Let the right one in: attestation as a usable CAPTCHA alternative

Tara Whalen, Thibault Meunier, Mrudula Kodali, Alex Davidson, Marwan Fayed, Armando Faz-Hernández, Watson Ladd, Deepak Maram, Nick Sullivan, Benedikt Christoph Wolters, Maxime Guerreiro, Andrew Galloni

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

CAPTCHAs are necessary to protect websites from bots and malicious crawlers, yet are increasingly solvable by automated systems. This has led to more challenging tests that require greater human effort and cultural knowledge; they may prevent bots effectively but sacrifice usability and discourage the human users they are meant to admit.We propose a new class of challenge: a Cryptographic Attestation of Personhood (CAP) as the foundation of a usable, pro-privacy alternative. Our challenge is constructed using the open Web Authentication API (WebAuthn) that is supported in most browsers. We evaluated the CAP challenge through a public demo, with an accompanying user survey. Our evaluation indicates that CAP has a strong likelihood of adoption by users who possess the necessary hardware, showing good results for effectiveness and efficiency as well as a strong expressed preference for using CAP over traditional CAPTCHA solutions. In addition to demonstrating a mechanism for more usable challenge tests, we identify some areas for improvement for the WebAuthn user experience, and reflect on the difficult usable privacy problems in this domain and how they might be mitigated.

Original languageEnglish
Title of host publicationProceedings of the 18th Symposium on Usable Privacy and Security, SOUPS 2022
PublisherUSENIX Association
Pages599-612
Number of pages14
ISBN (Electronic)9781939133304
Publication statusPublished - 2022
Event18th Symposium on Usable Privacy and Security, SOUPS 2022 - Boston, United States
Duration: 7 Aug 20229 Aug 2022

Publication series

NameProceedings of the 18th Symposium on Usable Privacy and Security, SOUPS 2022

Conference

Conference18th Symposium on Usable Privacy and Security, SOUPS 2022
Country/TerritoryUnited States
CityBoston
Period7/08/229/08/22

Fingerprint

Dive into the research topics of 'Let the right one in: attestation as a usable CAPTCHA alternative'. Together they form a unique fingerprint.

Cite this