4 ms·
If you want to simply limit amount of unwanted traffic, implement conventional image captcha with some minor twist. State-of-art bots do not (yet) have a human-
by altfredd 7y ago
If you want to simply limit amount of unwanted traffic, implement conventional image captcha with some minor twist. State-of-art bots do not (yet) have a human-like AI, so you will be safe(r) until someone adapts all existing bots to solve your modification.
If you want to hinder determined (but inept) adversary, impose reverse time limit: make your captcha a bit complex and deny answers, that arrive too fast. Legit users will spend a bit of time to solve captcha. Machine-learning-driven bots will blaze it. In addition to measuring speed of filling captchas you can measure amount of user time spent on other actions on your site — in process making your bot detector increasingly similar to Google's reCAPTCHA.
In general look for behaviors, distinguishing legitimate users from malicious. Hint: having Google account might or might not indicate a legitimate user, but it is probably more efficient to ask users for it directly than in roundabout way by using reCAPTCHA.