Hacker News new | past | comments | ask | show | jobs | submit login

I think this would fail under any directed attack. It’s too hard to generate a database that’s large enough.



This is the answer. It seems that most website owners are somehow super scared of a targeted attack, since it is indeed trivial to bypass (and they realize that), even if nobody will take the time.

I've heard stories from people that own small sites and still have someone targeting the site with custom scripts, but never anyone I know (not even a friend of a friend, only ever random people on the internet). But there is also the (much larger, from what I can tell) group of people that never had these issues. But people don't like risks, and installing a tracking captcha from google is made very easy. "Everyone does it, that ought to work!" (Meanwhile I hear of a 90% success rate from a recaptcha browser plugin, but who cares about that right?)


I've had received attacks from custom scripts to post spam in a blog that nobody read. I changed my custom robots tests a couple of times, and each time it took a few days for the bots to adapt. At the end I removed the comments section, so there was nothing to attack.


This is exactly the kind of story I'm taking about. I'm sorry about your experience, I don't doubt that you're real, but this is the kind of confirmation/hindsight bias that makes people misjudge risks. I expect you are an outlier, but I have no idea.

Might be interesting to poll random people that have websites with <100 unique visitors a month for this sort of thing to get us any sort of idea of how necessary an invasive CAPTCHA like Google's is.


XRumer (forum spamming) software had a feature over a decade ago that would reload a /register page on different proxies to generate a list of these sorts of questions. You'd run it for a moment, feed an answer for each question into XRumer, and then continue on your merry spammy way.

These ReCaptcha topics on HN really illuminate how few people have dealt with any real spam, much less targeted human or botnet attacks.


Can you teach it to play hangman? I'm thinking about digging out and dusting off my old perl cgi games. It might even keep humans out that don't have my sense of humor.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: