8 ms·
Very interesting idea (the invisible captcha approach)! Since you are a contributer, can you tell us how efficient this strategy is? I mean, do you still experi
by fractalf 7y ago
Very interesting idea (the invisible captcha approach)! Since you are a contributer, can you tell us how efficient this strategy is? I mean, do you still experience advanced bots being able to still act as humans?
- jmstfv 7y agoThey still try to sign up, but none of them can actually bypass the captcha. I implemented a custom callback that returns a HEAD response with 404 to fool them (because I noticed that attacks intensified when I returned 2xx or 3xx responses).
- fractalf 7y agoTHIS is what I'm talking about :) Great work! Seems to me this is very centered on Rails apps. Would it be possible to do somethink like this for "everyone"? I have nothing agains Rails, but as a js/php/python develper myself, I wouldn't know where to begin with this..
- jmstfv 7y agoThe easiest way to start would be introducing an invisible form field [0] and on submission, checking if it is not empty. Give this form field a random name so that it wouldn't be populated by password managers. You can take it one step further and check how fast the form was submitted. If it is below the predefined threshold, it is probably a bot. [0] To hide the form field, you can use one of these snippets, interchangeably: "display:none;" "position:absolute!important;top:-9999px;left:-9999px;" "position:absolute!important;height:1px;width:1px;overflow:hidden;"
- Master_Odin 7y agoIt should be stated that you should either use the first approach (display none) or give a 0 height/width, so that screen readers don't pick up these fake fields and ruin accessibility on your form.
- throwaway_bad 7y agoUnfortunately anything screen readers can recognize as invisible, a more sophisticated bot can too.
- shakna 7y agoThere's also aria-hidden to prevent screen readers from touching the honeypot field.