicious. [29:28.470 --> 29:35.670] I found no evidence for the part about recapture disabling audio CAPTCHAs, despite a ton of questions across the Internet asking how to do that. [29:36.890 --> 29:44.230] So, I think that this belief that audio CAPTCHAs are low security is what led HCAPTCHA to choose to do a visual-only CAPTCHA. [29:44.370 --> 29:45.970] After all, it will be very high security. [29:47.290 --> 29:50.270] But somewhere along the way, someone realized they need to make this accessible. [29:51.290 --> 29:56.570] To their credit, it really does appear that they implemented this accessible workflow before launching the product. [29:57.510 --> 30:07.410] However, discovering the accessibility requirement might have been a good time to step back and reconsider no audio CAPTCHAs or at least the level of difficulty and involvement that is involved in their accessibility workflow. [30:09.630 --> 30:16.750] So, somehow, they came through and came up with this long accessibility workflow in order to avoid audio CAPTCHAs. [30:17.970 --> 30:20.190] So, it doesn't quite work. [30:20.450 --> 30:21.050] What's next? [30:23.370 --> 30:28.290] Outside of the current state, HCAPTCHA says they're moving to a new text-based challenge system. [30:28.290 --> 30:37.310] This is the system I alluded to earlier that's both accessible and protects the privacy of users of accessible workflows as much as the other users. [30:38.370 --> 30:39.530] Let me rephrase that. [30:39.890 --> 30:43.610] This workflow will be equally private to the other workflow. [30:45.150 --> 30:50.750] So, this workflow, text-based challenges, has you answer questions like this one. [30:50.910 --> 30:51.990] What object can tell time? [30:52.230 --> 30:54.170] And makes its determinations based on that. [30:55.130 --> 31:04.990] The person I spoke with at HCAPTCHA said, direct quote, Ensuring that this translates well in every language, cultural context, and device state across our scale is a daunting task, end quote. [31:05.670 --> 31:06.810] And I believe it. [31:06.910 --> 31:09.150] This has a lot of challenges around culture and language. [31:10.030 --> 31:14.530] However, if this is done well, it's going to be amazing for certain populations with disabilities. [31:15.070 --> 31:20.430] It's one of the very few, if not the only, CAPTCHA that would actually be accessible to people who are deafblind. [31:21.570 --> 31:22.890] It could be bad for others. [31:23.050 --> 31:24.630] For example, those who are cognitively impaired. [31:25.430 --> 31:27.350] In some ways, it's a game changer. [31:27.790 --> 31:33.470] And once it rolls out, it means HCAPTCHA is going to be the best CAPTCHA on the market in terms of accessibility and privacy. [31:33.870 --> 31:37.130] Or in terms of accessibility, privacy, and the combination of both. [31:38.490 --> 31:42.690] Enough so that once this rolls out, I will recommend using them. [31:44.310 --> 31:47.070] HCAPTCHA has told me that they are still actively working on this. [31:47.250 --> 31:48.030] This is in beta. [31:48.310 --> 31:50.290] And it's something that customers can opt into. [31:50.290 --> 31:51.630] For their CAPTCHAs. [31:51.790 --> 31:59.070] So if anybody in the audience is an HCAPTCHA customer, and you're not using this, please, please, please, go in, turn it on. [32:01.210 --> 32:06.110] And, excuse me, go in, turn it on, and make sure it's available for the users of your website. [32:07.470 --> 32:13.350] I've been told that this has been in beta for about eight or nine months. [32:13.350 --> 32:20.870] It should be rolling out in the next few months, depending on the current uptake and how that affects the speed of their ability to validate the dataset. [32:22.430 --> 32:24.570] So, closing thought on HCAPTCHA. [32:24.830 --> 32:31.310] They are really close to being a best-in-class, accessible, effective, and privacy-first anti-automation product. [32:32.090 --> 32:42.570] Once that text-based challenge rolls out for all of their CAPTCHAs, they are going to be the best product out there for things that are accessible, effective, and privacy-first for protection