I'd agree partially, but I'd comment that it's also security by diversity. If every site had a unique captcha solution requiring custom software for a defeat, the force multiplier effect of "write once, run everywhere" would be hugely diminished, and it would be much less cost effective to implement various types of spam. So, the particular security strategy here is indeed weak, but I would say that it might actually strike closer to the root of the problem than just making a really hard, but still universally applied, captcha technology.