From: "ara.t.howard" Date: 2007-07-05T11:55:53+09:00 Subject: Re: [ANN] flatulent-0.0.1 ascii captcha for the masses On Jul 4, 2007, at 6:18 PM, John Joyce wrote: > you should do like blogger (blogspot) and others, allow writing and > after clicking on 'submit' or 'post' or whatever to submit the form > info, you then redirect to a page with the captcha and a submit. > after the captcha page is sent, begin the count. 60 seconds seems a > bit short for a whole post, but with a separate redirect to the > captcha page, it's totally reasonable. If it takes longer, redirect > again to a new captcha. After 3 or 4 failed attempts, save it in a > log, kill that cookie and require a fresh start or a harder captcha. > > Don't put the count in JavaScript EVER. Client side code is totally > spoof-able. > All you need is the session data in the cookie to identify the user > and check to see if the response came quick enough. > 60 seconds might not be long enough, but a browser will time out > during that long of a wait for a request's response. Still a little > longer might be appropriate from an accessibility standpoint. all good ideas - for now i'm just trying to get something working. fyi all the stuff is client side, however the captcha and timebomb have been blowfish encoded into hidden fields with a key known only to the server. one could make guesses, but that's about all. cheers. -a -- we can deny everything, except that we have the possibility of being better. simply reflect on that. h.h. the 14th dalai lama