A UC San Diego analysis presented at the USENIX Security Symposium and reported by MIT Technology Review in August 2010 uncovered a worldwide network of services that help spammers get past CAPTCHAs: hundreds, possibly thousands of laborers working for less than $50 a month, solving puzzles delivered by automated middlemen who sell the solutions to spammers in real time.

The economics defeat the design. CAPTCHAs work by being easy for humans and hard for computers, so the relay simply supplies the human. Delivery is so efficient that the average wait for a solution hovers around 20 seconds — fast enough for bots to register email accounts and post to forums and blogs without interruption.

The researchers probed one service, ImageToText, whose workers returned correct answers across a remarkable range of languages, including Dutch, Korean, Vietnamese, Greek and Arabic. Even CAPTCHAs set in Klingon — chosen as a control because perhaps one in a thousand random guesses would land — were solved by the workers.

The study concluded that sites run by Microsoft, AOL and Google, along with the widely used reCAPTCHA, were regularly compromised through these services; interviews with an anonymous operator, 'Mr. E', confirmed the model. For sophisticated spammers, the researchers found, CAPTCHAs were not a barrier but a cost of doing business.

It documents the exact moment a security control stopped being a barrier and became a price — about a penny per puzzle.

The system design is the clever part: automated middlemen, real-time delivery and a distributed workforce turn human intelligence into a metered API.

The evidence is empirical, not anecdotal: location analysis of the workers, live experiments including the Klingon control, and an insider interview.

It forced the security industry to rethink CAPTCHAs, since the test still works but the attacker's economics had absorbed it.

Any defense priced against machines can be defeated by the price of human time: know which of your controls are only as strong as the cost of paying someone to do the task by hand.

The USENIX paper's findings put the human-relay market on the record in 2010; the study's conclusion — that for sophisticated spammers CAPTCHAs are a cost of doing business — became the standard framing for why distorted-text checks alone stopped keeping bots out.

FOLLOW THE EVIDENCE

The sources

  1. How Spammers Use Low-cost Labor to Solve CAPTCHAS technologyreview.com