codinghorror.com (iirc) was using "captcha" which never changed, you just had to enter "orange". Or was it tbray.org? Anyway, Atwood claims, that naive approach was 99.9% effective: http://www.codinghorror.com/blog/2006/10/captcha-effectivene...
My position is that ANY form of captcha which requires some action by visitor is broken by design and should not be used at all.
Simple captcha like this will stop most of the automattic not targeted attacs. And if someone decides to write CAPTHCA breaker specifically for this site, nothing can help—then you either degrade to the level than even humans cannot say what characters are on the screen or it is cheeper to hire Mechanical Turk to do the job.