Then I installed reCaptcha, and now Akismet catches ~10 a month, and I've had to manually flag zero.
I'll take that illusion, thanks.
i've used defensio.com for filtering comments on my site with no captcha and rarely ever get a false positive or negative. false negatives are easy to spot, and users can manually override false positives by supplying an email address to get a confirmation link (which gets fed back to defensio as a false positive once clicked).
https://secure.grepular.com/Blocking_Comment_Spam_Using_ModS...
It's still working now.
If you're saying that it's possible to prevent manual, outsourced captcha solving, I would have to strongly disagree. It's similar to the futility of DRM as an antipiracy measure. As long as I can see the captcha, I can pay someone in another country to solve it for me.
I will agree that it's rare- but the most sophisticated and high-volume spammers do it, and they're the ones you have to worry about.
In case people start giving me sideways glances I want to make it clear that I haven't done any blackhat stuff in a very long time, but I'm still interested in the blackhat community from a security researcher's perspective.
All I have is anecdotal evidence- I know several people who are making their living spamming Craigslist and outsourcing their ReCaptcha solving. Since they can make $XX per post, paying pennies for captcha is a tiny expense. I don't condone this behavior, but be aware- it happens more than you think.
Anyway, probably best to take the discussion to email if you want more...perspective from the other side.