So for most sites, it'd probably be a good idea to put things like this in place but then to also be ready to roll out reCAPTCHA at any given moment, in the event a serious spam campaign begins.
So for most sites, it'd probably be a good idea to put things like this in place but then to also be ready to roll out reCAPTCHA at any given moment, in the event a serious spam campaign begins.
But the people writing bots really do not want to have to tweak their bot for any single site. And most of the people using bots cannot write their own.
I've been using a very simple negative captcha for many years with great success. I just don't get bot spam, and before I put it in place I got lots of bot spam.
There are some gotchas, though -- the main one that this project doesn't seem to know about are form-fillers, like Google Chrome, RoboForm, etc. -- i.e., bots that you want to be able to use your form.
My first version of a negative captcha tried to be sneaky -- I called the field "name" or something like that, and called the real name field "name2". This was a disaster; the form-fillers all put values into the name field, and suddenly tons of users (especially Google Chrome users) were unable to submit comments to me... and so quite probably a lot of them were unable to find a way to even tell me it was broken. Problems like this are a very good reminder to always use helpful, kind error messages even when you think you've just caught a spammer or some other nasty. You may have caught an actual customer.
My current version names the field something obviously NOT a standard field name, and gives it a label which is also not a standard field name (this was important), and I even clear the field with JavaScript on form submission just in case. The name of the field is hard-coded, as are all of the other field names on the page.
I have been ready to roll out more clever versions, but the years go by, and there's still no need yet.
Unless you have a site that's a big target for bot spammers, I highly recommend you just roll your own, and leave it extremely simple unless the spam returns (someday it will, presumably, but it has been at least 6-7 years and I'm still on the so-simple-it's-silly version).
This library could work with some tweaks and simplification, but currently I'd worry about form-fillers in real users' browsers. It hashes all of the real field names and makes the honeypot fields look valid. So a user who is accustomed to having their name/address filled in will first find that function is broken -- next they'll find themselves accused of being a bot when they submit the form (after tediously filling it out by hand).
I speak from the perspective of someone who often creates websites that various groups of people, for whatever reason, would very much like to cause chaos on. I use "spam" to mean both "advertising spam" as well as "distributed flooding" (sometimes in the form of so-called "shitposting", and/or just random text and images).
Heavy spamming can be an effective form of DoSing if it's not limited or controlled well enough. There are many people out there who take great personal pleasure in disrupting or reducing the quality of a service.
If you want to protect against typical pharma spam, this will be good. If you want to protect against the kind of thing I described above, then only a service like Cloudflare can help, and even then it can only help you so much.
(It's not easy to bypass Cloudflare from a straight bandwidth DDoS perspective, but it's not too hard if you just want to get through its anti-bot filtering to post spam. In such a case you can enable reCAPTCHA from the Cloudflare security panel, though.)
That's a hell of a lot of spam.
What's interesting is that they do seem to monitor the result. If I leave the succeeded spam comments for a while, the attacker adapts their strategy to follow the succeeded pattern. (Usually the initial attempts are just a neutral comment, irrelevant to my contents but doesn't contain any URLs or product names. Once it penetrates, they start spamming with URLs.)
I'm not sure if there're human behind this, monitoring bots activities, or bots are actually sophisticated enough to adapt.
Protecting forums is particularly hard because there are often real people involved in spamming them, sometimes with the aid of bots but not always. Some of them will fill in captchas, register user accounts, and post spam links along with half-assed original comments. Negative captchas are obviously useless against these; I've managed with having logs of moderators, but it's still unpleasant.
For a long time, I protected my blog comments with a simple "captcha" that was just a field labeled: "Enter the word elbow." The word wasn't even dynamic, it was just "elbow" every time. This still worked to filter out nearly all spam for years, because my site wasn't popular enough to merit any specific attention.