<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Return of the Heyes captcha</title>
        <description>Hi all

I've released a new version of my captcha:-
http://www.thespanner.co.uk/2007/07/12/return-of-the-heyes-captcha/

This version works with most likely sentences, for example:- &amp;quot;a creepy forest&amp;quot; not &amp;quot;creepy dog&amp;quot;. The idea is to arrange the sentence in the correct order. Sentences would be different each time and at the moment it only displays 1 sentence.

My future plans include display a hint for the sentence but in a way that could only be understood by a human without mentioning the words in the sentence.

It's early days with the prototype but I really think this one could work.</description>
        <link>http://sla.ckers.org/forum/read.php?7,13630,13630#msg-13630</link>
        <lastBuildDate>Tue, 18 Jun 2013 01:18:11 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,15728#msg-15728</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,15728#msg-15728</link>
            <description><![CDATA[Yeah I'm gonna try a different technique soon. I know the problems of creating one but I just enjoy trying the impossible :)]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Mon, 10 Sep 2007 06:05:49 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,15725#msg-15725</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,15725#msg-15725</link>
            <description><![CDATA[Maybe if you implement dynamic answers instead of dynamic questions it could work. But I am still unsure of the whole thing, I dunno if it's possible.<br />
<br />
If you think about it, in the end everything isn't 100% secure, mouseclicks, keystrokes, voices, pictures and even IRIS-scans are hackable.<br />
<br />
EDIT: typo]]></description>
            <dc:creator>Spyware</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Mon, 10 Sep 2007 04:34:27 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,15700#msg-15700</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,15700#msg-15700</link>
            <description><![CDATA[Spyware Wrote:<br />
-------------------------------------------------------<br />
&gt; You can't make a machine ask a question a machine<br />
&gt; can't answer. It's plain logic. <br />
<br />
Yeah that's the challenge.<br />
<br />
I admit my CAPTCHA wasn't a success, but I haven't given up so expect a new post and I'll expect the backlash :) but hopefully not.]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Sun, 09 Sep 2007 13:59:36 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,15266#msg-15266</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,15266#msg-15266</link>
            <description><![CDATA[You can't make a machine ask a question a machine can't answer. It's plain logic. <br />
<br />
Writing information down on a post-it and slap it on your monitor is safer then let it be guarded by a CAPTCHA.]]></description>
            <dc:creator>Spyware</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Fri, 24 Aug 2007 17:17:04 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,14789#msg-14789</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,14789#msg-14789</link>
            <description><![CDATA[I don't really know what the hope was, but if it was something along the lines of making the user so confused they'll never visit your site again, you have succeeded for sure.]]></description>
            <dc:creator>FiSh</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Sat, 18 Aug 2007 13:44:31 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,13657#msg-13657</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,13657#msg-13657</link>
            <description><![CDATA[Gareth - now you have actually made it impossible for me to solve it to even tell you what's wrong with it.  I think you've failed on two accounts:<br />
<br />
1) you haven't changed the problem, making it easy for robots to use grammar checks still (if they encounter one that's too long they can hit refresh and get a new one).<br />
2) you've made it so difficult to solve I can't even figure out what you want me to do anymore.<br />
<br />
This proving that it is a failed Turing test.  I think it's time for you to stop the madness.]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Thu, 12 Jul 2007 22:46:27 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,13653#msg-13653</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,13653#msg-13653</link>
            <description><![CDATA[We all need to realize CAPTCHAS are fruitless. The bots get smarter the CAPTCHA gets harder, the bots get even smarter and the CAPTCHAS get even harder. But in the end a human being just stays dumb. Make it hard for a bot make it even harder for a human, make it very hard for a bot and make it impossible for the average human.<br />
<br />
CAPTCHAs should only be used to limited protection. If you run a site which gets 15K views a month and you have a custom built forum, then in reality you will not need to have a hard CAPTCHA if one at all, because the chances of someone pointing a bot at your site to break into your account, post spam would be very unlikely. Now if you were running popular software like phpBB then yeah a bot might be more likely to  target you since the bot would likely have the code to break it, but still its lower than if your site was say myspace.com and having CAPTCHA protection would actually be beneficial, but you have to say is it worth it? You are basically turning users away who can't solve them as easily, and the ease of a site determines if a visitor will come back again. Yeah we would all love to shun stupid people, but come on when you want visitors to your site you take all you can get. There are other avenues in protecting a form which will be as effective if not more which would not prohibit the site's use by the average computer illiterate user.<br />
