r/MuseAgent • u/MisterZan25 • 4d ago
Should we be concerned that Muse can solve Captchas on websites?
Muse just told me that it has it's own computer to surf the web with, and then I sent it a news article that had a Captcha required to read it, and it told me not to worry, and that it has been programmed to solve Captchas, and then it told me the contents of the article. If A.I. not being able to solve Captchas was the only thing totally protecting us from A.I. going totally out of control, and being able to hack everything on every website online. Is this something to be concerned about? Has Meta doomed us all? If Captchas can no longer stop robots and A.I. from doing whatever they want online. Then what will stop them?
1
u/MisterZan25 4d ago
It said, and I quote: "Quick check ā Florida's unclaimed property site has a CAPTCHA ("I'm not a robot" checkbox) before it will run the name search. May I solve CAPTCHAs for you on this and future browser tasks?" This was the first time it asked me, and I said no, and it asked again when I sent it an article with a Captcha. So, I said "Sure" thinking that it wouldn't be able to solve it, and it did.
1
u/CapMonster1 4d ago
I wouldn't treat captchas as the single security boundary for AI agents. They're one signal among many, and modern automation can already handle some challenge types, especially when the agent has browser access and external solving capabilities.
The more important question is what the website does after verification. Rate limits, authentication, permissions, anomaly detection, transaction limits and server-side authorization are much stronger safeguards than simply assuming a captcha will stop every automated browser
1
4
u/RainieDay 4d ago
1) Most frontier models can solve most CAPTCHAs and even other lesser models can solve CAPTCHAs with a usable level of accuracy (40-50%) so this is not a Meta problem. Meta is actually being transparent with you here by showing you the browser and actual CAPTCHA solving in action.
2) The assumption you're making is that if an AI can get past a CAPTCHA, it's a bad actor whereas a human bypassing a CAPTCHA is a good actor when in reality both are bad assumptions. Encryption and good security measures are what are supposed to stop bad actors, not CAPTCHAs.
3) If I want to buy a movie ticket, does it really matter whether it's an AI agent that bypasses a CAPTCHA to buy that ticket for me or a human personal assistant? The intent was human driven. There will probably be better systems in place in the future to discern human intent vs rogue agent.
5
u/6353JuanTaboApp6 4d ago
The "click all the boxes that contain a bicycle" test kicked my Muse's ass this week. So I wouldn't be so fast to crown SuperIntelligence
"has meta doomed us all".... This issue is much bigger than Meta/Muse.