[dokuwiki] Re: Anti spam brainstorming

  • From: "Gabriel Birke" <gabriel.birke@xxxxxxxxx>
  • To: <dokuwiki@xxxxxxxxxxxxx>
  • Date: Fri, 10 Nov 2006 10:26:10 +0100

Hello,

Manni from chongqed.org [manni@xxxxxxxxxxxx] wrote:

> CAPTCHAs work. 

Please let me rephrase this: "CAPTCHAS work as long as they are not
widely deployed and no progress is made in the field of pattern
recognition and artificial intelligence." The thought behind CAPTCHAS is
to present a "puzzle" that humans can solve easily (e.g. pattern
recognition) but computers can't. There is an arms race going on and my
estimate is that CAPTCHAS will be only slightly effective for one or two
years maximum. See these links:

http://sam.zoy.org/pwntcha/
http://en.wikipedia.org/wiki/Captcha

> You could simply include some _text_ that users 
> must copy and you will beat 100% of all bots out there 
> without annoying any of your users, even those with visual 
> handicaps, too much. Something like "Please type these three 
> letters: XYZ". You can make those three letters random, but 
> today, even three hard-coded letters will work.

... until a slightly motivated spam script programmer comes along.
I could write a circumvention script for text queries in a day - give me
a week an I could make it sophisticated and configurable with a plugin
architecture for every text-only technique you can think of, tailored to
specific sites. Text can be parsed and analyzed too easily. 

BTW, I am NOT programming spam scripts, I just wanted to point out that
text captchas are ineffective in the long run.

Graphic CAPTCHAS *may* give us some breathing room.

Greetings,

Gabriel

-- 
DokuWiki mailing list - more info at
http://wiki.splitbrain.org/wiki:mailinglist

Other related posts: