How Not to invent the next-gen CAPTCHA
lbrandy.com
lbrandy.com
I wrote a plugin years ago for MovableType as a proof of concept (which I still use on my own blog): http://www.blahedo.org/botblock/ Even a user that doesn't want to touch any of the code (even though it's pretty easy) can always edit "Add one to this number:" to "What number comes after this number:" or somesuch. To solve the "more humans on this end" problem, it seems like you have to let them modify the very questions themselves.
The question "RAND(1,100) + RAND(1,100) = ?" may represent 10,000 distinct questions, but the effort to answer them is only marginally greater than the effort you spent in writing it. Basically every CAPTCHA approach based on "I'll just have a bank of X" (questions, images, etc) will fail, because the spammers can classify faster than you can add to the set.
Note the "conventional" CAPTCHA, which has stood the test of time, doesn't have a "bank" of anything, it generates fresh stuff all the time. ReCAPTCHA has a bank, but it's structured to be way larger than any set of questions you will ever pull, and is also cleverly set up so that they still benefit a bit even if it is "broken".
I'm also not sure I'd say that the "conventional" variety has "stood the test of time". I still see sites using them, but many of them are now so hard for humans to make out that you have to make multiple tries. And that's if you're a human with good eyesight and full cognition. The audio captchas out there are loud and obnoxious and mostly incomprehensible.