Avatar

Bots or humans? (General)

by Alfie ⌂ @, Vienna, Austria, Sunday, November 04, 2018, 00:35 (42 days ago) @ WorldofBB
edited by Alfie, Sunday, November 04, 2018, 18:22

Hi!

Not sure if it's just me - but in the past few weeks I've been getting several spam account registrations per day.

Not only you. 10–20 / day for years… Are you talking about registrations (without activation) or “true” spammers? The former ones should be deleted within 24 hours anyway.

The captchas available are fairly useless and none of the options make any difference one way or the other.

Agree. I had an “improved” version of the math-captcha (where the numbers to add are given as words) for ages. Useless. I’m timing how long it takes to fill in the registration form (from GET to POST). I removed it.
With captcha: x̃ 3.54 ms (2.04–8.70)
Without: x̃ 3.35 ms (0.55–7.51)
Lesson learned: It takes bots just a fraction of a millisecond to break the captcha.

Would be great if reCAPTCHA was an option, as I find it to be one of the most effective ways to limit spam accounts these days.

What about accessibility and Google’s questionable data protection?

Any suggestions?

According to my server-logs it takes humans (yep, and the true spammers as well) about one minute register. I’m considering to throw a nice

exit(header("HTTP/1.0 403 Forbidden"));

if the registration takes less than one second – and switch off all other filters I have now (query a recent local copy of StopForumSpam’s banned IPs, query remotely SFS and BotScout).

--
Best regards,
Alfie (Helmut Schütz)
BEBA-Forum (v1.8β)


Complete thread:

 RSS Feed of thread

powered by my little forum