From: "ara.t.howard" Date: 2007-07-05T23:49:06+09:00 Subject: Re: [ANN] flatulent-0.0.1 ascii captcha for the masses On Jul 5, 2007, at 3:12 AM, Alex Young wrote: > Only naive ones... The brute force attack that still works is a > birthday attack. Using that they can try attacks as fast as they > can generate *new* captchas - you expect a collision every 1.2*sqrt > (n) attempts, where n is the size of your keyspace. That's > probably OK for "captcha per comment" sites, but it's dangerous for > "captcha per account" sites. yes. although flatulent does works without sessions, it's about three lines to save the data into the session and validate against that as well so a cautious person would be wise to do so. i'll be adding automatic session validation for rails - but the api should make it super easy anywhere. cheers. -a -- we can deny everything, except that we have the possibility of being better. simply reflect on that. h.h. the 14th dalai lama