Visual Verification: Request of NFB to Officially Support CAPTCHA Accessibility Initiatives

The following letter was composed and sent to Dr. Marc Maurer, President, National Federation of the Blind, on July 28, 2007. It has been five weeks now. We continue to await a response from the organization concerning their official position and willingness to dedicate additional resources to these critical accessibility concerns.

July 28, 2007 

Dear Dr. Maurer:

My name is Darrell Shandrow.  You and I met a number of times at NFB national conventions and the National Center for the Blind.  I am an online accessibility evangelist, operating a blog known as Blind Access Journal.  It can be found at http://www.blindaccessjournal.com.  My purpose for writing this letter is to ask you to direct some of the resources of the National Federation of the Blind toward effectively advocating equal accessibility of CAPTCHA (visual verification) and other multifactor authentication systems for the blind and visually impaired.   

In CAPTCHA and some hardware based multifactor authentication schemes, a string of distorted characters is presented visually, and entry of those characters into an edit field is required in order to be granted access to a protected system.  The purpose of CAPTCHA is to differentiate between a script or other automated computer program designed to abuse a resource and a real human being who desires legitimate access.  Visual multifactor authentication schemes provide a second level of security beyond the traditional username and password.  Pictures can’t be interpreted or automatically conveyed using Braille or speech access devices and many hardware security keys still do not provide any alternative output mechanisms.  Until an accessible alternative is made available, people with vision loss can’t see the code to be entered into the box to be granted admission.  

There now exists a number of techniques to reasonably accomodate CAPTCHA and multifactor authentication for the blind and visually impaired.  The most commonly implemented accomodation is an audio CAPTCHA, where the characters in the image are audibly played back to the blind or visually impaired user for correct entry into the edit box.  America Online, Microsoft and PRWeb are examples of companies offering this form of accomodation.   

Another form of accomodation is a text based CAPTCHA.  In such a scheme, a user is asked to solve a simple logic or math problem or answer a basic question in order to be granted admission.  The Federal Emergency Management Agency (FEMA) is an example of an agency that uses such a text based solution.  Some technology experts say this solution is relatively easily cracked by computer programs, so it probably will not be widely implemented in its current form. 

  A third form of accomodation involves the need for manual human intervention on the part of the company requiring the CAPTCHA.  In such a scheme, the resource is protected with a visual CAPTCHA along with a link to click, an e-mail address to write a message or a telephone number to call.  The blind person clicks the link, writes the e-mail or calls the telephone number to receive assistance.  Unfortunately, this approach is fraught with serious challenges that make it completely unworkable in most cases where it is in use.  When a blind user fills out the form, writes the e-mail or calls the number, it is absolutely necessary that the request for help be fulfilled immediately in order for the solution to provide a level of access equal to that enjoyed by his or her sighted peers.  In almost all cases, such requests for assistance either go completely unanswered or are answered in an inappropriate time frame, perhaps days after the request is made.  Another serious problem is the actions taken once the requests are answered.  Are there specific processes in place for effectively delivering these reasonable accomodations?  Are all employees who may be taking the calls properly trained to follow the procedures?  It has been proven to us over and over that the unfortunate answer to both questions is a resounding “no”.  Though some companies are willing to offer these manual interventions as reasonable accomodations, it is clear that, in all cases we have experienced, they do not take seriously the promise to actually deliver the goods.  Examples of web sites supposedly offering the human intervention method of accomodation include GoDaddy.com, Slashdot.org, ticketmaster.com and Yahoo.com. 

Unfortunately, there still exist many web sites that do not offer any reasonable accomodations to their visual CAPTCHA at all.  Examples of sites in this camp include activate.sirius.com, friendster.com and myspace.com.  When a blind person does manage to find someone at these companies to contact, assistance is rarely, if ever, offered. 

At a bare minimum, visual only CAPTCHA locks blind people out of equal participation in web sites such as information portals and social networking resources.  More seriously, visual CAPTCHA without reasonable accomodation actually prevents blind people from completing business transactions, as in the CAPTCHAs on godaddy.com and ticketmaster.com.  Finally, visual only multifactor authentication schemes, such as security keys, can prevent blind people from accessing their money or even obtaining or retaining employment! 

I am writing to ask that you direct the National Federation of the Blind, as the largest consumer organization of the blind in the United States, to show clear leadership in advocacy for access to CAPTCHA and multifactor authentication.  In the short term, please officially support the Yahoo! Accessibility Improvement Petition at http://blindwebaccess.com and make higher level efforts to contact Yahoo! executives to discuss the need for a better CAPTCHA solution on Yahoo! web sites.  In the longer term, please consistently support existing grassroots advocacy efforts in this area and carry out new efforts on an organizational level to exercise influence and, possibly, legislation to address these serious concerns. 

Sincerely, 

Darrell Shandrow – Accessibility Evangelist

We thank the American Council of the Blind for joining us in support of the Yahoo! Accessibility Improvement Petition along with the organization’s willingness to consider taking on additional future efforts surrounding accessibility issues involving CAPTCHA and multifactor authentication. A cross-organizational approach to this and other critical access needs would serve to further these vital causes.

Visual Verification: While Changing Logos and Signs, PayPal Still Says "No Blind People Allowed"!

Recently, the folks over on the PayPal Blog have been writing about all the changes being made to their logos and signs. Alas, there’s one signage change the eBay / PayPal folks seem to be resisting! That change involves removal of the “No Blind People Allowed” signs imposed by their continued inaccessible CAPTCHAs and, sometime in the not-too-distant future, their Security Key! Let’s all continue to flood PayPal’s customer service people regarding this issue of vital importance.

Visual Verification: Twitter Audio CAPTCHA Issues Likely Resolved – Please Retest

The reCAPTCHA folks have been hard at work over this Labor Day weekend chasing down the issues with their audio CAPTCHA implementations in secured forms with Internet Explorer 7.0. Please retest the Twitter audio CAPTCHA and submit your feedback as soon as possible. Let’s also be sure to show our appreciation to the reCAPTCHA team for going far above and beyond the call of duty to resolve this critical issue over a holiday weekend!

Visual Verification: Study Seeks to Expand the Usefulness of Audio CAPTCHA

Andy Schlaikjer, a Ph.D student at Carnegie Mellon University, has asked us to carry the following announcement:

I’m conducting a study to aid my research and development of a new form of audio CAPTCHA. If you’d like to participate, please visit the Audio reCAPTCHA study web site.

A CAPTCHA is a special kind of test which can be used to tell humans and computers apart. Many web sites use CAPTCHA’s to combat fraud and automated access to their services. Unfortunately, most CAPTCHA’s are based on a visual task, such as recognizing distorted letters in an image. Such a task can be quite difficult, or impossible, for visually impaired human users to perform.

In an attempt to alleviate this accessibility concern, audio-based CAPTCHA’s have been developed which require users to listen to and transcribe a short audio clip containing a series of random spoken digits. However, performance of state-of-the-art Automatic Speech Recognition technology suggests that this approach may not represent a very strong CAPTCHA in practice. Additionally, the data collected from such a test may only be used to determine the authenticity of the user, and is normally discarded once the test has been performed.

The goals of my research are (1) to develop a stronger form of audio CAPTCHA, (2) create a CAPTCHA which collects useful data, and (3) to strengthen support and adoption of audio-based CAPTCHA’s on the Web. To these ends, I am developing a new audio CAPTCHA based on a more complex task: Transcription of arbitrary speech. For more information, please contact me, or visit the study web site at the URL mentioned above.

Cheers,
Andy Schlaikjer

While we appreciate the new found consideration of accessibility by the people at Carnegie Mellon University, with respect to CAPTCHA, and recognize that audio CAPTCHA is the current state of the art, the considerable ongoing research in this area ought to bring all of us to one concern, which we must ultimately address. Audio CAPTCHA, like its visual cousin, inherently denies access to the deaf and hearing impaired population. This means that the presentation of both an audio and visual CAPTCHA continues to lock out those people whom happen to be both blind and deaf. It seems to us that greater focus ought to be placed, instead, on the development of a highly secure, non-sensory challenge response system that does not inherently discriminate against any legitimate human being, regardless of disability.

Since the reCAPTCHA team has taken considerable steps to improve the accessibility and usability of their current audio CAPTCHA scheme, let’s all help Andy with his study. At the same time, let us all remind CMU and others that, in the long run, audio and visual CAPTCHA does not afford equal access and full participation to all human beings. Instead, it is absolutely critical that a better method of authentication and authorization be devised.

Visual Verification: Trouble with Audio CAPTCHA on Twitter

We have received numerous reports from blind users who are unable to use Twitter’s audio CAPTCHA for the past several days. We ask as many of you as possible to visit Twitter, try the audio CAPTCHA and report your results in this ticket opened with Twitter’s customer support team. If you’re already signed into Twitter, it will be necessary to sign out in order to try the audio CAPTCHA again.

Urgent: Bloglines May Soon Become Inaccessible!

The Bloglines people have just come out with their beta representing the future of the service. As it stands, things don’t look very good for us blind folks with respect to its continued accessibility. Once we lose Bloglines, there will be no accessible, web based RSS feed aggregator for blind people! Let’s all urgently provide our feedback to the Bloglines team reminding them of our existence and asking them to keep accessibility in mind.

TV Guide Wireless – At Last, Accessible Online TV Listings!

If you have been looking for easy to use, fully accessible online television listings, your search is over! The TV Guide Wireless service for mobile PDA and smart phone users is just the ticket. Simply select the TV Listings link, enter your zip code and select your provider to find out what’s on TV right now. The listings are provided in a simple text format showing the channel number, channel name and title of the currently playing program. If you want to know what’s on for a different date or hour, accomplishing that is straightforward as well. This service comes highly recommended for both its usability and full accessibility to blind and visually impaired computer users. If you agree that this is the most accessible resource for TV listings, please consider submitting your feedback to TV Guide. Let’s make sure the company is made aware we are using this site, in hopes that it remains both accessible and available to us in the future.

Imagine The Dark Future of CAPTCHA and Multifactor Authentication for the Blind

If you’re blind or severely visually impaired, imagine that you wake up one day to find…

  • You compose an e-mail to your sister, only to discover you can’t send it due to a visual CAPTCHA that provides no audio playback or other reasonable accomodation. A telephone number is given for visually impaired users. After waiting on hold for an hour, the person at the other end of the line has no clue how to help you. You consider switching e-mail providers, but you wonder if your bank account balance would support such a decision…
  • You log into your bank’s web site, only to find that a new visual security scheme has been implemented without considering your need for equal access. Since there is no reasonable accomodation for you as a blind person, your username and password are no longer sufficient and you have lost the ability to access something as simple as the balance of your own checking account! Since you do not live with a sighted person, you’re out of luck for a few days until you can find one with whom you trust with your personal bank account. Personal web surfing, for any reason, is not permitted at the office, so a co-worker is not an option.
  • You decide to log into PayPal to check your account balance there, only to find that the PayPal Security Key is now required for all customers! You never got one of those because the numbers it displays are only delivered visually. You assumed it wouldn’t be a requirement, or that accessibility would be considered before that happened. You’re now also locked out of your PayPal account! You give up, get showered, dress and leave for work…
  • At the office, you find yet another nasty surprise. All computers are now equipped with a visual display token for purposes of authentication and heightened security. The token displays a sequence of characters you must enter, in addition to your existing username and password, in order to be granted access to your work computer. Furthermore, due to the high security nature of the job, this process is required once every hour and anytime you leave your desk for breaks, lunch, etc. You suggest asking a supervisor for help with this process until it can be made accessible, but your employer sees fit to go ahead and get rid of you instead. Accomodating your needs would just be too much of an “undue burden”… You’re fired!
  • You return home to begin the process of applying for Social Security, Unemployment and other welfare benefits, only to find that most of the web sites require solving a visual CAPTCHA. You’ll have to go down to these separate offices in person! Getting assistance in person is an absolute nightmare! After waiting in line at Social Security for an hour, the agent says she is too busy to help you due to the need to serve other clients and, anyway, isn’t all this done online nowadays? You’re given a bunch of paperwork to have filled out by some sighted person, one of these days…
  • It takes so long to find competent sighted help that you don’t start receiving any welfare benefits for almost two months! In the meantime, you have lost your house and are now living in a homeless shelter! You can forget about another job, as most employers now require secure visual authentication, and most job related computer applications are virtually totally inaccessible to blind people…
  • Most assistive technology companies have since gone out of business, due to the implementation of visual authentication and the almost total lack of mainstream technology that even approaches any level of functionality with screen readers. Only a single company remains, delivering a screen reader to the few remaining blind government employees who retain their jobs by a thread. The Federal government is dying to be granted the ability to use the same visual authentication scheme as that employed in the private sector, if only they could successfully get Sections 504 and 508 of the Federal Rehabilitation Act repealed. There are national security reasons for doing this which clearly trump the needs of a few blind people. Congress and the President are in negotiations to make that happen any day now…

We should be afraid, be very afraid, of the clear and present danger posed by inaccessible CAPTCHA, visual only multifactor authentication schemes and other technologies that do not reasonably accomodate our needs. Our fear should not result in our cowering in a corner waiting for it to happen. Instead, we must become angry enough to start really doing something about it! Anger is not always a bad emotion. It is often a response to injustice, which we can choose to channel into taking positive action. As a blind community, are we up to the challenge of absolutely insisting that our need for equal accessibility be reasonably accomodated? As a blind individual, what actions will you take right now and later to ensure a brighter, more accessible future for you and your blind brothers and sisters? Don’t choose to remain in the dark one more second! Please feel free to take our poll on accessibility and provide your feedback by way of posting a comment to this article.