1 |
On Wed, May 27, 2009 at 3:20 PM, Marijn Schouten (hkBst) |
2 |
<hkBst@g.o> wrote: |
3 |
> -----BEGIN PGP SIGNED MESSAGE----- |
4 |
> Hash: SHA1 |
5 |
> |
6 |
> Robin H. Johnson wrote: |
7 |
>> On Wed, May 27, 2009 at 01:45:24PM -0500, Dale wrote: |
8 |
>>> Is there something besides a captcha that can be used? I hate those |
9 |
>>> things because they make no sense to me. I usually just give up when I |
10 |
>>> encounter one of these and try three or four times with no success. The |
11 |
>>> ones that look like broken glass or something are the ones I don't even |
12 |
>>> try anymore. I can't get past one of those. |
13 |
>> recaptcha [1] is very common at this point, offloads the problem to an |
14 |
>> external service, supports visually-challenged users, and includes it's |
15 |
>> own detection of brute forcing from IP addresses and subnets. |
16 |
>> |
17 |
>> If that's not acceptable to you, I'll just deploy calculus-captcha. |
18 |
>> calculus-captcha is best viewed on this page here: |
19 |
>> http://random.irb.hr/signup.php |
20 |
>> (reload a few times to see the fun they had in qualifying questions). |
21 |
> |
22 |
> The reCAPTCHA page mentions[1] that simple text recognition (with minimal |
23 |
> distortion) is easy to do with computer programs. Given that the |
24 |
> calculus-captcha are non-distorted LaTeX'ed formulas we should therefore |
25 |
> probably assume that computers can read those formulas. They only seem to have |
26 |
> very few kinds of questions (zeros of small polynomials, differentiation of some |
27 |
> trigonometric functions (only cos and sin), arithmetic), all of which are |
28 |
> extremely simple especially for a program[1]. If this CAPTCHA becomes widespread |
29 |
> someone WILL break it. |
30 |
|
31 |
As it turns out; our mailing list subscription form is not meant to be |
32 |
an impenetrable fortress and I doubt we care if the CAPTCHA service we |
33 |
are using is breakable or not (worst case the spammer uses humans |
34 |
looking for porn to fill out the CAPTCHA) The point here is to just |
35 |
make it a little bit harder to spam everyone; not to make it |
36 |
impossible, defense in depth and all that. |
37 |
|
38 |
> |
39 |
> On the other hand I like that reCAPTCHA puts your answers to use for automatic |
40 |
> digitizations of books. Unfortunately their "Stop spam, read books" message |
41 |
> doesn't make this very clear unless you already know. |
42 |
> |
43 |
> Marijn |
44 |
> |
45 |
> [1]:http://recaptcha.net/captcha.html |
46 |
> |
47 |
> - -- |
48 |
> If you cannot read my mind, then listen to what I say. |
49 |
> |
50 |
> Marijn Schouten (hkBst), Gentoo Lisp project, Gentoo ML |
51 |
> <http://www.gentoo.org/proj/en/lisp/>, #gentoo-{lisp,ml} on FreeNode |
52 |
> -----BEGIN PGP SIGNATURE----- |
53 |
> Version: GnuPG v2.0.11 (GNU/Linux) |
54 |
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org |
55 |
> |
56 |
> iEYEARECAAYFAkodvLMACgkQp/VmCx0OL2zK/QCgmt+/RincRzXtmuGNTxsE4Yd+ |
57 |
> wo8An2zcFsPPaxpzbB75lYlnFCAg1o8q |
58 |
> =glct |
59 |
> -----END PGP SIGNATURE----- |
60 |
> |
61 |
> |