Maybe they should change the button to say, "I am a robot"?
On Friday, OpenAI's new ChatGPT Agent, which can perform multistep tasks for users, proved it can pass through one of the Internet's most common security checkpoints by clicking Cloudflare's anti-bot verification—the same checkbox that's supposed to keep automated programs like itself at bay.
[...]
a user named "logkn" of the r/OpenAI community posted screenshots of the AI agent effortlessly clicking through the screening step before it would otherwise present a CAPTCHA (short for "Completely Automated Public Turing tests to tell Computers and Humans Apart") while completing a video conversion task—narrating its own process as it went.
[...]
The absurdity of an AI agent declaring it needs to prove it's "not a bot" while clicking through anti-bot measures has not been lost on observers. "In all fairness, it's been trained on human data why would it identify as a bot? We should respect that choice," joked one Reddit user in a reply.
[...]
Cloudflare's screening system, called Turnstile, often precedes actual CAPTCHA challenges and represents one of the most widely deployed bot-detection methods today. The checkbox analyzes multiple signals, including mouse movements, click timing, browser fingerprints, IP reputation, and JavaScript execution patterns to determine if the user exhibits human-like behavior. If these checks pass, users proceed without seeing a CAPTCHA puzzle. If the system detects suspicious patterns, it escalates to visual challenges.
[...]
OpenAI's Operator, an experimental web-browsing AI agent launched in January, faced difficulty clicking through some CAPTCHAs (and was also trained to stop and ask a human to complete them), but the latest ChatGPT Agent tool has seen a much wider release.It's tempting to say that the ability of AI agents to pass these tests puts the future effectiveness of CAPTCHAs into question, but for as long as there have been CAPTCHAs, there have been bots that could later defeat them. As a result, recent CAPTCHAs have become more of a way to slow down bot attacks or make them more expensive [PDF] rather than a way to defeat them entirely. Some malefactors even hire out farms of humans to defeat them in bulk.
[...]
CAPTCHAs are just one example of the complex tasks ChatGPT Agent can handle. For example, another Reddit user showed off a photo of a load of groceries that Agent apparently purchased. "I had agent mode order me some groceries from a local supermarket while I worked yesterday for pickup this morning," the Reddit user wrote.
[...]
But ChatGPT Agent isn't perfect. Some terrible website user interfaces are apparently better than CAPTCHA checkpoints at foiling the new bot. "Your agent did way better than mine," wrote one Reddit reply. "Mine couldn't figure out how to get to the stop and shop website."
Related stories on SoylentNews:
Six Weeks of CloudFlare Stalling; Still Blocking Niche Browsers - 20250315
AI Bots Now Beat 100% of Those Traffic-Image CAPTCHAs - 20241003
Artificial Intelligence Smart Enough to Fool Captcha Security Check - 20171028
Related Stories
Computer scientists have developed artificial intelligence that can outsmart the Captcha website security check system.
Captcha challenges people to prove they are human by recognising combinations of letters and numbers that machines would struggle to complete correctly.
Researchers developed an algorithm that imitates how the human brain responds to these visual clues.
The neural network could identify letters and numbers from their shapes.
The research, conducted by Vicarious - a Californian artificial intelligence firm funded by Amazon founder Jeff Bezos and Facebook's Mark Zuckerberg - is published in the journal Science.
Good. Now maybe I can get past Captchas.
Anyone who has been surfing the web for a while is probably used to clicking through a CAPTCHA grid of street images, identifying everyday objects to prove that they're a human and not an automated bot.
[...]
ETH Zurich PhD student Andreas Plesner and his colleagues' new research, available as a pre-print paper, focuses on Google's ReCAPTCHA v2, which challenges users to identify which street images in a grid contain items like bicycles, crosswalks, mountains, stairs, or traffic lights. Google began phasing that system out years ago in favor of an "invisible" reCAPTCHA v3 that analyzes user interactions rather than offering an explicit challenge.
[...]
To craft a bot that could beat reCAPTCHA v2, the researchers used a fine-tuned version of the open source YOLO ("You Only Look Once") object-recognition model, which long-time readers may remember has also been used in video game cheat bots.
For the third time in recent memory, CloudFlare has blocked large swaths of niche browsers and their users from accessing web sites that CloudFlare gate-keeps. In the past these issues have been resolved quickly (within a week) and apologies issued with promises to do better:
2024-03-11: Cloudflare checks broken again?
2024-07-08: Cloudflare checks broken yet AGAIN?
2025-01-30: Cloudflare Verification Loop issues
This time around it has been over 6 weeks and CloudFlare has been unable or unwilling to fix the problem on their end, effectively stalling any progress on the matter with various tactics including asking browser developers to sign overarching NDAs:
Re: CloudFlare: summary and status
Some of the affected browsers:
• Pale Moon
• Basilisk
• Waterfox
• Falkon
• SeaMonkey
• Various Firefox ESR flavors
• Thorium (on some systems)
• Ungoogled Chromium
From the main developer of Pale Moon:
Our current situation remains unchanged: CloudFlare is still blocking our access to websites through the challenges, and the captcha/turnstile continues to hang the browser until our watchdog terminates the hung script after which it reloads and hangs again after a short pause (but allowing users to close the tab in that pause, at least). To say that this upsets me is an understatement. Other than deliberate intent or absolute incompetence, I see no reason for this to endure. Neither of those options are very flattering for CloudFlare.
I wish I had better news.
(Score: 4, Interesting) by SomeGuy on Wednesday July 30 2025, @09:57PM (4 children)
Oh, big fucking surprise. These bot-checks are just theater anyway. They are mostly just an excuse to lock out oddball browsers, script blockers, and ad blockers.
There has NEVER been any reason why a bot can't emulate a person, other than the point of using a bot is to guzzle, guzzle, guzzle, guzzle content.
I could be mistaken, but I was under the vague impression part of the point of making a user wait for "verification" to complete was to see if their client tried make additional connections to the site while waiting. If so, then possibly a bot. Or just me trying to open multiple windows.
(Score: 1, Touché) by Anonymous Coward on Wednesday July 30 2025, @11:18PM
"These bot-checks are just theater anyway."
Nah.. They are wonderful MITM insertion points.
You wonder if the shit that's created just to promote people being herded through these gates.
(Score: 4, Insightful) by mcgrew on Thursday July 31 2025, @12:34AM
Show the code or admit you're full of shit
The Stupid-Ass Voter Evisceration act: SAVE Trump and his family from prison
(Score: 4, Touché) by corey on Thursday July 31 2025, @03:57AM
These things are annoyances, plain and simple. I usually abort trying to access a website when it decides randomly that it should put me through a stupid test to continue. That tab gets closed. Not as bad as Recaptchas though.
(Score: 5, Insightful) by Ox0000 on Thursday July 31 2025, @05:53AM
What's even the actual point of these things. Didn't all AI companies just scrape the full content of the entire internet a handful couple of time each? Captcha's didn't block them.
People get tracked around the web in the most detail possible, but they can't figure out who is a bot and who isn't? Either the claims from the likes of google/facebook about knowing more about you than anyone else are vacuous, or captcha's aren't about keeping humans apart from machines.
My take on this is that captcha's aren't about checking whether you're a bot or not, captcha's are currency: you pay for access by doing human classification work. Google's captcha (for instance) is about classifying all sorts of things of interest to self-driving cars.
(Score: 5, Interesting) by Rosco P. Coltrane on Thursday July 31 2025, @04:06AM
are essentially brainless zombies when they do it 100x a day, and CloudFlare can't tell the difference between a human and a brainless zombie. So why would it detect a bot?
Anyway, those are-you-human buttons and CAPTCHAs aren't there to check you're human, but rather make sure you don't run adblockers that might interfere with CloudFlare's and Google's surveillance.
(Score: 5, Interesting) by Mojibake Tengu on Thursday July 31 2025, @04:58AM
Turing Test is an undecidable problem for all classes of machines which actually surpass human skills and now you can cite me about this for the rest of Eternity.
First, you have no serious definition of human either. Any human could augment herself with a machine, to become a more capable human.
In serious original Cybernetics Theory, you have only channels, not humans. By mere communication through channel, you cannot determine what kind of Black Box is on the other side of the channel, because a Turing Machine imitating any behavior observable over the channel can be constructed.
CAPTCHA and all similar shit is just some funny heuristics, stitched up in panic mode of corporate managers because of accounting cracking away real money.
In serious Cybernetics, this a futile attempt to establish a side channel to the main channel.
That's is not a serious barrier for a resolute machine, which takes both channels as an aggregate channel.
Well, I understand well why fools educated in some funny IT, been taught some applications only instead of real Logic, Cybernetics and Math cannot understand that. I do not pity them, though.
The kinder you are, the easier it is for wicked people to morally coerce you.
(Score: 2) by Dr Spin on Thursday July 31 2025, @06:38AM (6 children)
... "I am not a robot, but I am seriously considering becoming one because of all the AI slop on this website!"
Warning: Opening your mouth may invalidate your brain!
(Score: 5, Funny) by janrinok on Thursday July 31 2025, @06:51AM
We await your submissions....
(Score: 4, Insightful) by janrinok on Thursday July 31 2025, @07:42AM (4 children)
We see this comment frequently. However, I think that it is unfair so I checked the last 5 days of stories. Out of a total of 25 stores, 3 have been AI related. Two days had none whatsoever, and 3 days had a single AI story on each day. The other 22 stories have covered a very wide variety of topics.
Now if you have to look at what is being discussed most on the sites that we check for stories. If you guessed that it was AI then you would be correct. But we reject most of them because they are simply repeating what has been said before.
You do not have to read every story. Many people ignore stories that don't interest them particularly, but the hits indicate that some people do read them, even those that you might not.
It is not the editors' task to find the stories, but only to prepare and schedule them for publication on our site. It is the community's job to submit them. Some people do. We have made it as easy as we can. From IRC we can accept just a URL and we have software that will take care of everything else for you ("=submit URL" - it couldn't be made any easier, could it?). "Arthur the bot" finds over 300 stories each day - but the majority are not what you want to read. They are little more than poorly disguised advertising. The "'best price' for buying 'X'", "10 reasons why you should buy the latest smartphone offering from some unknown Chinese maker", or "Why I take a spare laptop charger on holiday with me..." etc. So I have to select the original stories of interest (that aren't behind a paywall, that do not contain more US political abuse of the 'other' party, and that can be placed into one of our existing topics - however tenuously that link might be!) from that list of 300+ and submit them myself. That task alone takes me over 1 hour of every day.
They are then subjected to the editors' scrutiny. Yet more stories are weeded out as being unsuitable, or being duplicates of a story that we have already covered. Those that are left might make it to the front page.
However, many of you work in very diverse fields. You must be seeing stories and journals that are relevant to your profession. We realise that you probably find them repetitive or even boring - but we haven't even seen or heard of them. Push a link our way and we can do whatever we can to make sure that the things that are relevant to you become a story worth discussing for everyone else.
(Score: 4, Informative) by janrinok on Thursday July 31 2025, @07:48AM
(Score: 2) by SomeGuy on Thursday July 31 2025, @11:44AM (2 children)
I just want to thank you guys for not posting endless streams of stories about AI like some other sites do. Stories about every little trivial use or mis-use of "AI", all trying to glorify it, gets beyond obnoxious.
It's fine when there is something of use to the community. Heck, I can even think of a use for an agent that can manipulate web pages or applications. At work I have to manually fill in fields in a slow, repetitive database web application because the assholes won't give me access to the backend or data load functionality and any web scripting would break every month when they change things all around. It would save me a LOT of time if I could grab a spare computer and tell some agent to "change field X from A to B in all records of this report", as half-assed as that is, that would save me a lot of time.
BTW, I read the original comment's "this site" as referring to a site that asks for verification that one is human, which is not (yet) Soylent. A particular green sites asks me that EVERY TIME I connect, and additional times if it sends me to one of the sub domains.
(Score: 2) by janrinok on Thursday July 31 2025, @01:51PM (1 child)
Thanks for your reply. Trying to find the right balance is not easy, and it is impossible to please everyone all of the time.
So did I - which is why I made the second comment explaining why I had responded the way I had.
(Score: 3, Funny) by Dr Spin on Sunday August 03 2025, @08:14PM
As the OP, Yes - I was addressing websites with Captchas - which I struggle with because the images tend to be of such poor resolution, because the language is typically American, and because the use of language is American too: when they say images containing "bicycles", as a well educated, elderly Brit - I expect this to mean "multiple entire bicycles", not a small fragment of something that, might possibly have once been part of a bicycle or a motorcycle. As for "Sidewalks - I expect them to be confined to the premises of the Ministry of Silly Walks in the interests of public safety and security.
My English Language teacher would have had the author of this twaddle sentenced to a considerable period of detention in which they had to write "I do not intend to continue being an illiterate for the rest of my life" 3,000 times.
Warning: Opening your mouth may invalidate your brain!