from automation. [32:43.210 --> 32:44.450] So watch for that to happen. [32:45.130 --> 32:47.530] Okay, now I'm really done with HCAPTCHA. [32:47.650 --> 32:48.370] What about others? [32:49.190 --> 32:57.130] We're starting to see decoupling of automation detection from AI-hard problems in order to other methods of differentiating human from automation. [32:57.810 --> 33:01.910] So this raises the question, do we continue using AI-hard human-easy problems? [33:02.470 --> 33:04.230] What do we do when these are exhausted? [33:04.530 --> 33:07.890] And are there other, more effective ways to handle automation on the Internet? [33:08.370 --> 33:11.330] And how will any future solution interact with accessibility? [33:13.430 --> 33:15.130] So let's start with what I wouldn't use. [33:15.790 --> 33:18.090] Nothing that is a visual-only CAPTCHA. [33:19.070 --> 33:21.310] You know, type the letters, type the numbers, whatever. [33:21.730 --> 33:24.230] These are just inaccessible for certain people. [33:25.010 --> 33:27.390] And they're easily solved by automation at this point. [33:27.770 --> 33:30.510] So they're providing pretty minimal security, if any. [33:31.490 --> 33:35.590] At this point, I would like to take the opportunity to call out an Internet darling. [33:36.650 --> 33:37.130] Wikimedia. [33:37.130 --> 33:39.750] They use one of these CAPTCHAs, visual-only. [33:40.250 --> 33:44.970] They've also got a bug that's 16 years old, pointing out that it's inaccessible. [33:45.550 --> 33:46.470] People have written code. [33:46.610 --> 33:48.070] People have written whole new CAPTCHAs. [33:48.350 --> 33:51.550] They've even considered moving to age CAPTCHA, but they haven't changed that. [33:52.110 --> 33:55.690] As far as I can tell, this is simply due to lack of institutional will. [33:56.510 --> 34:00.190] Instead, they come up with a process where users reach out to admins manually. [34:01.330 --> 34:04.590] Similar to a lot we talked about with age CAPTCHA, but even longer, even worse. [34:06.630 --> 34:08.410] So, other things I wouldn't use. [34:08.750 --> 34:11.070] Anything that is this slide-the-puzzle-piece CAPTCHA. [34:11.630 --> 34:16.170] As simple as they look, if they're not providing an alternative, they exclude anyone who can't operate a mouse. [34:16.990 --> 34:25.230] And many of them are built by companies that are located in places without strong disability access laws, so don't expect to see any accessible options from them soon. [34:27.310 --> 34:34.250] So, all of that is a long way of saying, HCAPTCHA is actually one of the better CAPTCHA options when you're examining security, accessibility, and privacy. [34:34.770 --> 34:38.950] They've at least thought about accessibility, which is more than going to be said for many of their competitors. [34:39.750 --> 34:43.490] They've got a very strong story around privacy, if you can use the visual-timed workflow. [34:44.050 --> 34:51.170] In my current estimation, with accessibility as the top priority, they are the second-best CAPTCHA currently available. [34:51.170 --> 34:55.350] And again, as soon as that text-based challenge rolls out, they will be the best. [34:56.410 --> 35:06.230] Honestly, the fact that they're so close to being the best is what makes it all the more frustrating that their accessibility is currently so long and, in my opinion, problematic. [35:08.850 --> 35:19.750] We've already talked about reCAPTCHA and the I'm not a robot checkbox, so looking more towards the future, this represents another option, using patterns and machine learning to determine if a user is automation or human. [35:20.410 --> 35:26.090] However, there's always going to be marginal cases which have to fall back to something if you're using only machine learning. [35:26.670 --> 35:29.990] Probably that means falling back to one of these AI-hard, human-easy problems. [35:30.910 --> 35:44.450] It increases the difficulty of circumventing the CAPTCHA, because now the automation has to at least behave like a human, have a full browser probably, operate at human speed, but this doesn't actually stop automation, it just slows it down. [35:45.690 --> 35:48.270] So at this point, I want to make my radical proposal. [35:48.690 --> 35:51.390] The age of the CAPTCHA is over, it's time to replace it. [35:51.930 --> 35:53.270] I base this on two things. [35:53.590 --> 35:56.610] First, shrinking category of AI-hard, human-easy problems. [35:56.970 --> 36:02.570] Quite frankly, I think we're just running out of problems in this class as AI becomes better and better at solving more and more problems. [36:03.410 --> 36:10.090] Second, quite honestly, the fact that CAPTCHA farms exist means that these CAPTCHAs aren't even particularly reliable today. [36:10.330 --> 36:11.630] We've got humans solving them. [36:12.150 --> 36:17.190] Some sources have even placed the cost as low as a dollar for a thousand solves of CAPTCHAs. [36:18.770 --> 36:20.690] So, what's next? [36:21.030 --> 36:22.490] CAPTCHAs are used for a lot of purposes. [36:23.050 --> 36:25.470] Broadly speaking, I split these into two categories. [36:25.950 --> 36:29.010] There are bot prevention and there's data integrity protection. [36:30.750 --> 36:35.270] Bot prevention includes a lot of things, but primarily it's about the fairness of resource usage. [36:35.670 --> 36:40.830] In this case, websites are showing a CAPTCHA if users are doing something that may be unfair to other users. [36:40.830 --> 36:47.530] For example, if they're requesting too many pages too quickly, trying to log in too often, which might be an attempt to guess passwords. [36:48.730 --> 36:52.330] In this case, CAPTCHAs are often a primitive form of rate limiting. [36:52.790 --> 36:54.990] So, why not go straight to actual rate limiting? [36:55.830 --> 37:03.930] As a living example of this, Project Gutenberg is perfectly happy for you to download their full library as long as you do it slowly enough not to impact other users. [37:04.550 --> 37:07.910] They actually hand out a curl command line to allow users to do that. [37:09.510 --> 37:14.010] Data integrity protection is more about making sure that only good data is getting into systems. [37:14.690 --> 37:15.570] Spam protection. [37:16.490 --> 37:21.250] This is a much harder problem partially due to the flexible nature of what is and isn't spam. [37:21.970 --> 37:24.950] A post about photo editing software on a photography forum? [37:25.230 --> 37:26.310] Probably not spam. [37:26.910 --> 37:28.430] On a knitting forum? [37:29.070 --> 37:29.770] Probably spam. [37:30.810 --> 37:37.110] The nerd in me wants to suggest AI as the solution to this, but honestly, it's probably too complicated for most sites to set up. [37:37.110 --> 37:46.610] Absent someone creating a really good way of building user-friendly, generalized AI anti-spam systems, which is a tall order. [37:47.850 --> 37:48.890] Problem is complicated. [37:49.350 --> 37:52.730] If a site or service requires payment, you could require a valid credit card. [37:52.910 --> 37:55.690] If not, perhaps a valid email from a trusted provider. [37:56.630 --> 38:00.790] But what these solutions have in common is making the validation of the user someone else's problem. [38:01.270 --> 38:05.610] If you're thinking that sounds like it might be federated or social, Simon, it kind of does to me too. [38:06.990 --> 38:14.630] Beyond this, I'm not honestly sure what you can do beyond paying a company to do this determination for you. [38:17.990 --> 38:23.230] Basically, I'm not sure what a website owner without a high degree of technical expertise can do. [38:24.810 --> 38:28.150] Personally, though, I'm beginning to think something hardware-based is the way to go. [38:28.610 --> 38:30.190] And it turns out I'm not alone. [38:31.210 --> 38:35.190] Cloudflare rolled out something that they call cryptographic attestation of personhood in 2021. [38:35.750 --> 38:39.190] This uses FIDO security keys in order to verify the user. [38:39.810 --> 38:46.150] Cloudflare claims that this lets you anonymously test to be a real person, being a real person, without having to solve any puzzle. [38:46.490 --> 38:47.750] And it takes about five seconds. [38:47.990 --> 38:52.790] Basically, you have a FIDO key, it challenges you, you press your button, and off something goes. [38:53.710 --> 39:00.510] And they don't get any more information than you are one of the keys in a set of no smaller than 10,000. [39:01.970 --> 39:03.730] However, it's pressing a button. [39:03.730 --> 39:06.850] It's vulnerable to what Cloudflare calls the drinking bird attack. [39:07.830 --> 39:12.790] Basically, these tokens verify that a button is being pushed, not that there's an actual human there pushing the button. [39:13.910 --> 39:15.190] To Cloudflare, this isn't an issue. [39:15.390 --> 39:23.810] They point out that the attestation process on the devices, which includes some public key cryptography, takes long enough that it's actually slower than most modern Hatcher farms. [39:24.390 --> 39:30.170] So therefore, this method may not perfectly prevent automation, but it does slow it down compared to current solutions. [39:32.410 --> 39:37.270] As I was prepping this talk, I was thinking, that's really neat, but why do I need a separate device? [39:37.530 --> 39:39.950] Why not build this into the laptop or the phone? [39:40.910 --> 39:43.290] As it turns out, Cloudflare got there first. [39:43.290 --> 39:47.690] On June 22nd this year, they rolled out something they called private access tokens. [39:48.310 --> 39:50.610] For now, this only works with Apple devices. [39:51.270 --> 39:56.530] However, what it does is allow the attestation of personhood without any dedicated device. [39:57.130 --> 40:01.770] In this process, you go somewhere, Cloudflare asks Apple to attest to your device. [40:02.530 --> 40:06.010] Cloudflare learns your IP address and what web page you want to visit, but no device IDs. [40:06.690 --> 40:11.430] On the flip side, Apple learns the device IDs, but nothing about what website you want to visit. [40:12.610 --> 40:17.750] In Cloudflare's estimation, this is quicker and more privacy-protecting than their previous solutions. [40:18.710 --> 40:24.010] And it's built using open standards, so expect other manufacturers to start providing it soon, I hope. [40:24.690 --> 40:35.230] The person I spoke with at HCAPTCHA said that they actually have hooks built in for protocols like this, and they're hoping to roll this same private access token out to their customers shortly. [40:35.550 --> 40:37.030] I think it was private access token. [40:38.490 --> 40:43.290] Nor is HCAPTCHA alone, or Apple, or Cloudflare. [40:43.470 --> 40:56.050] It seems there are indicators that most or all of the major players in the attestation of personhood or the CAPTCHA space, including Apple and Microsoft, are looking at things like this, where you don't have to do anything. [40:57.070 --> 41:00.770] So, basically, zero interaction verification of humanity. [41:02.190 --> 41:04.270] So, let's come back to accessibility. [41:04.590 --> 41:05.610] How does this relate to that? [41:06.070 --> 41:10.730] Well, a lot of these hardware-based solutions are minimal or no interaction. [41:11.250 --> 41:13.650] This actually works out really well for people with disabilities. [41:13.650 --> 41:18.750] If you don't need to interact with a device, it's inherently equally accessible to everybody. [41:20.350 --> 41:26.530] Minimal interaction, like the ones that require pressing a button, could still be a problem for some people, such as people who are quadriplegic. [41:27.110 --> 41:31.510] So, I'd like to see manufacturers make tokens that are usable by those people. [41:32.730 --> 41:38.710] So, given the option, though, I'd really recommend going with some kind of zero interaction attestation protocol. [41:39.470 --> 41:43.550] It's inherently accessible and will reduce friction for users at the same time. [41:44.390 --> 41:45.810] Basically, it's a win all around. [41:47.170 --> 41:54.050] Finally, to wrap up this section on the future, I believe the CAPTCHA, at least in the form of solving a puzzle, is going away. [41:54.790 --> 41:56.730] It's just a matter of when and how. [41:57.470 --> 42:07.810] A future where automation doesn't flood the Internet with spam, your device can automatically be verified