OpenAI’s ChatGPT Agent casually clicks through “I am not a robot” verification test

Date:

Share:



The CAPTCHA arms race

While the agent didn’t face an actual CAPTCHA puzzle with images in this case, successfully passing Cloudflare’s behavioral screening that determines whether to present such challenges demonstrates sophisticated browser automation.

To understand the significance of this capability, it’s important to know that CAPTCHA systems have served as a security measure on the web for decades. Computer researchers invented the technique in the 1990s to screen bots from entering information into websites, originally using images with letters and numbers written in wiggly fonts, often obscured with lines or noise to foil computer vision algorithms. The assumption is that the task will be easy for humans but difficult for machines.

Cloudflare’s screening system, called Turnstile, often precedes actual CAPTCHA challenges and represents one of the most widely deployed bot-detection methods today. The checkbox analyzes multiple signals, including mouse movements, click timing, browser fingerprints, IP reputation, and JavaScript execution patterns to determine if the user exhibits human-like behavior. If these checks pass, users proceed without seeing a CAPTCHA puzzle. If the system detects suspicious patterns, it escalates to visual challenges.

The ability for an AI model to defeat a CAPTCHA isn’t entirely new (although having one narrate the process feels fairly novel). AI tools have been able to defeat certain CAPTCHAs for a while, which has led to an arms race between those that create them and those that defeat them. OpenAI’s Operator, an experimental web-browsing AI agent launched in January, faced difficulty clicking through some CAPTCHAs (and was also trained to stop and ask a human to complete them), but the latest ChatGPT Agent tool has seen a much wider release.

It’s tempting to say that the ability of AI agents to pass these tests puts the future effectiveness of CAPTCHAs into question, but for as long as there have been CAPTCHAs, there have been bots that could later defeat them. As a result, recent CAPTCHAs have become more of a way to slow down bot attacks or make them more expensive rather than a way to defeat them entirely. Some malefactors even hire out farms of humans to defeat them in bulk.



Source link

━ more like this

Fairer pricing, fewer options: The changing shape of monthly car insurance payments – London Business News | Londonlovesbusiness.com

Motor insurance customers are paying less to spread the cost of their cover but fewer can do so at all. The latest Consumer Intelligence...

Gold falls over 5% amid stronger dollar and profit-taking – London Business News | Londonlovesbusiness.com

Gold tumbled more than 5% on Tuesday, marking its steepest one-day drop since August 2020, as a stronger US dollar and heavy profit-taking...

Samsung is working on XR smart glasses with Warby Parker and Gentle Monster

As part of its Galaxy XR headset presentation, Samsung also briefly teased another wearable product. It's working in collaboration with two eyewear companies,...

Why the Samsung Galaxy XR can support ‘almost all’ Android apps

The Samsung Galaxy XR is designed to be a showcase for Android XR, Google's new AR / VR operating system, but unlike competing...

Samsung Galaxy XR hands-on: A smarter, more open take on Apple’s Vision Pro for half the price

Apple's Vision Pro was meant to usher in a new era for headsets. However, its high price and somewhat limited utility resulted in...
spot_img