3 ms·
Hashcash just hurts people with older computers. If spammers wanted to get around Hashcash, a decent sized rig will blow through them. Hell, it would be easier
by ixwt 12y ago
Hashcash just hurts people with older computers. If spammers wanted to get around Hashcash, a decent sized rig will blow through them. Hell, it would be easier than OCR.
- atoponce 12y agoThis doesn't hold up for a number of reasons. First, the client should be actively and asynchronously working on the puzzle when the page loads, so when the submit button is pressed, the puzzle is solved, and ready to be submitted to the server. Asynchronous JavaScript has already been solved. Even for a Raspberry Pi, a 16-byte Hashcash puzzle can likely be solved before the user has finished typing in the form. Second, the point of Hashcash is to stop spammers from mass POST attempts. Form spammers rely on bots, without JavaScript, to mass POST to forms, millions of times per day. As soon as JavaScript is required, this immediately stops 90% of the bots in use, right now. Of course, they'll adapt, with JavaScript VM bots if Hashcash is the norm, which then ties up the client solving the puzzle. The longer the client is tied up, the less it can spam in a given amount of time. It _drastically_ slows down the amount of comments a spammer or zombie network can perform. As computing gets more powerful, the Hashcash minting size can be increased, to continue tying up the bots. "Blowing through them" couldn't be a bigger exaggeration and further from the truth. Third, properly implemented Hashcash is designed to prevent double spending. So, once the token is spent, it cannot be spent again. Even better implementations will not allow tokens that have not been minted within a certain timeframe, such as 24 hours. The Hashcash specification has the timestamp as part of the token. This discourages mining the tokens early, for spending later. Lastly, captchas have shown to be entirely ineffective against bots. Do a search for beating captchas, and you'll see the sad state of affairs. Captchas are getting harder for humans to interpret, because bots are getting better at OCR, and defeating them, with increasing reliability. In every instance I've deployed Hashcash into a web form, I have yet to see spam come through. In one site, as of the time of this writing, Hashcash is solely responsible for blocking 670,624 spam POST attempts in a 10 year run. The big drawback, is forcing JavaScript to be enabled, in able to POST to a form. From what I've seen on the virtual web hosts I administer, it seems to be about 10% of the web traffic has JavaScript disabled, on average. This might be acceptable, and it might not.