6 ms·
Except they don't always work. Spammers have ways to get around them, including farming it out to extremely cheap labor. I started reading Engineering Securit
by aryastark 13y ago
Except they don't always work. Spammers have ways to get around them, including farming it out to extremely cheap labor.
I started reading Engineering Security, by Peter Gutmann. Excellent book, btw. At the start of the book he discusses security theory vs. reality. One thing he describes is the "most ineffective CAPTCHA of all time" (according to mainstream security theory). This "ineffective" CAPTCHA on a blog required exactly one thing: the user had to enter the word "orange."
Surprisingly, the blog received zero spam. The reason it's so effective is because it's different. Whereas CAPTCHA is a monoculture. Standard CAPTCHA fits into the economic model for spammers. But for spammers to adjust their behavior for just this one blog? It's not worth it for them.