4 ms·
Looking at the source code for at least the first example [0] it looks like a simple $('form').submit() would work just as well. It's all the library is doing i
by philo23 7y ago
Looking at the source code for at least the first example [0] it looks like a simple $('form').submit() would work just as well. It's all the library is doing internally (after some HTML5 form validation checks)
I suspect most slider captcha's out there are doing something similar or at the very most setting a hidden field to "true" or "1" etc. Very few are probably fingerprinting your mouse/touch movements to actually validate you're a real human being.
[0] https://github.com/kthornbloom/slide-to-submit/blob/master/js/slide-to-submit.js https://github.com/kthornbloom/slide-to-submit/blob/master/j...
- joosters 7y agoI was wondering this. Surely a captcha needs to have some form of 'hidden knowledge' that is validated only by sending something to the server for it to check - like the jigsaw puzzle captcha at the end of the article, or a 'pick the images containing a bus' kind of thing. With the slider, there doesn't appear to be anything stopping a bot client from just submitting a form and pretending that it interacted with some HTML and javascript.
- ivanhoe 7y agoIt's just not popular enough to be handled by bot scripts (yet)... and most of spam bots are not targeting one particular site so this worked for a while, just like math captcha and drag-an-image worked for a while. The moment they get popular enough for bot authors to tackle the issue, they'll stop working.
- dylz 7y agoThe sliders you generally see in the US tend to be just setting a field to true or 1. The sliders in China are doing more than the same amount of fingerprinting if not more than recaptcha, port scan your local device from your browser, and other fun things. Alibaba's sets a dozen cookies prefixed with big_brother, which I find amusing. They will let you slide once or twice, then challenge you with an actual captcha if you fail heuristics. Blocking fingerprinting scripts will result in outright failure to sign in, or being challenged with a full captcha every attempt. They also generally do not give a crap about accessibility.