completely privately, and you never see a CAPTCHA, sounds pretty darn nice, doesn't it? [42:09.030 --> 42:14.230] Alright, as I wrap up, we can go on towards questions, and then you all go on towards your next talks. [42:14.430 --> 42:15.630] What do I want you thinking about? [42:16.490 --> 42:17.170] Three things. [42:17.550 --> 42:21.290] First, when doing design, make sure you're considering all users and requirements. [42:22.090 --> 42:27.750] Adding accessibility at the end is probably part of what made HCAPTCHA's process take so long. [42:29.290 --> 42:31.610] Second, be aware of what happens at the margins. [42:31.910 --> 42:33.830] I spoke a lot about human-easy problems. [42:34.150 --> 42:36.470] But for whom are these problems actually easy? [42:36.730 --> 42:37.970] Is it actually all humans? [42:38.990 --> 42:43.830] Every design decision that is made is a trade-off, even the ones you think probably aren't. [42:44.550 --> 42:48.150] A fancy searchable drop-down box might be inaccessible to a screen reader user. [42:48.150 --> 42:53.870] So for every decision that you're making, consider who's at the margins and how that decision is affecting them. [42:54.750 --> 42:57.550] Third, design for a mainstream that works for everyone. [42:57.810 --> 43:05.290] When it comes to accessibility, trying to create and maintain parallel workflows or products is a pretty good way to end up breaking your entire system. [43:05.990 --> 43:11.910] And if it helps to think of it this way, in accessibility, separate is never equal. [43:14.010 --> 43:17.050] And at this point, I am very happy to answer your questions. [43:19.650 --> 43:20.230] All right. [43:20.430 --> 43:24.590] So if anyone has any questions, go ahead and go up to the mic and you can ask him directly and he'll be able to hear you. [43:24.830 --> 43:27.950] I don't know if anyone has any questions for Stephen today. [43:32.200 --> 43:35.380] We also don't have any questions on the chat, Stephen. [43:35.760 --> 43:37.720] We've got one typing on the chat. [43:37.960 --> 43:39.260] Yeah, I see that right now. [43:55.070 --> 43:55.830] Still typing. [43:58.830 --> 44:00.610] Gives everybody in the room a chance to think. [44:08.040 --> 44:17.580] On a personal curiosity, are there any other strategies that are being explored in terms of this type of validation outside of text and visual and sound based? [44:20.180 --> 44:24.880] The hardware based tokens are the biggest one that I'm aware of. [44:31.210 --> 44:38.930] Honestly, I would say at this point, there seems to have been something of an industry realization that the capture as it stands as a puzzle isn't the way of the future. [44:40.350 --> 44:44.250] And it seems like every time I turn around, there's somebody proposing something new. [44:45.890 --> 44:51.870] So while I can't think of anything else that isn't hardware based right now, I'm sure there's something out there. [44:53.010 --> 44:55.450] All right, we have the question in the chat. [44:55.810 --> 44:59.570] You talked about would be accessible privacy first captchas, but with caveats. [45:00.150 --> 45:04.410] What do you recommend for one right now before the next generation solutions come online? [45:05.970 --> 45:07.750] Okay, yes. [45:08.550 --> 45:22.010] So, right now, I think if you want a captcha that is accessible, that is verifiably private, or at least privacy first, there really isn't a perfect solution on the market. [45:28.920 --> 45:34.740] For accessible, anything that's providing both visual and an audio should be good enough. [45:37.680 --> 45:43.880] With the knowledge that the first time through age capture is very high friction, you can certainly consider them. [45:44.200 --> 45:50.300] I think they're doing a... they're trying, is what I will say. [45:51.420 --> 46:00.000] But I really do want to emphasize that when age capture comes online, brings their tech space challenge online, they will be the clear winner. [46:00.240 --> 46:01.480] There will be no question about it. [46:01.600 --> 46:05.200] If you want to capture after that's online, go to age capture. [46:05.500 --> 46:06.660] They will be accessible. [46:07.020 --> 46:08.320] They will be privacy first. [46:08.640 --> 46:10.360] They will be verifiably private. [46:10.640 --> 46:13.980] If you want to dig through the protocols and run a browser extension. [46:15.100 --> 46:18.000] And they're going to have that for all of their users. [46:18.000 --> 46:28.480] So it won't matter if you're someone who needs assistive technology or someone who doesn't, you will have the same level of experience with their CAPTCHA once that tech space challenge is online. [46:30.660 --> 46:31.560] Another question. [46:31.720 --> 46:39.380] What are some affordable options for people who want to implement CAPTCHAs on their personal sites or for something, you know, a small project? [46:39.540 --> 46:43.280] Are there affordable options or free options that are useful? [46:44.780 --> 46:45.280] Yes. [46:45.840 --> 46:49.220] Both HCAPTCHA and ReCAPTCHA, I believe, have free options right now. [46:51.420 --> 47:00.020] If you're looking for something that's self-hosted, I'm afraid I don't have a good answer for you just because I haven't done sufficient research into self-hosted CAPTCHAs. [47:00.980 --> 47:04.800] Mostly, I've honestly been focused on the commercial side. [47:08.660 --> 47:09.020] Excellent. [47:09.200 --> 47:12.080] Well, are there any other questions from the room or from the chat? [47:17.060 --> 47:19.540] Well, it looks like we might have another question coming in on the chat. [47:30.530 --> 47:31.490] Thoughts about privacy pass? [47:31.490 --> 47:32.750] Thoughts about privacy pass? [47:32.750 --> 47:32.770] Privacy pass? [47:34.690 --> 47:37.270] I haven't dug into the crypto privacy pass. [47:37.810 --> 47:47.350] So, with that caveat, privacy pass is a little complicated right now, in my opinion. [47:47.910 --> 47:54.730] The reason I say it's complicated right now is that it works quite well if you can use the visual time workflow. [47:56.690 --> 47:59.030] I actually went back and re-verified this week. [47:59.310 --> 48:04.130] Right now, with the accessible workflow that I just talked about, it doesn't work. [48:04.250 --> 48:05.870] So, you cannot use privacy pass. [48:07.170 --> 48:14.230] And if you... I have seen some sites that have their beta of the text-based challenge. [48:14.570 --> 48:14.910] Excuse me. [48:15.190 --> 48:16.930] HCAPTCHA's beta of the text-based challenge. [48:19.070 --> 48:22.450] But privacy pass's challenge for CAPTCHA is not one of them. [48:25.070 --> 48:30.910] So, right now, privacy pass is useful if you can use the visual time workflow. [48:31.530 --> 48:44.930] If you can't, then that's... in all honesty, that's a place where right now HCAPTCHA is impacting the privacy of people who need to use the accessible workflow in a negative way. [48:47.430 --> 48:51.970] So, complicated feelings, complicated answer. [48:52.250 --> 48:58.150] That boils down to... they need to turn on the text-based challenge for privacy pass. [48:58.470 --> 49:01.270] And once that challenge is turned on, have at it. [49:01.490 --> 49:05.810] Verifiably private, you know, blinded tokens is a great thing. [49:06.110 --> 49:09.550] It just needs to be actually accessible before I can fully recommend it. [49:12.270 --> 49:12.830] Excellent. [49:13.050 --> 49:13.410] All right. [49:13.410 --> 49:15.290] Well, thank you so much for your time, Steven. [49:15.470 --> 49:16.730] We really enjoyed your presentation. [49:17.650 --> 49:18.190] Thank you. [49:19.230 --> 49:30.830] And if anyone wants to follow up with Steven, again, the Matrix chat will be open for the rest of the conference and beyond, so you can interact directly with Steven for any further questions or any materials from his presentations for the chat. [49:31.570 --> 49:33.110] And so, thank you again, Steven. [49:33.110 --> 49:36.190] Come back in ten minutes for the next chat. [49:36.350 --> 49:39.330] Botnets are the best way to measure user-hostile behavior on the Internet. [49:39.870 --> 49:41.350] Thank you for attending. [49:41.350 --> 49:41.530] lots of learning. [49:41.970 --> 49:42.330] Probably, thanks to the risks of