3 ms·
Most CAPTCHA's nowadays I find unnecessarily complex. Use tricks like timing form completion (<50ms? Bot), hidden fields, etc, before ruining the UX with CAPTCH
by KhalPanda 12y ago
Most CAPTCHA's nowadays I find unnecessarily complex. Use tricks like timing form completion (<50ms? Bot), hidden fields, etc, before ruining the UX with CAPTCHA.
Then again... does HN really care about UX? Token expiration after x time when browsing through the listings, ancient unresponsive design, etc.
There comes a point where it'll be more cost effective for spammers to just farm out the solving of CAPTCHA's to people in third-world countries. It just depends if there is enough value in spamming HN for them to bother (probably not, given the user-curated-and-rated content model.
- jaredmcateer 12y agoTiming form completion also rejects legitimate users that have form filling extensions (e.g., LastPass, 1Password, Roboform, etc.) In my experience hidden form fields were only marginally effective, a lot of bots run headless browsers capable of detecting if a field has been hidden by JS/CSS
- timr 12y agoBetween a simple captcha and a CSRF token, I've found that nearly all spambots are defeated. Hidden form fields don't do much, since bots are almost never paying attention to anything other than the DOM. What can work well -- if you're willing to give up on fallback for non-JS users -- is inserting a required form element into the page with JS on submit.