UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Google's new hand-wave captcha can be bypassed with a stock photo

Google has begun testing a new reCAPTCHA method that requires users to wave their hand in front of a camera to verify their identity. So, in addition to solving puzzles and reading garbled text, you can now use your computer's camera to pass verification.

Leave a comment
Google's new hand-wave captcha can be bypassed with a stock photo

Google has begun testing a new reCAPTCHA method that requires users to wave their hand in front of a camera to verify their identity. So, in addition to solving puzzles and reading garbled text, you can now use your computer's camera to pass verification.

When gesture verification is triggered, the browser requests access to the camera and asks you to perform a simple gesture — for example, waving your hand or showing an open palm. Google notes that the system records a short video of this movement and uses AI to capture the coordinates of 21 joints of the hand to complete verification. After that, the video is immediately deleted, and Google assures that it does not store it anywhere, writes Neowin.

This procedure itself may be uncomfortable for those who don't want their biometric data (and a hand scan technically falls into this category) recorded somewhere. But the situation gets even more confusing as early testers discovered that the new hand-wave reCAPTCHA system can be fooled with a regular stock photo.

One of the users of the social network X tested the new check by running a stock image of a hand through the OBS virtual camera, and the system passed it. Journalist Neowin also tested this method. It took him a few tries and a few different stock photos, but in the end he was also able to pass the test. He simply had to adjust the position of the stock image of a person waving in OBS, and Google’s engine recognized it as a legitimate gesture.

Given the simplicity of the process, the entire procedure can be automated in a matter of minutes. A simple Python script is enough to completely eliminate the effectiveness of the new reCAPTCHA method. There is even no need to involve AI bots, which are usually used to solve puzzles and other verification methods.

The new reCAPTCHA method is still in its early stages of development, and Google will hopefully update its AI to at least reject static images. However, this incident, combined with users' initial skepticism about how Google handles their data, is unlikely to get many people waving their cameras around anytime soon.

PhantomCaptcha phishing campaign: Russian hackers target state administrations and organizations assisting Ukraine
PhantomCaptcha phishing campaign: Russian hackers target state administrations and organizations assisting Ukraine
On the topic
PhantomCaptcha phishing campaign: Russian hackers target state administrations and organizations assisting Ukraine
“This step is necessary to prove that I am not a bot.” ChatGPT AI agent easily passes the “I am not a robot” CAPTCHA
“This step is necessary to prove that I am not a bot.” ChatGPT AI agent easily passes the “I am not a robot” CAPTCHA
On the topic
“This step is necessary to prove that I am not a bot.” ChatGPT AI agent easily passes the “I am not a robot” CAPTCHA
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram
Also Read
Головоломка киянина Quadline перемогла на фестивалі інді-ігор Google Play
Головоломка киянина Quadline перемогла на фестивалі інді-ігор Google Play
Головоломка киянина Quadline перемогла на фестивалі інді-ігор Google Play
Харківська художниця намалювала новий дудл для Google на День Незалежності України
Харківська художниця намалювала новий дудл для Google на День Незалежності України
Харківська художниця намалювала новий дудл для Google на День Незалежності України
Фахівців Google тепер годуватимуть роботи. Вони також уміють давати корисні (і не дуже) поради
Фахівців Google тепер годуватимуть роботи. Вони також уміють давати корисні (і не дуже) поради
Фахівців Google тепер годуватимуть роботи. Вони також уміють давати корисні (і не дуже) поради
Кінець епохи. Пошуковик Google більше не відповідатиме на безглузді запити
Кінець епохи. Пошуковик Google більше не відповідатиме на безглузді запити
Кінець епохи. Пошуковик Google більше не відповідатиме на безглузді запити

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.