Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Have CAPTCHA's got harder?

Featured Replies

Just a question thats annoying me... have they got harder? Or are my eyes getting worse...

 

A few years ago i could easily do them, now im having to refresh about 10 times just to get something thats legible...

 

or the flipside, are bots getting cleverer...

Def getting harder,im the same having to refresh half a dozen times...i could prob get em first time if i had a few beers.

Yes, they're getting harder, but they don't need to. It's poor design on the developers' part in my opinion. My own forum uses an image captcha. You see two images, one complete, one scrambled. Simply arrange the scrambled image to look like the complete image, and you're in. No trying to read out of focus squiggly text with no contrast for my punters! :)

Edited by notbanksy

Yes, they're getting harder, but they don't need to. It's poor design on the developers' part in my opinion. My own forum uses an image captcha. You see two images, one complete, one scrambled. Simply arrange the scrambled image to look like the complete image, and you're in. No trying to read out of focus squiggly text with no contrast for my punters! :)

Seems like a clever idea. Did you design that system yourself?

Seems like a clever idea. Did you design that system yourself?

HAHA no chance! My attempts at code have been beyond laughable. Thank god I have other talents. It's called Key Captcha. I would have linked to it in my other post, but I'd forgotten the name! https://www.keycaptcha.com/

Why don't just use captchas when a form is used a multiple times ?

Just like twitter does.

 

This way, when you want to use a contact form just to write one message those irritating captchas don't show up.

Yeah, i can hardly read it, really dislike web sites using it, I mean its a great tool, but there are other ways to fight spam, pls use :p

  • 3 weeks later...

To check spammers... It is neccessary to have harders CAPTCHA's. The robot machines or automatic machines vwere very smart to fool those easy captcha codes. So this was done for the internet's authenticity, Which is our genuine need.

To check spammers... It is neccessary to have harders CAPTCHA's. The robot machines or automatic machines vwere very smart to fool those easy captcha codes. So this was done for the internet's authenticity, Which is our genuine need.

I guess its the only way to stop spammers who use bot to register in the forum.I hate to enter captcha as a user but as a admin point of view,i can understand the importance of it.

 

anyone for irony?

  • 2 weeks later...

It's funny really; captha's.

 

I used to have one on my forms. I always found it a headache as you have to keep updating it, most all users find them annoying, they aren't great for accessibility and the cleverer spam bots still get through.

 

We always used to use captcha's and would still get spam; not constantly but at least a few times per week. So you add a security question as well; and you cut some of them out; but some still manage to figure it out.

 

 

Fast forward to today and we have this:

http://www.fizixstudios.com/contact

 

No captcha and no spam.

 

Captcha's are IMHO a poor and lazy solution to a problem.

 

 

If anyone is interested; our contact form has a non intrusive honeytrap; based on form submit speed.

 

A typical bot will load the html, wack text into the fields quickly and submit quickly (talking seconds). A typical user however will take longer to fill in a form, a lot longer.

 

For an end user to get caught up by the honey trap they will have to type like a hyperactive 3 year old. A bot however will always get caught by the honeytrap.

Interesting solution, but one that can (and eventually will) be evaded programmatically by inserting a delay in the bot.

 

I prefer using a honeypot field with a common name attribute that's hidden with CSS, and discarding all submissions with that field filled in.

Interesting solution, but one that can (and eventually will) be evaded programmatically by inserting a delay in the bot.

 

I prefer using a honeypot field with a common name attribute that's hidden with CSS, and discarding all submissions with that field filled in.

 

Your right, but at that point I'd look for a new solution. At the moment it works so they aren't doing it yet (or at least most). We register each honeypot hit and we get between 5 and 12 per day on average. Checking the IP's and message contents they are literally all spam (or a few people trying to hit the honeytrap after I've mentioned it on a forum - but then we tend to get their slow-ass attempts come through as emails before they hit the trap lol).

 

 

I did consider a hidden field that only bots would fill in, but that could be a bit intrusive if someone was using a screen reader.

Edited by FizixRichard

Most if not all screenreaders will respect display: none. Has to be a regular <input type="text"> rather than an <input type="hidden">, so the spambots can't tell the difference.

It's funny really; captha's.

 

I used to have one on my forms. I always found it a headache as you have to keep updating it, most all users find them annoying, they aren't great for accessibility and the cleverer spam bots still get through.

 

We always used to use captcha's and would still get spam; not constantly but at least a few times per week. So you add a security question as well; and you cut some of them out; but some still manage to figure it out.

 

 

Fast forward to today and we have this:

http://www.fizixstudios.com/contact

 

No captcha and no spam.

 

Captcha's are IMHO a poor and lazy solution to a problem.

 

 

If anyone is interested; our contact form has a non intrusive honeytrap; based on form submit speed.

 

A typical bot will load the html, wack text into the fields quickly and submit quickly (talking seconds). A typical user however will take longer to fill in a form, a lot longer.

 

For an end user to get caught up by the honey trap they will have to type like a hyperactive 3 year old. A bot however will always get caught by the honeytrap.

 

Interesting , but how do you keep track of the speed between the form submissions ?

What if the bot deletes all the cookies before each submission ?

 

Sorry if this is a stupid question ,

 

Cheers :)

Most if not all screenreaders will respect display: none. Has to be a regular <input type="text"> rather than an <input type="hidden">, so the spambots can't tell the difference.

 

I understand that by standards they should ignore hidden fields, I wasn't 100% sure whether they followed it strictly though. Also I was unsure whether a spam bot would ignore them.

 

 

Interesting , but how do you keep track of the speed between the form submissions ?

What if the bot deletes all the cookies before each submission ?

 

Sorry if this is a stupid question ,

 

Cheers :)

 

It passes a timestamp with the form. I wouldn't rely on cookies as end users might not allow cookies.

 

 

ETA for clarity:

 

When the form loads, the server side script creates a timestamp which is passed with the form to the post script. The post script reads the timestamp, creates another timestamp with the "submit time" in it.

 

So you have a rough "form load" and "form submit" time; which you can compare to get a rough "form was open" time.

 

If the "form was open" time is less than a reasonable data entry time then you throw a honeypot error.

 

It's rather crude really, but it works and because you are scoping for stupidly fast form submissions a real person is highly unlikely to be caught up in it without actually trying to abuse the form anyway.

Edited by FizixRichard

I understand that by standards they should ignore hidden fields, I wasn't 100% sure whether they followed it strictly though. Also I was unsure whether a spam bot would ignore them.

 

 

 

 

It passes a timestamp with the form. I wouldn't rely on cookies as end users might not allow cookies.

 

 

ETA for clarity:

 

When the form loads, the server side script creates a timestamp which is passed with the form to the post script. The post script reads the timestamp, creates another timestamp with the "submit time" in it.

 

So you have a rough "form load" and "form submit" time; which you can compare to get a rough "form was open" time.

 

If the "form was open" time is less than a reasonable data entry time then you throw a honeypot error.

 

It's rather crude really, but it works and because you are scoping for stupidly fast form submissions a real person is highly unlikely to be caught up in it without actually trying to abuse the form anyway.

 

Ha , I get it now , thanks for sharing this , I think it's a very clever solution.

 

Cheers :)

It works and was in part, inspired by a rather lengthy discussion I was participating in on Sitepoint about finding CAPTCHA alternatives. :)

Edited by FizixRichard

The other option I quite like is heuristic services like Akismet. The more spam they're fed, the better they get at distinguishing spam from ham.

HAHA no chance! My attempts at code have been beyond laughable. Thank god I have other talents. It's called Key Captcha. I would have linked to it in my other post, but I'd forgotten the name! https://www.keycaptcha.com/

 

Another vote for keycaptcha here. It's a captcha, but it's also fun! I put it on a PHPBB forum and it pretty much eliminated fake accounts.

 

The standard 'recaptcha' has definitely got harder, and it's so ugly now too, looks out of place on any website.

Edited by WebTam

If I'm honest, I don't think keycaptcha is that great of an idea. Playing with it just now, it has a certain novelty value. However if I was doing something; say wanting to sign up to a site so I can do something or send an email, I would probably find it annoying as it has slowed me down; when I have a kajillion other things to do.

 

It also presents a usability/accessibility issue. If I were blind, had poor eyesight or some other visual impairment I'd screwed. I could not access your service or conact you. The same could be said for certain learning difficulties.

 

Also another thing that annoys me with captha's is when you sit there writing a long message on a contact form and you make a mistake on the captcha or it fires off "wrong" even when you get it right; had that before; and you loose the message you spent 20 minutes writing.

 

Captcha's are a blight, a pain in the arse. I think we as developers should be being a bit more inventive and trying to find more transparent solutions that don't get in the way of legitimate users.

 

 

eta: I can't bloodywell type today, mad case of butter fingers, I might as well be banging the keyboard with my head.

Edited by FizixRichard

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.