2 ms·
Timing form completion also rejects legitimate users that have form filling extensions (e.g., LastPass, 1Password, Roboform, etc.) In my experience hidden form
by jaredmcateer 12y ago
Timing form completion also rejects legitimate users that have form filling extensions (e.g., LastPass, 1Password, Roboform, etc.) In my experience hidden form fields were only marginally effective, a lot of bots run headless browsers capable of detecting if a field has been hidden by JS/CSS
- timr 12y agoBetween a simple captcha and a CSRF token, I've found that nearly all spambots are defeated. Hidden form fields don't do much, since bots are almost never paying attention to anything other than the DOM. What can work well -- if you're willing to give up on fallback for non-JS users -- is inserting a required form element into the page with JS on submit.