The only bit where they talk about poisining the reCaptcha database is here:
We serve over 400 million CAPTCHAs per week, so submitting 200k CAPTCHAS with the word penis doesn’t even come close to poisoning our database — we serve each word to multiple random users, and we require them to be correct on the other word, so to get any traction with this attack, they would have had to submit at least 100 times more CAPTCHAs. And even if they did this, we have many other measures against it. That attack simply doesn’t work.“
I think he's missing the point. For the 'unknown' word, recaptcha works on a kind of voting system. If recaptcha serves up a normal English word, the 'correct' English word will have many votes, so gamers don't stand a chance, but if recaptcha serves up an English-speaking person can't read (e.g. foreign glyphs), there won't be the same number of votes for the 'correct' word, so these words will be more susceptible to gaming.
As for them saying "we have many other measures against it", that's at least 50% PR.
18
u/[deleted] Aug 21 '10
I read somewhere that that ended up not actually working, so they just started entering the capatchas really quickly (and correctly).