Categories: NewsTech

Cloudflare: It’s time to replace CAPTCHAs as the go-to for human verification

I think we’re all familiar with the CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) test—the typical Internet user encounters one every 10 days. The test is meant to verify you as a human user (as opposed to a bot), but to be frank with you, I can’t even count the number of times that I’ve failed a CAPTCHA test due to a misclick. In fact, Cloudflare recently estimated that around 500 human years are wasted every single day—just to prove “humanity”.

The DNS experts recently shared an experimental verification method to “end this madness” and replace CAPTCHAs, unveiling a system that utilises trusted USB keys to help users prove… that they are human. In the future, Cloudflare says that phones and computers will come with this ability by default, too.

“Today marks the beginning of the end for fire hydrants, crosswalks, and traffic lights on the Internet.”

An alternative: Cryptographic Attestation of Personhood

This system essentially supports a number of USB security keys (such as YubiKeys, HyperFIDO keys, and Thetis FIDO U2F keys), and relies on Web Authentication Attestation. This is basically an API that has already been implemented as a standard on many modern web browsers and operating systems, and it uses the cryptography capabilities of devices to authenticate users on the web.

Technical jargon aside, this is Cloudflare’s elevator pitch:

“The short version is that your device has an embedded secure module containing a unique secret sealed by your manufacturer. The security module is capable of proving it owns such a secret without revealing it. Cloudflare asks you for proof and checks that your manufacturer is legitimate.”

Cloudflare says that privacy is still at the forefront of their thinking, and the aim of the experimental method isn’t to know which human you are, merely that you are actually a human user. This means that the attestation process does not include biometric authentication, although Cloudflare still needs to know who the manufacturer of your device is to authenticate you.

However, Cloudflare admits that there is still room for error/abuse when it comes to its new system, such as the possibility of “automated button-pressing systems”. Something like a drinking bird mechanism could feasibly press a capacitive sensor, and essentially authenticate the system. Still, this would still be slower compared to professional CAPTCHA-solving services, and Cloudflare says that there are existing safeguards in place to mitigate the consequences here.

In any case, the project is still at the experimental stage, and only USB and NFC security keys work for now. You can try out the Cryptographic Attestation of Personhood here, and provide feedback here. Or, if you think you have the skills to help the team get rid of CAPTCHAs forever (that’s the dream, isn’t it), the Cloudflare team is actually hiring now.

So, what do you think?

[ SOURCE ]

Recent Posts

TNB Electron turns on 240kW DC Charger at Yard TNB Mergong, Alor Setar

TNB Electron turns on yet another EV charging location at one of TNB's own premises.…

18 hours ago

GXBank on cybersecurity, scams and AI: What really happens behind the scenes to protect users

GXBank recently marked its second anniversary with more than one million Malaysians onboard, cementing its…

2 days ago

Realme C85: World record-breaking “ultra waterproof” phone, but not for the reason you think

Realme has just launched a new budget-oriented mid-range smartphone in Malaysia, the Realme C85 5G.…

2 days ago

sooka’s Gilerrr Streaming Challenge Draws 273 Participants, Clinches Malaysia Book of Records Title

This post is brought to you by sooka. sooka pulled a lively crowd to Pavilion…

2 days ago

Infinix teams up with Pininfarina for future smartphone designs. Note 60 Ultra launching first in 2026

Infinix has just announced its strategic partnership with Pininfarina for its upcoming flagship smartphones, revealed…

3 days ago

Your Proton car can soon be controlled from a Huawei smartwatch

During Proton's Tech Showcase, the national carmaker has also highlighted its digital and connected automotive…

3 days ago

This website uses cookies.