4 ms·
Is the spam very specifically targeted at your site? If not, just implement your own very simple captcha system and see if they can handle that. Spammers gener
by computer 13y ago
Is the spam very specifically targeted at your site? If not, just implement your own very simple captcha system and see if they can handle that.
Spammers generally use captcha solving APIs which map to humans in low-wage countries. They pay ~$2/1000 solved captchas (a few years ago, not sure what it's like now.)
If you're not a specific target, changing your captcha might be enough to no longer easily be a victim of such a service without changes to the spammer software.
- Prefinem 13y agoI am not sure how to tell if it targeting the site. I will look into creating another captcha to see if that will help
- computer 13y agoPerhaps as an experiment try "enter the first character of your post/comment". That would kill any remote human captcha solvers (since they don't actually know the post content), and likely require some rewriting of the spamming software, assuming that is automated. Of course, this is not a long term perfect solution against motivated adversaries, but it's a way to see how the current spammers work. Another: Add a keydown handler to your message-textarea and log (to a hidden form field) how many key presses are being used per post. If the spam software is setting the content field programmatically, you then know how to detect them.
- Prefinem 13y agoThat is a great idea... much simpler than I had imagined. I will implement this tomorrow to base off results from today
- deleted 13y ago[deleted]
- qu4z-2 13y agoThey're both good ideas, but bear in mind that the keydown detection may trigger under other conditions (eg I use a plugin to let me edit text fields in external vim. People pasting quotes/urls could also be odd keystroke numbers)
- Prefinem 13y agoI could just check for 1 or greater. I wouldn't have to check for an equal amount