“Stop Spam, Draw Shapes”
josscrowcroft.com
josscrowcroft.com
I used to get a TON of spam on my website(s) until I threw in a hidden text field. When the form is submitted I assume the submission is spam if the hidden text field's value isn't blank. I don't get spam anymore and people don't have to mess around with a captcha (plus nobody's complained).
...although I'm sure it's only a matter of time until the spammers figure this technique out.
I use the "honeypot" field trick as well, and really like it, but this approach has some problems worth mentioning.
For one, make sure you give real users a way to contact you if they somehow get trapped -- you'd think it won't happen, but have you tested every available form-filler plugin out there? A few months ago Google released a new version of Chrome that started putting email addresses into my hidden field. Maybe Chrome thought it was a "confirm your email" field? No idea; I fixed the problem by adding an HTML label for it. But it's a damned good thing I wasn't just secretly discarding the input, or I'd have lost a lot of purchases.
Next, as you mentioned, if anyone targets you specifically, it's trivial to circumvent this with a single line of code in a bot.
There are ways to make it harder to circumvent, though -- use all random field names, insert the hidden field at random locations in the sequence of fields, etc.. I'm still using the simple approach, though, since it's still working. :)
I deal with real clients (read older people) every day and they can barely read the actual text on the screen, let alone text that is skewed and mangled in an attempt to foil machines.
This proof of concept, while pretty cool from a geek point of view, doesn't do anything to solve the problem in a better way.
Stuff like hidden fields, timestamp analysis, crowd-sourced classifiers (like Akismet), on the other hand, do.
same thing with spam comments on my site. i didn't bother with captchas or other annoying requirements like openid. it submits everything through defensio (http://www.defensio.com/) on the backend and if it looks like spam, you just have to put in an email address to manually confirm the comment and re-train defensio. otherwise people can leave anonymous comments without any hassles. the amount of comments that need to get manually verified are very low, and i never see spam get through.
Even with server-side validation, it's still trivial to break; it only requires tracking a line through an otherwise blank image.
This is fundamentally unusable as a CAPTCHA, and can't be made significantly better. The whole point of a CAPTCHA is to be difficult for computers and doable for humans, hence stuff like warped characters and image categorization. Tracking a line against a blank BG is not difficult for a computer.
V1.0 will combine it with a standard PHP captcha, which is replaced onload.
I get that it's a proof of concept, but it's a concept that doesn't work. You can't make recognizing a line easy for humans and difficult for a computer. The best you could do is introduce noise and make the line a shape that humans are likely to recognize... and bam, we're back at warped characters.
Certainly, not hard for spammers to break, but as long as it doesn't have widespread use, they won't bother putting in the effort.
But this can be said about almost any Javascripty custom trick, and there are ones that no effort from user and don't have accessibility issues beyond requiring JS.
http://www.joelonsoftware.com/uibook/chapters/fog0000000063....
Depending on the sensitivity, this CAPTCHA could definitely drive away users.
I'm looking to include a "Switch to default captcha" option for those concerned with usability (myself included)
You need a lot more shapes… but there aren't many shape/size/position combinations that are easy for humans.
You need complicated images, as plain shape/background (and in general shapes on background that are separable on histogram) are easy to trace.
I'm afraid that nice gesture recognition algorithm is not enough to defend against bots programmed to recognize known solutions & replay (slightly randomized) predefined answers.
For whatever reason I don't have the dexterity to draw a correct shape very quickly :-) That suggests if the captcha was used a lot (like every time I submitted a comment or something) I would quickly become frustrated and stop participating.
But I was proven wrong: http://i.imgur.com/QO8pY.png
This looks pretty sweet, I wonder how the shape matching works.
https://skitch.com/jameskilton/fdcir/motioncaptcha-demo
It's a good idea, just needs to be a little more on the lenient side for those of us who aren't artistically inclined.
Edit: Hmm if you go faster it has a fuzziness to it: