3 ms·
One time tested approach for me is to very precisely measure how long the fastest human could fill out a specific form in ms (must be done per form, and must co
by hashtree 13y ago
One time tested approach for me is to very precisely measure how long the fastest human could fill out a specific form in ms (must be done per form, and must consider browser autofilling). Then, include an encrypted timestamp value as a hidden field value on said form and check that:
1) The form was recently submitted (i.e. you cannot submit forms from two hours ago). Done well with another approach I take, this also catches bots that try to resubmit already cracked form instances. This is a bigger issue than you might give it credit for. Often they will crack a form instance by hand and then submit variations of fields they care to spam in programatically. Crack once by hand, submit spam 10000 times automatically therafter.
2) That the delta between receiving the form submission and when it was generated is greater than how long the fastest human would take.
It has a throttling effect to spamming (if nothing else), in addition to preventing most programatic spam. It is also nice that it does not depend on client-side javascript that can be tampered with. Used in combination with some other approaches, I have several sites that serve millions of users a year that all but remove the need for captchas (contact me if you are interested).
- ghostdiver 13y agoThat's good approach and it just works.
- Prefinem 13y agoI was thinking about this, but the form submission could honestly take less than a second by a person since all you have to do is type a comment. (Thinking of someone posting 'lol') to code. I have had users complain when they can't post fast enough (generally when two or more are in a vivid discussion) and always end up turning off the "wait between posts" check for forums like vB, xF, phpBB, etc.. Do bots submit instantly? Would just inserting a timestamp with javascript fix it?
- hashtree 13y agoIt has worked for me with forms that take less than 1000ms. For simple one field forms, they typically have a reasonable length requirement on my platforms (e.g. 32 characters). Things that fit in less than that length are typically things that should be tags (e.g. funny, insightful, etc). Trying this 32 char minimum myself just typing jibberish gets me over the minimum needed time to detect bots.
- Prefinem 13y agoI see... that makes sense... I will have to check with some of my user base and see how they feel about this