5 ms·
If a CAPTCHA is the only thing keeping your site secure from abuse then I think you have larger problems.
by chickenfries 8y ago
If a CAPTCHA is the only thing keeping your site secure from abuse then I think you have larger problems.
- wild_preference 8y agoIt probably eliminates 90% of it for 90% of websites, like off-the-shelf spamware hitting your blog's comments. The prevention measure you create for the remaining 10% (like a moderation queue + human review if you can afford it) is likely to only work because its workload is diminished 90% by a crude measure like ReCaptcha. Your dismissal doesn't illuminate anything. It turns out that abuse prevention is hard and costly.
- avip 8y ago> It turns out that abuse prevention is hard and costly This should come as Tshirt or coffee mug.
- spookthesunset 8y ago> If a CAPTCHA is the only thing keeping your site secure from abuse then I think you have larger problems. This is one of those pithy remarks that add zero value to a discussion. I'm curious how you would approach blocking automated access to various parts of your site?
- chickenfries 8y agoWell usually ReCAPCHA is usually used on sign in pages. You can rate limit login attempts, exponentially increasing rate limit (or just locking out) IPs that exceed allowed login attempts and analyze your logs to ban abusive IPs. Yeah, that's harder than ReCAPTCHA, but I think a lot of these big companies can afford to do these pretty basic steps. If you just want to throw some comments on your free blog and not have to moderate the comments (and honestly, how many comments does your blog get that you can't read them?) then sure, throw ReCAPTCHA on there. But there are plenty of big companies that use ReCAPTCHA.
- spookthesunset 8y ago> You can rate limit login attempts, exponentially increasing rate limit (or just locking out) IPs that exceed allowed login attempts and analyze your logs to ban abusive IPs. Rate limiting and bot blocking are two totally different things. Rate limiting only increases the cost of a bot attack. Either they need more IP's (which are dirt cheap in the black market) or they need more time--either way it is increased cost. But it won't stop a bot. Just slow it. Banning IP's might have worked back in 2000, but these days it is useless. Bypassing an IP block is trivially easy for even a low-sophistication attacker.
- tinus_hn 8y ago> Bypassing an IP block is trivially easy for even a low-sophistication attacker. Not easy for an average user though.
- Lyren 8y agoYou could rate-limit at a higher limit based on username as well. I guess a potential problem with that however is the login-blocking of high profile accounts with known usernames. Maybe only those accounts could be solved by a captcha to bypass the login-block. And if there is a solution like that, login-blocks will basically become useless & therefor also disappear.