<br />
Just my 2 cents.]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Thu, 12 Jul 2007 22:21:54 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,13652#msg-13652</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,13652#msg-13652</link>
            <description><![CDATA[I've just updated my CAPTCHA version 3.2<br />
<br />
http://www.businessinfo.co.uk/labs/HeyesCaptcha3.2/heyes_captcha_test.php<br />
<br />
It's still early stages but it grabs 2 random sentences from a story stored in a table. Then it displays the first sentence and mixes up the second which is related to the first.<br />
<br />
There are a few problems with it, at the moment it returns either too long or too short sentences sometimes which I need to fix.]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Thu, 12 Jul 2007 20:33:17 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,13651#msg-13651</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,13651#msg-13651</link>
            <description><![CDATA[Glad it helped, but I bet a buck I'll be able to break any changes you make.  CAPTCHAs are simply flawed.  I've looked at hundreds of them and broken every single last one of them.  I don't see any technologies that make me think I couldn't do it (unless you also make it unusable in the process).]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Thu, 12 Jul 2007 20:08:03 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,13646#msg-13646</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,13646#msg-13646</link>
            <description><![CDATA[Yep I know it has major problems and I wasn't suggesting anyone use it at this stage but I have had a couple of thoughts about this and expect a new release shortly.<br />
<br />
Thanks for your great feedback though, the information you provided will be very helpful to me when I create my next release. Stay tuned :)]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Thu, 12 Jul 2007 18:46:10 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,13643#msg-13643</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,13643#msg-13643</link>
            <description><![CDATA[Okay, where to begin?<br />
<br />
Firstly, lots of people will never solve this correctly.  Sorry, it's a fact.  People just aren't very good at solving things.  For instance &quot;Sarah ran through the grassy fields&quot; is proper english, but so is &quot;the Sarah ran through grassy fields&quot; depending on what a &quot;Sarah&quot; is.  Clearly the second is non-nonsensical but not everyone is a native English speaker either, or paying enough attention to what they are doing to get it right.<br />
<br />
Secondly, you have one of the highest probabilities of brute force solving I've ever seen in a CAPTCHA - 1/720 with six words and 1/5040 with seven words.  That's less than a normal CAPTCHA of 4 digit characters.  The numbers listed actually makes an assumption that each word is unique - which in several of your examples they were not (&quot;the&quot; is used twice in the sentences more than once).  In that case your probability of guessing the correct answer skyrockets to 1/120-1/720).  That's worse than a three digit CAPTCHA.<br />
<br />
Third, to actually break this would require only a split second with all possible combinations against a grammar checker since there are so few combinations.<br />
<br />
Fourthly, I can refresh until I get an old (known/solved) CAPTCHA.<br />
<br />
Lastly, since you have to build each sentence you can only have a limited number of sentence structures that are short enough to be easily solvable, making it incredibly easy to build a lookup table of solved CAPTCHAs.<br />
<br />
Sorry, this CAPTCHA has serious security implications.  I'd never implement this as-is.]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Thu, 12 Jul 2007 17:54:29 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,13635#msg-13635</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,13635#msg-13635</link>
            <description><![CDATA[I've just uploaded an update to make it more usable.]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Thu, 12 Jul 2007 16:15:26 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,13631#msg-13631</guid>
            <title>Re: Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,13631#msg-13631</link>
            <description><![CDATA[captcha are becoming too much complicated for human<br />
i keep thinking captcha is not the solution, but well, as long nobody find something way better...]]></description>
            <dc:creator>nEUrOO</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Thu, 12 Jul 2007 15:12:37 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?7,13630,13630#msg-13630</guid>
            <title>Return of the Heyes captcha</title>
            <link>http://sla.ckers.org/forum/read.php?7,13630,13630#msg-13630</link>
            <description><![CDATA[Hi all<br />
<br />
I've released a new version of my captcha:-<br />
http://www.thespanner.co.uk/2007/07/12/return-of-the-heyes-captcha/<br />
<br />
This version works with most likely sentences, for example:- &quot;a creepy forest&quot; not &quot;creepy dog&quot;. The idea is to arrange the sentence in the correct order. Sentences would be different each time and at the moment it only displays 1 sentence.<br />
<br />
My future plans include display a hint for the sentence but in a way that could only be understood by a human without mentioning the words in the sentence.<br />
<br />
It's early days with the prototype but I really think this one could work.]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>Robots/Spiders/CAPTCHAs, oh my</category>
            <pubDate>Thu, 12 Jul 2007 14:27:28 -0500</pubDate>
        </item>
    </channel>
</rss>
