From: John Joyce Date: 2007-07-05T09:18:01+09:00 Subject: Re: [ANN] flatulent-0.0.1 ascii captcha for the masses On Jul 4, 2007, at 6:52 PM, Sammy Larbi wrote: > ara.t.howard wrote: >> >> - image has an encoded timebomb in it: attacker has only 60s for >> post. this just rules out brute force attacks. > > From when does it start counting? If I've read a blog post and > then try to comment, it's likely I've already used more than 60 > seconds. In fact, probably most of the time I take more than 60 > seconds to comment by itself. > > I think a good protection scheme will take into account several > factors, assign them points for failure (or passing), and once a > threshold has been reached, fail the entire thing (or pass it, if > you chose that route). > > Sam > > you should do like blogger (blogspot) and others, allow writing and after clicking on 'submit' or 'post' or whatever to submit the form info, you then redirect to a page with the captcha and a submit. after the captcha page is sent, begin the count. 60 seconds seems a bit short for a whole post, but with a separate redirect to the captcha page, it's totally reasonable. If it takes longer, redirect again to a new captcha. After 3 or 4 failed attempts, save it in a log, kill that cookie and require a fresh start or a harder captcha. Don't put the count in JavaScript EVER. Client side code is totally spoof-able. All you need is the session data in the cookie to identify the user and check to see if the response came quick enough. 60 seconds might not be long enough, but a browser will time out during that long of a wait for a request's response. Still a little longer might be appropriate from an accessibility standpoint.