CAPTCHAs Don't Work

I begged, yelled, screamed, pleaded for CAPTCHAs so I could stop the comment spam.

TypePad delivered for me and everyone else who was asking for them and I am very thankful.

But the damned comment spam just keeps flowing past the CAPTCHAs and onto my pages.

Uggh.

The Internet Axis of Evil wins another round.

Comments

Really very good..Believe that you certainly go of.

I love the first comment. Posted within a few hours? Oy ...

CAPTCHA's alone are not sufficient to prevent automated comment spam. They need to be paired with other measures that detect retry attacks. True comment spam prevention is going to require a layered approach. We had lots of fun figuring this out for Rock Star: INXS voting, which was unauthenticated, and were ultimately successful because we didn't depend on a HIP challenge alone.

egalitarian euphoria aside, its always been and perhaps always will be a fine line between "user generated content" and "abuser generated content"

Ingenious! CAPTCHA and other technologies like it are basically there to keep "honest people honest" - those that want to step around the rope barrier will always find a way.

There's always been a simple way to bypass CAPTCHA, and has often been used by spammers: set up a free porn site, which requires only to resolve a CAPTCHA to be allowed to view the porn. As there is an immense number of free porn seekers, it's easy to serve a captcha to each one -- when it's resolved, your program can easily add spam to the captcha's originating page.

Adding random session based form elements is another method to detect automated posting. It isn't a full solution, but so far we've been successful using this approach. I suspect if too many people start doing this, the spammers will handle it (it is easy to code for), but it works for now.

I thought about not posting this for that very reason, but it isn't like I'm the first person to have this idea.

Perhaps Kozoru could have searched your comments and then notified you which ones were spam, but alas, it is vaporware and JSF is more interested in polyphasic sleep experiments and making commercials. :( :( :(

Fred, I'm posting comments without any CAPTCHA requirements on this post. This is a possible reason that you are still being flooded by spam.

Just posting to try out the captcha ;). I'd like to see a mashup of captcha code and the flickr letter tags - something like this but at least composed into a single bitmap with the character sizes scaled somewhat randomly and some other efforts to make it harder to find the character boundaries. At any rate it would be more fun than regular captchas!

Face it Fred - your a blogshere superstar, no gettin' around that. Solution: Put out a bad LP.

I've found keyword filtering to be one of the most effective comment spam prevention techniques. I auto-trash comments including terms that have no chance of being used in a legitimate post, and moderate terms on the edge. Not a perfect solution either, but it certainly helps.

Well at fastblogit installing captcha eliminated 99% of the spam. I suspect that you left some alternate posting mechinism behind. You got to find and close all the holes in the dyke

Fred--

Have you tried out Akismet yet?

Batelle has a good post on Akismet and MT at http://battellemedia.com/archives/002490.php

And, while I'm at it, I might as well put a (admittedly biased and self interested) plug that you try using WordPress itself!

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment