CRAPCHA: Completely Ridiculous And Phony Captcha that Hassles for Amusement
crapcha.com
crapcha.com
That takes time and effort, something which is often in short supply. Easier to just slap any old captcha on there, even a mostly ineffective one will stop the drive-by scripts.
I had to implement a non-CAPTCHA method of stopping spammer signups to our forums, and after a day of work I had something that still let through 2-3 spammers a day. A CAPTCHA would have taken under an hour (plugins available) and probably have stopped more.
/s
If you can come up with something else that can distinguish legitimate users and bad guys, you'd be a very popular guy.
Oftentimes, a simple JavaScript-based spam protection is enough.
Pure evil!
If you have a decent site, you can afford to review/delete/block spam afterwards, but if you have a small site and don't babysit it every dey, then a tough captcha is an absolute requirement.
I run a phpBB forum and 2 blogs. They got the standard spam like everyone else. Once I installed Spam Destroyer for Wordpress and made a 3-line JS-based modification for phpBB, I reduced spam by approximately 99,99%.
My main Web App gets something like 40,000 visits per week and is online since 2006. I never bothered with a CAPTCHA and there are hardly any spam signups. Same JS-based spam protection mechanism.
For years, I had a non-captcha on my blog that simply read:
Enter the word "elbow": ________
That was it. The word was hardcoded, and the server simply checked to see if that input field did, indeed, contain the word "elbow". Spam completely halted for a long time. Eventually, it started showing up again, and once I got tired of deleting a couple of spams per week, I changed it to: Enter the word "humour", but with American spelling: ________
Once again, spam stopped for a long time. As a bonus, I had a couple of commenters complaining that not everybody was a native English speaker and this question was too hard. I say "bonus", because I like keeping away commenters who can't be bothered to spend five seconds on Google.This started to break down eventually as well. My latest effort, done more for fun than effectiveness, is to implement a hashcash proof-of-work system in Javascript. In short, the server sends a random salt to the client, and the client must then come up with a string which, when concatenated with the salt, has an SHA-1 hash with a certain number of leading zero bits. This is easy to verify (the server just takes the client's result, performs a hash, counts the leading zero bits) but hard to produce (the client has to brute-force it).
The relative slowness of JavaScript crypto makes this not actually very useful in a theoretical sense. I've calibrated the difficulty to take about 20 seconds of work in the browser, but a decent native code implementation can do the same amount of work in maybe a tenth of a second. So, against a determined attacker, it won't be much of an obstacle.
But as a relatively small site with a completely custom anti-spam solution, I don't get determined attackers. I get the occasional spam message with this in place, but from the server logs it's obvious that it's actual real human beings firing up the comment form and waiting the ~20 seconds for the hashcash to complete before posting their comment. Terribly inefficient for them, and it keeps stuff down to a manageable level.
In summary, if you have a small site, you can throw up nearly any custom anti-spam measure, no matter how silly or easy, and have it be effective. A standard captcha may be easier to add than a non-standard anything, but it's definitely not an "absolute requirement". Big sites are completely different, since they'll attract enough spammer attention for site-specific attacks.
Literally hyperbole.
It totally wasn't the most pleasant experience.
Sure, the computer does not get it 100% of the time, but it gets it more often then me, and fails faster.
It wasn't until the social virus was released on 4chan that uploaded itself, along with any random file it happens to find in Documents or other sensitive areas publicly, that the captchas were put in place.
This evolved to the point where they started selling 4chan as a service without a captcha (I'm actually all for that).
Sometimes there is just no way around the problem.
Okay, not every CAPTCHA, but a scarily large amount of them are just plaintext with fancy formatting. Occassionally I see one with an actual image, but with the plain text as part of the image URL.
So this is actually easier to solve than the audio mode of reCAPTCHA.
$('.crapcha').each(function() {
console.log(['Crapcha',
$.map($(this).find('span'), function(letter) {
return $(letter).text();
}).join('') ]);
});Compile and release the statistics to your evil deed on HN.
My favorite captcha experience: it only checked the first 3 characters matched (as in only enter the first 3 of a two word captcha). I supposed maybe I misunderstand how they work but I would have thought they checked against at least one full word.
That would have been the "workaround".
I frequently have to click reload half a dozen times or more before I find one that I'm able to decode.
I think there is an opportunity for user experience improvement when it comes to stopping bots.
http://mashable.com/2013/04/17/crapcha/
http://thomaspark.me/2013/04/crapcha-completely-ridiculous-a...
Except there does seem to be one old duplicate of the exact `http://crapcha.com/` one. Perhaps it allows a re-post after enough time has elapsed.
So it's an intelligence race. The more intelligent system (a computer, human, or hybrid) will be able to deceive the lesser intelligent system (computer, human or hybrid).
So the problem changes from: "Is the entity I am dealing with a computer or a human" to: "Does the entity I am dealing with have intentions to gain an unfair advantage over this transaction."
Humans have a part of our brain where we look for how others might be taking advantage of us, the algorithms and data structures there are remarkable. Computers will need to acquire those abilities if they are to manage the exchange of money, goods and services.
When machine intelligence advances that far, we'll be able to easily automate human-level examination of every single comment or submission or whatever. So I think the problem will get better, not worse, with that level of power.
Maybe put this at the last step of something the person really wants?