Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This sounds like it's coming from someone who hasn't had any real experience with large scale spam problems.

We operate a forum with 250k members and ~800k posts per month, a new registration every minute and we get so many spam bots even with captcha (mechanical turk etc) and without captcha it's unworkable. Captcha is a necessary evil, but it does help.

This seems to be coming from someone dealing with a site where spam wouldn't be that much of a problem, who would sign up to animoto to spam? Very silly post.



They are proposing alternative methods that don't put the burden on the user in the form of explicit action. By using honeypot fields that would only be filled out by a robot, and timestamp analysis which effectively detects automatic form submission, they can weed out the bots without asking their users to do anything.

What's so silly about that?


Honeypot fields and their ilk are easy to bypass with a focused attack. For smaller sites, that's fine - who's going to make the effort to target you? Keep out the opportunistic bots rattling your contact form, and life's good.

For juicier targets, something more sophisticated is necessary. Captchas are one answer.


Are there alternate yet equally as effective measures than what has been discussed? If so I'd like to hear more.


Ant-spam services like Akismet.


Nothing, they're a good solution for this company. My point was the conclusions were based on this company, not everyone who suffers spam, the article has since been updated with:

> For some reason this article has hit the front page of Hacker News and is getting quite a lot of traffic. I should mention that yes, I acknowledge CAPTCHAs are of course sometimes unavoidable. That doesn’t mean, however, that we should ever feel good about using them, nor should we fool ourselves that users don’t mind them.

Which was my point. When spam is a serious issue then captchas are unavoidable 99% of the time.


If you're site is running on a popular forum software, robot-only inputs and timestamp analysis would eliminate most of your problems.

Spammers are probably not targeting your website in particular, rather the software your forum is run on. If you add atypical anti-spam measures you'll separate yourself from others using the same platform, defeating the typical phpbb or vbulletin bot which probably accounts for most of your spam.


The thing is though, for anything small scale a simple "Type Human" in a box is 100% effective for the random spam bots. For anything like what you are experiencing you are being targeted so even with the best CAPTCHA around spam is still going to be a problem.

I honestly believe that CAPTCHA's are one of the most evil things on the internet and that there are many valid and better ways to avoid spam.

BTW im not just some random guy with an axe to grind over this, I wrote http://www.wausita.com/captcha/ as an example of how trivial 90% of the CAPTCHA's on the web are trivial to decode.


A lot of targeted attacks use humans to decipher captchas. Hell, a lot of programs used by internet marketing will display a captcha to decipher every 2 seconds in order to post in a forum/website. Invisible fields are in my opinion a much better solution, but who cares what I think, did you try other solutions before calling them silly?


You have a valid point. However this is pointing out ignorance of developers (I being one of them) that most of the time captcha is unnecessary and annoying to UX.

So yes, who would spam animoto? But you know what, now their spam filter is good enough, their user registration has been increased. Better more "foolproof" techniques will always be needed, and directed attacks are hard to prevent, but getting to a good enough point is great as well.

And the problem you face may be a smaller percentage of sites than animoto, who do need captcha especially if you are the target of a directed attack.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: