Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] CAPTCHA on keitai
- Date: Mon, 24 Mar 2008 13:09:19 +0900
- From: Curt Sampson <cjs@example.com>
- Subject: Re: [tlug] CAPTCHA on keitai
- References: <47DE0C71.1010107@articlass.org> <8763vlikfm.fsf@uwakimon.sk.tsukuba.ac.jp> <d8fcc0800803171606u42d3e8afle0d8f4a51a10f076@mail.gmail.com> <87k5k0r2s1.fsf@uwakimon.sk.tsukuba.ac.jp> <d8fcc0800803172314pe18074fxbc03ad0d6e686473@mail.gmail.com> <87d4psqynb.fsf@uwakimon.sk.tsukuba.ac.jp> <20080318093415.GD2593@lucky.cynic.net> <87lk4fvder.fsf@uwakimon.sk.tsukuba.ac.jp> <20080322090057.GG5267@lucky.cynic.net> <878x0afsj9.fsf@uwakimon.sk.tsukuba.ac.jp>
- User-agent: Mutt/1.5.17 (2007-11-01)
On 2008-03-23 04:49 +0900 (Sun), Stephen J. Turnbull wrote: > Curt Sampson writes: > > > Indeed, very true. To restate my point, given that they certainly have > > the capability to write software that will get around your particular > > form of protection, what makes you belive that they will take even a > > minimal amount of effort to do this for your site rather than just aim > > their automated systems at plenty of other sites out there that use more > > standard systems? > > (1) As (dark-side) hackers, they take pride in their dirty deeds done > dirt cheap. They'll do this for hate, not money. Do you have any evidence for this point? Let me present some to the contrary. According to Jeff Attwood: The comment form of my blog is protected by what I refer to as "naive CAPTCHA", where the CAPTCHA term is the same every single time. This has to be the most ineffective CAPTCHA of all time, and yet it stops 99.9% of comment spam. http://www.codinghorror.com/blog/archives/000712.html As another anecdote, ever since I switched the software on the keitai-dev wiki from Meatball Wiki to something much less common, my previously enormous spam problems have gone away. I have no captcha (or any other attempt to prevent spam) in place at all. > (2) My main point is that it's unlikely that the standard is all that > standard that deviating from it in a "significant" way is all that > easy. Remember our side is fairly constrained in how we can hide > stuff, because our users have to be able to see it. Not at all. For example, you can freely change the names of your form input fields to anything you like; your users never see those (except perhaps in the URL of a GET request). That one change alone may well stop a program, if few enough other people are doing it that they've not bothered to try and work out some automated way of dealing with new field names. > > Well, if the spam problem is any indication, you're not likely to get one. > > The spam problem is harder because neither postage nor authentication > is acceptable to most spam-fighters. > > I think either audio: "Type D O G B E R T in the box", or Josh's "what > is this image a picture of: cat dog car rabbit spammer-in-a-blender??" > are big (fairly) cheap wins. They're not; they've all been beaten. If the common spam-sending programs are not defeating them, it's merely because they're not widely enough used to make it worthwhile. cjs -- Curt Sampson <cjs@example.com> +81 90 7737 2974 Mobile sites and software consulting: http://www.starling-software.com
- Follow-Ups:
- Re: [tlug] CAPTCHA on keitai
- From: Stephen J. Turnbull
- References:
- [tlug] CAPTCHA on keitai
- From: Dave M G
- [tlug] CAPTCHA on keitai
- From: Stephen J. Turnbull
- Re: [tlug] CAPTCHA on keitai
- From: Josh Glover
- Re: [tlug] CAPTCHA on keitai
- From: Stephen J. Turnbull
- Re: [tlug] CAPTCHA on keitai
- From: Josh Glover
- Re: [tlug] CAPTCHA on keitai
- From: Stephen J. Turnbull
- Re: [tlug] CAPTCHA on keitai
- From: Curt Sampson
- Re: [tlug] CAPTCHA on keitai
- From: Stephen J. Turnbull
- Re: [tlug] CAPTCHA on keitai
- From: Curt Sampson
- Re: [tlug] CAPTCHA on keitai
- From: Stephen J. Turnbull
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] recommendations for user friendly CMS (with VMware?)
- Next by Date: Re: [tlug] recommendations for user friendly CMS (with VMware?)
- Previous by thread: Re: [tlug] CAPTCHA on keitai
- Next by thread: Re: [tlug] CAPTCHA on keitai
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links