From: Chad Perrin Date: 2007-07-05T16:34:40+09:00 Subject: Re: [ANN] flatulent-0.0.1 ascii captcha for the masses On Thu, Jul 05, 2007 at 09:18:01AM +0900, John Joyce wrote: > > > you should do like blogger (blogspot) and others, allow writing and > after clicking on 'submit' or 'post' or whatever to submit the form > info, you then redirect to a page with the captcha and a submit. > after the captcha page is sent, begin the count. 60 seconds seems a > bit short for a whole post, but with a separate redirect to the > captcha page, it's totally reasonable. If it takes longer, redirect > again to a new captcha. After 3 or 4 failed attempts, save it in a > log, kill that cookie and require a fresh start or a harder captcha. Avoid reliance on cookies. For one thing, cookies can be forged. For another, you'll lose a lot of people with requirements for cookies. Modern browsers tend to provide a means for selectively refusing cookies, and a lot of people use those features. > > Don't put the count in JavaScript EVER. Client side code is totally > spoof-able. > All you need is the session data in the cookie to identify the user > and check to see if the response came quick enough. Session data need not be stored in a cookie. There are other ways to do it as well -- allow for those who won't (or can't) accept cookies. -- CCD CopyWrite Chad Perrin [ http://ccd.apotheon.org ] McCloctnick the Lucid: "The first rule of magic is simple. Don't waste your time waving your hands and hopping when a rock or a club will do."