3 ms·
It's literally impossible to detect any kind of decent bots without JS, so it's absolutely necessary
by FrenchDevRemote 4y ago
It's literally impossible to detect any kind of decent bots without JS, so it's absolutely necessary
- sylware 4y agothat cure is worse than the disease.
- FrenchDevRemote 4y agoyeah no. The disease is: -24/7 credential stuffing on all the accounts of everyone, everywhere -99% of spam content on 100% of the websites you visit -websites down all the time because of DDOS -10-100X hosting costs for sites because of bad bots The problem is not JS, but what they do with JS.
- atoav 4y agoI have a single question on a blog contact page for roughly 5 years now, that can be answered with a google query and is extremely permissive about how you write the answer. I have not received a single spam message on that email address as of now (quite a few actual comments tho). Granted: people who don't manage to put in the time to answer the question are not people who I am interested in — a stance which a government website cannot afford — but there are ways to solve this sufficiently without Recaptcha. If your forms are juicy goals for targeted attacks this might be a different matter, but how about just paying a bunch of devs to program it for your state and open-source it?
- FrenchDevRemote 4y agoWell exactly, you're a low value target, a 0$ value target, a bad actor would actually loose money by trying to spam you, so of course no one even tried, but you could be spammed to death in less than a hour of work >If your forms are juicy goals for targeted attacks this might be a different matter, but how about just paying a bunch of devs to program it for your state and open-source it? Because it's a really hard problem and it would cost a lot of money while probably not even being really effective, and reducing your revenue at the same time because your UX is probably a lot more terrible than the existing solutions? +BTW the captcha in recaptcha is not even the main value of this service, the main value is the bot detection algorithms that run before/during/after the captcha, which gives you a "human/bot" score before you even filled the captcha Good luck reproducing that in every company that needs it. It would cost a ton of money with really lame results most of the time
- atoav 4y agoAs I said: I am not a juicy target. Yet I see other non-juicy targets deploy captchas like there would be no other way. My issue with this is: Every public government website on earth is going to have this problem. The obvious solution is that governments invest public money into solving the problem resulting in public code. Sure a way has to be found how governments can build and maintain digital infrastrucure, maybe on a state level, maybe on a multinational level, beyond just a one-off thing.