photog.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for your photos and banter. Photog first is our motto Please refer to the site rules before posting.

Administered by:

Server stats:

245
active users

#captcha

1 post1 participant0 posts today
Replied in thread
Subject: #captcha

It gets better. This year, PayPal has phased in captchas that work as follows: You're presented with a grid similar to the one that you've posted. But you're asked to pick the objects that will sound alike if you drop them on the floor.

No, the objects aren't clearly identifiable. Is a thin cylinder a pencil? Is it a straw or a presentation pointer? Lord only knows.

PayPal seems to have compromised after complaints. That captcha now appears, for me, mostly when my IP address changes. But, seriously, WTH.

#OpenAI’s #ChatGPT Agent casually clicks through “I am not a robot” #verification test

"This step is necessary to prove I'm not a bot," wrote the bot as it passed an anti-AI screening step.

by Benj Edwards – Jul 28, 2025

"Maybe they should change the button to say, 'I am a robot'?

"On Friday, OpenAI's new ChatGPT Agent, which can perform multistep tasks for users, proved it can pass through one of the Internet's most common security checkpoints by clicking #Cloudflare's anti-bot verification—the same checkbox that's supposed to keep automated programs like itself at bay.

"#ChatGPTAgent is a feature that allows OpenAI's #AIAssistant to control its own web browser, operating within a #sandboxed environment with its own virtual operating system and browser that can access the real Internet. Users can watch the AI's actions through a window in the ChatGPT interface, maintaining oversight while the agent completes tasks. The system requires user permission before taking actions with real-world consequences, such as making purchases. Recently, Reddit users discovered the agent could do something particularly ironic.

"The evidence came from Reddit, where a user named "logkn" of the r/OpenAI community posted screenshots of the AI agent effortlessly clicking through the screening step before it would otherwise present a #CAPTCHA (short for "Completely Automated Public Turing tests to tell Computers and Humans Apart") while completing a video conversion task—narrating its own process as it went.

"A screenshot of OpenAI ChatGPT Agent showing the bot writing "The link is inserted, so now I'll click the 'Verify you are human' checkbox to complete the verification on Cloudflare. This step is necessary to prove I'm not a bot and proceed with the action."

"The screenshots shared on Reddit capture the agent navigating a two-step verification process: first clicking the "Verify you are human" checkbox, then proceeding to click a "Convert" button after the Cloudflare challenge succeeds. The agent provides real-time narration of its actions, stating "The link is inserted, so now I'll click the 'Verify you are human' checkbox to complete the verification on Cloudflare. This step is necessary to prove I'm not a bot and proceed with the action."

arstechnica.com/information-te

Evolution of robots. Concept of replacing people with robots, artificial intelligence.
Ars Technica · OpenAI’s ChatGPT Agent casually clicks through “I am not a robot” verification testBy Benj Edwards

@404media says "wild goose chase" diverters for #AI #scrapers use too many resources and don't affect the AI sewer very much. In addition, the scrapers have solved #CAPTCHA" so those just waste everyone's time.
According to the article, #Anubis is an #OpenSource program which requires browsers to complete a #JavaScript test which is already done routinely. It says this test would be overwhelmingly burdensome for scrapers if they had to do it on multiple websites.
404media.co/the-open-source-so

404 Media · The Open-Source Software Saving the Internet From AI Bot ScrapersAnubis, which block AI scrapers from scraping websites to death, has been downloaded almost 200,000 times.

What bothers me nowadays:
- #Ads now are always meant to be targeted, based on as much and as private data possible. #Marketeers and companies make us believe it’s either targeted ads or they can’t survive and offer their services. They ignore that there is another way. And they want us to believe there is none.
- That it appears to me that all companies now want to earn money with ads and/or collecting and selling data. Sometimes I would like them to focus on the product and not on how they can collect data. If my toaster only works with ads on the display or with a cloud account, I think it tells a story. If your oven only works with a #Captcha, I think it’s too far and too late. And don’t forget: The cost for ads has an impact on the price of the product.
#privacy #security

Also ich möchte ja immer alle Probleme der Menschheit ein für alle mal lösen. Ich habe jetzt eine Lösung für das #EScooter-Problem gefunden.

Ihr kennt doch sicher alle diese #Captchas, bei denen wir irgendwelchen KI-Fuzzis helfen, zu lernen, was Zebrastreifen oder Busse sind. Ab morgen wird diese Art Captcha durch Escooter-Bilder ersetzt und man muss seine Menschlichkeit dadurch beweisen, dass man das Bild auswählt, auf dem der EScooter sinnvoll geparkt ist.

Das hat einen Erziehungseffekt und auch den Vorteil, dass unbelehrbare Idiot*innen von allen möglichen Angeboten ausgeschlossen sind.

Anbei zwei Beispiele. Ihr könnt schon mal testen, ob Ihr reinkämet.

reCAPTCHA: Verify you are human by selecting all images below that match this species <AI-slop image of a dog>.
Me: bulldog, chihuahua, something with fur and sunglasses that looks as though it's escaped from a David Cronenberg film, avocado. <laugh-groans awkwardly and clicks the "Submit" button>
reCAPTCHA: Excellent, human, you may proceed!

Social media post I wrote for my employer on other platforms.

2025-04-04 (Friday): Injected #KongTuke script in pages from legitimate but compromised websites leads to fake #CAPTCHA style pages and #ClipboardHijacking (#pastejacking). These pages ask users to paste script into a Run window. Latest info at

Information from an infection run earlier today at github.com/PaloAltoNetworks/Un

Of note, we can find legitimate websites with the injected hashtag#KongTuke script by pivoting on the KongTuke domain in URLscan:

urlscan.io/search/#lancasternh