Top Banner
www.employment.gov.au The inaccessibility of CAPTCHA How you may be undermining the accessibility of your online service
34

The inaccessibility of CAPTCHA

Jan 22, 2018

Download

Internet

Ross Mullen
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: The inaccessibility of CAPTCHA

www.employment.gov.au

The inaccessibility of CAPTCHAHow you may be undermining the accessibility of your online service

Page 2: The inaccessibility of CAPTCHA

What is CAPTCHA

Page 3: The inaccessibility of CAPTCHA

Why use CAPTCHA?

• It’s a way to stop bots from compromising your online service

– Creating accounts

– Spamming users

– Commenting on forums

Page 4: The inaccessibility of CAPTCHA

Why use CAPTCHA?

• It’s free, fully automated and pretty straight forward to add

• Requires no effort to continue using it

Page 5: The inaccessibility of CAPTCHA

How they work

• When a challenge is completed correctly the user can continue the task

Page 6: The inaccessibility of CAPTCHA

Problems

• CAPTCHA is not accessible

– Many are difficult to use via the keyboard

• Especially with a screen reader

– Very difficult to use if you’re vision impaired

– Difficult to understand any audio challenge

Page 7: The inaccessibility of CAPTCHA

Alternatives

• Google’s reCaptcha

– Users only need to tick an option

Page 8: The inaccessibility of CAPTCHA

Google reCaptcha

• Uses a range of criteria to determine humanness

– User behaviour on the page

– If the user has a Google account

Page 9: The inaccessibility of CAPTCHA

Problem solved?

• No

– In cases when the risk analysis engine can't confidently predict whether a user is a human or an abusive agent, it will prompt a CAPTCHA to elicit more cues, increasing the number of security checkpoints to confirm the user is valid

Page 10: The inaccessibility of CAPTCHA

Do you feel confident using it?

• If you can’t be sure users will never see a CAPTCHA, can you recommend using it?

– An accessible website is made inaccessible

Page 11: The inaccessibility of CAPTCHA

Captcha has been compromised

• Services exist where people solve in bulk

– CAPTCHA farms, using human labour

Page 12: The inaccessibility of CAPTCHA

Background reading

• Breaking CAPTCHA

– www.troyhunt.com/breaking-captcha-with-automated-humans/

• Artificial intelligence smart enough to fool Captcha security check

– http://www.bbc.com/news/technology-41775968

Page 13: The inaccessibility of CAPTCHA

Other alternatives

• Form submission times

• Honeypot

• Email verification

Page 14: The inaccessibility of CAPTCHA

Form submission times

• If a form has been submitted quickly consider it’s been sent by a bot

– Ignore the input

Page 15: The inaccessibility of CAPTCHA

Honeypot

• Include a hidden form field on the page

– If this is filled ignore the input

Page 16: The inaccessibility of CAPTCHA

Email verification

• Ask a user to confirm their email address by clicking a link emailed to them

Page 17: The inaccessibility of CAPTCHA

All reasonable responses

• Use layered security to improve the security

system

Email verification

Form submission times

Honeypot

Page 18: The inaccessibility of CAPTCHA

Other approaches

• Asking a user to add two number together

• Asking a question

Page 19: The inaccessibility of CAPTCHA

Number CAPTCHA problem

• If bots can submit a form, bots can probably work out this

Page 20: The inaccessibility of CAPTCHA

Word CAPTCHA problem

• Need to create 100’s of question and answer combinations to ensure they don’t repeat

Page 21: The inaccessibility of CAPTCHA

Besides is this a good look?

• Asking trivial questions doesn’t look good on a government website

– “what colour is the sky?”

Page 22: The inaccessibility of CAPTCHA

The problem

• CAPTCHA is a frontend solution to a backend problem

– Why should users have to prove they are human

Page 23: The inaccessibility of CAPTCHA

Most viable alternative

• SMS text message

• Self declaring on the account signup

• Staff assistance if the user is having problems

• Application behaviour monitoring

Page 24: The inaccessibility of CAPTCHA

SMS text message

• Send a text message with a code before the user can perform a task

Page 25: The inaccessibility of CAPTCHA

SMS text message downside

• Can incur significant cost if all users are now receiving a text message

– Be discerning and provide the text message option for those who actually require it

Page 26: The inaccessibility of CAPTCHA

Self declaration

• Ask if the user requires extra screen reader support

– use the SMS text message option instead of CAPTCHA

Do you require extra screen reader support?

Page 27: The inaccessibility of CAPTCHA

Self declare downside

• Users may not want to self-declare to be identified as different or requiring extra help

Page 28: The inaccessibility of CAPTCHA

Staff assistance

• If you can’t avoid CAPTCHA, ensure there is help available

– Confirm the user outside of CAPTCHA

Page 29: The inaccessibility of CAPTCHA

Staff assistance example

• A link asking the user to contact you if they encounter difficulties

If you are having problems contact us

Page 30: The inaccessibility of CAPTCHA

Staff assistance

• Can be a suitable stop-gap whilst a long-term strategy for moving away from CAPTCHA is decided

– Be pragmatic

Page 31: The inaccessibility of CAPTCHA

Application monitoring

• Large number of unused accounts created

• Large number of requests from the same IP address

– Investigate and block

Page 32: The inaccessibility of CAPTCHA

The trade off

• Security and accessibility can co-exist

– Except when captcha is used to provide the security

Page 33: The inaccessibility of CAPTCHA

Summary

• Current CAPTCHA implementations are not accessible

– Some may adhere to certain WCAG 2.0 criteria

– Assume all are inaccessible

Page 34: The inaccessibility of CAPTCHA

Summary

• The Digital Service Standard advocates user needs and putting the user first

– What user need is there for using CAPTCHA?

– It’s a business need, not a user need