Posted by Jonathan N. Little on 05/01/07 22:37
Chris Morris wrote:
> "Jonathan N. Little" <lws4art@centralva.net> writes:
>> The principle behind the *security* in CAPTCHA is that the characters
>> are represented as distorted binary data images of the characters
>> which can neither be recognized as characters
> ...by people. I mentioned CAPTCHAs at a talk on web application
> security I was giving earlier today, and the audience found them very
> annoying from a user perspective...
I totally agree...I was not advocating the use of CAPTCHAs just that
TP's script is masquerading as one...which it is not.
>
> The reason the majority of spam-bots don't break CAPTCHAs is not
> because it's especially difficult (several well-documented methods
> exist) but because there are enough sites out there that don't have
> any anti-spam defences of any sort it's not worth their time to try.
>
Proper server-side validation of data and simple measures to prevent
relaying is your best defense.
--
Take care,
Jonathan
-------------------
LITTLE WORKS STUDIO
http://www.LittleWorksStudio.com
Navigation:
[Reply to this message]
|