Hacker News new | past | comments | ask | show | jobs | submit login

I always figured that CAPTCHAs worked because they limited on a resource that was harder to steal - human attention.

Rate limit by IP, and you get attacked by a botnet that "steals" IP addresses with malware.

Rate limit by PoW and you get people stealing AWS accounts, or using aforementioned botnet. See bitcoin mining.

Rate limit by CAPTCHA and you have to get a lot more clever (see things like setting up porn sites and proxying CAPTCHAs there)

So while you can pay to have CAPTCHAs solved, you actually DO have to pay and can't just steal your way in, so it means your target has to be more valuable.




> So while you can pay to have CAPTCHAs solved, you actually DO have to pay and can't just steal your way in, so it means your target has to be more valuable.

None of these things you listed above are available for free. They all require either effort to obtain or paying someone to do the work.


Someone did the math down thread: https://news.ycombinator.com/item?id=37056504

Unless you set your challenge to many minutes of work, you are not competitive with the human-centric solutions.


Can you steal AWS accounts with no effort?

And keep stealing them after you get blocked on the first ones?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: