Results 1 to 10 of 10

Thread: Exploring Facebook's New Social CAPTCHA Authentication

  1. #1
    Join Date
    Apr 2003
    Posts
    13,270
    Rep Power
    35

    Default Exploring Facebook's New Social CAPTCHA Authentication

    Facebook rolled out the “social CAPTCHA” mechanism authentication mechanism, based on the approach described in Facebook’s Using Social Information for Authenticating a User Session patent. While CAPTCHA is traditionally used to distinguish between humans and bots, Facebook’s method is designed to distinguish legitimate users from impostors. It does this by asking questions about the user’s social network.

    Facebook prompts the user to authenticate using the “social CAPTCHA” approach if the site notices an anomaly in the way the person is logging in. In one such case, Facebook states: “You are signing in from a location we’re not familiar with. For your protection, please take a moment to answer a few security questions.” The user is then presented with an option to answer their predefined secret question or to identify photos of their friends.
    Read more: http://blog.zeltser.com/post/1258010...authentication

    That's pretty cool. Of course, if you add a lot of persons you don't really know much about, then you might fail the captcha tests.

    Anyone run across the new captcha yet?
    "The best software is the one that fits your needs." - A_A

    Virus free since: date unknown
    Anti-virus free since: August 2008

  2. #2
    Join Date
    Aug 2007
    Posts
    43
    Rep Power
    0

    Default

    No..I haven't seen it yet but one would only encounter it if trying to hack somebody's account or logging in from somewhere u don't normally like a friend's house or a cybercafe.

    I think Facebook is going to far with this one.All they have to do is make it optional for you to set specific IP's that are allowed to log in the account (like your home or work PC's).

    Digital currency websites like E-gold have had that feature for years and if your IP address changes (even cable/DSL IP's change occasionally) then a PIN is sent to your email which you have to confirm b4 logging in.

  3. #3
    Join Date
    Nov 2004
    Posts
    5,192
    Rep Power
    25

    Default

    I have run across it. It was extremely annoying. Basically I went overseas and tried to sign in. Facebook didn't recognize the IP bank that I was on as one of the "regular" IPs that I sign in from and decided to ask me questions.

    It works nicely if you use Facebook for just contacts and friends, but when you do like me and have multiple games like Mafia Wars and such that you mass-add people then you have a crack-load of persons that you don't know personally.

    It's good in some senses, but the bad part is if you fail you have to wait a number of hours (12/24 I think it was.....) before you are able to try logging in again.
    Knowing the solution doesn't mean knowing the method. Yet answering correctly and regurgitation are considered "learning" and "knowledge".

  4. #4
    Join Date
    Feb 2006
    Posts
    4,242
    Rep Power
    0

    Default

    Great implementation .
    |--- www.RealJamaicaEstate.com ™ ---|
    Invest small = small returns [micro enterprise] | Invest Big = returns Big [macro enterprise]
    --- www.fashionsJAMAICA.com ™ -|- www.ChampsJamaica.com

  5. #5
    Join Date
    Feb 2007
    Posts
    6,512
    Rep Power
    0

    Default

    Friend asked me to fix something on his account and ended up having to call him back and put those questions to him. Mini had same prob when he used a bb with diff. location settings. Annoying really.
    ShadowWolfe, signing off *salute*
    /user has permanently disconnected from the Animus.

  6. #6
    Join Date
    Mar 2005
    Posts
    7,052
    Rep Power
    0

    Default

    I had experienced this from months ago...when I kept on logging in from different mobile devices.

    It doesn't ask me anymore though.
    Lover of Technology, period!!||Currently loaded: Samsung Galaxy Note 10+

  7. #7
    Join Date
    Oct 2006
    Posts
    9,074
    Rep Power
    27

    Default

    Not sure this is any better than the regular captcha. You could find ppls friends and their names easy.
    This posting is provided "AS IS" with no warranties, and confers no rights.
    You assume all risk for your use. © 2006 Azix Solutions.
    All rights reserved.

    Dropbox: http://db.tt/8qVS35lo

  8. #8
    Join Date
    Feb 2007
    Posts
    6,512
    Rep Power
    0

    Default

    How easy is that though? For people with hundreds or thousands of friends, and fb shows you a few random ones, how easy is it?

  9. #9
    Join Date
    Apr 2003
    Posts
    13,270
    Rep Power
    35

    Default

    Quote Originally Posted by ShadowWolfe Hellscream View Post
    How easy is that though? For people with hundreds or thousands of friends, and fb shows you a few random ones, how easy is it?
    It easy for semi. He has a leet mind that can quickly remember faces and names in a few mins after scanning through some pics. But for the rest of us mortals, not so easy.
    "The best software is the one that fits your needs." - A_A

    Virus free since: date unknown
    Anti-virus free since: August 2008

  10. #10
    Join Date
    Jul 2009
    Posts
    3,700
    Rep Power
    18

    Post

    Quote Originally Posted by Technoboy View Post
    I had experienced this from months ago...when I kept on logging in from different mobile devices.

    It doesn't ask me anymore though.
    This exact thing happened to me three weeks ago when signing in with I.M. apps from my phones

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •