A proof of concept bypass of Google’s reCaptcha V2 verification system, posted online Tuesday, uses Google’s own web-based tools to pull off the skirting of the system. IT security experts from AlienVault and Positive Technologies commented below.
Chris Doman, Security Researcher at AlienVault:
The current favoured method of Spammers to solve Captcha’s is to pay third world workers tiny wages to solve them manually (http://www.deathbycaptcha.com/).”
Alex Mathews, Lead Security Evangelist at Positive Technologies:
“The whole idea to use speech recognition to fence off the bots is quite outdated, so we don’t recommend using it anyway: modern speech recognition software is good enough to bypass it (even without Google). There exist a lot of different methods that are much harder to bypass. But the main problem here is the same as simple passwords: mass services don’t want to push their customers to “more complex” security measures because it makes their services less accessible.”
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.