4 ms·
I think it is best to design your own captcha around your use case. All you need to do is make the amount of work for spammers too high for targeting your site.
by no_gravity 7y ago
I think it is best to design your own captcha around your use case. All you need to do is make the amount of work for spammers too high for targeting your site.
Just recently, I added the idea of a captcha that might actually be enjoyable for users to my list of "things that should exist":
http://www.gibney.de/things_that_should_exist http://www.gibney.de/things_that_should_exist
The idea is to show the user a random image and ask what is on it. If the image is beautiful, that might even be fun. And there are many sites that offer beautiful public domain images. And have tags for everything in them.
There probably are many other funny and enjoyable captcha ideas one could implement.
- Theodores 7y agoExactly. Plus with your use case there may be other criteria, for instance, if you have an 'apply now' job application form you can take in other data such as how long it took for someone to fill in the form and where their IP address is. If you are hiring for a job in London and you are not likely to hire the office manager from Timbuktu who spends less than ten seconds uploading their CV and writing some cover letter then you can make your backend form processing not forward that email on to the HR department. Putting a timestamp in the form as a form field with it encoded is easy. On the submit side you can unencode it and come to some judgement on the matter. There is also the hidden checkbox with 'hideit' set to 1, not sure why that works but it does with a form you have written yourself, i.e. not stock Wordpress. Although we don't like Google doing their deep-stalking of the visitors, fingerprinting them in re-captcha, there is no harm in collecting a little bit about the user. The user agent, screen size and location is useful in a sales/support perspective. If someone has a posh computer that says something about them. If they are using an old copy of a Microsoft browser then that says something about them. On a general forum there can be standards of English to enforce. If someone is not using capital letters to start sentences, not using punctuation and not spelling so well then that can be flagged before they hit the 'send' button. I have done a lot of tidying up of email lists created by bots and what surprises me is how easy it is to spot the fakes. It is like the bad guys in movies and games, doing everything possible to make it easy to get 'em. If spammers did real world robbery they would carry a bag labelled 'swag', be wearing 'Groucho glasses' and a stripey jumper.
- zbaylin 7y agoPassThePopcorn has a similar CAPTCHA-like implementation to the Pexels one you mentioned in your article. It has a repository of movie posters (which I think are user submitted to the movies themselves), one of which is chosen and the user is asked what movie the poster is for. I've always thought of that as an "enjoyable" CAPTCHA.
- viceroyalbean 7y agoGazelleGames does that with game covers. Lichess has one where you need to find a checkmate in one move. It's usually pretty easy, but could in theory be frustrating for someone just starting with chess.
- Fej 7y agoI've always thought this is a terrible CAPTCHA, not because it's hard but because one could reasonably write a bot that simply reverse image searches the movie poster and picks the closest response.
- xioxox 7y agoI had one of those answer a question boxes on my MoinMoin wiki. It was something like, "Enter an element which combines with oxygen to form CO2". The spammers worked their way round that pretty quickly. There must be humans who are working on helping the bots.
- dbjorge 7y agoRolling your own CAPTCHA is very, very likely to introduce accessibility issues for your site. It is the accessibility equivalent of "rolling your own cryptography" for security. Among surveys of screen reader users, CAPTCHAs are regularly listed as the single most frustrating part of trying to use web sites via assistive technology. Even if a CAPTCHA does offer a non visual alternative, it is very common for it to be inaccessible for folks with cognitive disabilities (eg, dyslexia) or motor impairments. Another common issue is assuming that users all speak English fluently. In this example, "beauty" is likely to be sufficiently culture specific to cause localization challenges. https://www.w3.org/TR/turingtest/ https://www.w3.org/TR/turingtest/ is a good resource for learning about the accessibility implications of many common types of CAPTCHA implementation.