I appreciate the sentiment, as I had it, but rest assured any future publicly accessible form I build will get at least a CAPTCHA in front of it.
I appreciate the sentiment, as I had it, but rest assured any future publicly accessible form I build will get at least a CAPTCHA in front of it.
I did once run into an issue where a signup form was abused by a spammer, but that was a simple fix (tip: in verification emails, do not include any information that the user typed in the form).
If you are careful with your forms, you don't need captchas. Captchas add a lot of friction for some users, so if they can be avoided, they should be.
Proof of work isn't a CAPTCHA.
or was it more complicated, like not needing to store which fake account had which details?
Hi <name>, thank you for signing up...
The spammers put their spam message in the name field, so my server started sending messages like this:
Hi Get free cialis now http://example.com, thank you for signing up...