savannah-hackers-public
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Savannah-hackers-public] captcha insufficient


From: Karl Berry
Subject: Re: [Savannah-hackers-public] captcha insufficient
Date: Sun, 18 Sep 2011 21:38:42 GMT

    I'm a little confused, you want this on the registration page?

That's what I was thinking, yes.

    If the captcha isn't stopping them, 

My thought was that spammers very likely can automate captcha reading.

And I don't want to propose making the captcha harder, either -- I have
seen captchas which I cannot make out, and I was more or less human the
last time I checked :).  (address@hidden ticketmaster!)

    then I don't think also asking for the current month will either. :(

I think we should keep the captcha, don't get me wrong.  I expect it
shuts out more than any other single question.

I was suggesting an additional question whose answer be the integer
which is the sum of the GNU announcement year *plus* the current month.
That requires a human to read a web page and understand some
instructions -- another barrier.

And the answer changes over time (unlike before, when it was just the
announcement year), so they can't just learn the static answer and
spread it around among themselves.  That is what appeared to be
happening before.

Maybe eventually we'd have just as many problems as we had before, but
.. maybe not.

    Are you suggesting adding a captcha every time a new patch/bug/support 
    item is submitted or updated?  If so, I think that may get a little 
    annoying to users.

Totally agreed.  Not suggesting that.

    What do you think the ideal solution is?

The above is my best idea that I heop would shut out max spammers while
not being unduly painful for real users.

In addition, no matter what we do on the registration page, I think we
will have to monitor newly-added items.  I plan to set up a script for
that.  I'm just hoping to minimize the number of bad guys getting in.

Thanks,
k



reply via email to

[Prev in Thread] Current Thread [Next in Thread]