From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1M9imq-0006VX-Ib for garchives@archives.gentoo.org; Thu, 28 May 2009 16:49:01 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 90016E0460; Thu, 28 May 2009 16:48:59 +0000 (UTC) Received: from qw-out-1920.google.com (qw-out-1920.google.com [74.125.92.147]) by pigeon.gentoo.org (Postfix) with ESMTP id 6EF4EE0460 for ; Thu, 28 May 2009 16:48:59 +0000 (UTC) Received: by qw-out-1920.google.com with SMTP id 5so1552029qwf.10 for ; Thu, 28 May 2009 09:48:59 -0700 (PDT) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Project discussion list X-BeenThere: gentoo-project@lists.gentoo.org MIME-Version: 1.0 Sender: antarus@scriptkitty.com Received: by 10.231.35.13 with SMTP id n13mr590290ibd.24.1243529338860; Thu, 28 May 2009 09:48:58 -0700 (PDT) In-Reply-To: <4A1DBCB3.4010808@gentoo.org> References: <4A1D6C7C.7090605@gentoo.org> <4A1D8A44.3090101@gmail.com> <4A1DBCB3.4010808@gentoo.org> Date: Thu, 28 May 2009 09:48:58 -0700 X-Google-Sender-Auth: 7f05b13006e1a708 Message-ID: Subject: Re: [gentoo-project] Spam reduction proposal - switching lists to a web-form for subscription From: Alec Warner To: "Marijn Schouten (hkBst)" Cc: "Robin H. Johnson" , gentoo-project@lists.gentoo.org Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Archives-Salt: d6423c8a-07d1-48b8-a634-675bfc795a5c X-Archives-Hash: 64b910330e3f3f98582cd4480e1019b5 On Wed, May 27, 2009 at 3:20 PM, Marijn Schouten (hkBst) wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Robin H. Johnson wrote: >> On Wed, May 27, 2009 at 01:45:24PM -0500, Dale wrote: >>> Is there something besides a captcha that can be used? I hate those >>> things because they make no sense to me. I usually just give up when I >>> encounter one of these and try three or four times with no success. The >>> ones that look like broken glass or something are the ones I don't even >>> try anymore. I can't get past one of those. >> recaptcha [1] is very common at this point, offloads the problem to an >> external service, supports visually-challenged users, and includes it's >> own detection of brute forcing from IP addresses and subnets. >> >> If that's not acceptable to you, I'll just deploy calculus-captcha. >> calculus-captcha is best viewed on this page here: >> http://random.irb.hr/signup.php >> (reload a few times to see the fun they had in qualifying questions). > > The reCAPTCHA page mentions[1] that simple text recognition (with minimal > distortion) is easy to do with computer programs. Given that the > calculus-captcha are non-distorted LaTeX'ed formulas we should therefore > probably assume that computers can read those formulas. They only seem to have > very few kinds of questions (zeros of small polynomials, differentiation of some > trigonometric functions (only cos and sin), arithmetic), all of which are > extremely simple especially for a program[1]. If this CAPTCHA becomes widespread > someone WILL break it. As it turns out; our mailing list subscription form is not meant to be an impenetrable fortress and I doubt we care if the CAPTCHA service we are using is breakable or not (worst case the spammer uses humans looking for porn to fill out the CAPTCHA) The point here is to just make it a little bit harder to spam everyone; not to make it impossible, defense in depth and all that. > > On the other hand I like that reCAPTCHA puts your answers to use for automatic > digitizations of books. Unfortunately their "Stop spam, read books" message > doesn't make this very clear unless you already know. > > Marijn > > [1]:http://recaptcha.net/captcha.html > > - -- > If you cannot read my mind, then listen to what I say. > > Marijn Schouten (hkBst), Gentoo Lisp project, Gentoo ML > , #gentoo-{lisp,ml} on FreeNode > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v2.0.11 (GNU/Linux) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iEYEARECAAYFAkodvLMACgkQp/VmCx0OL2zK/QCgmt+/RincRzXtmuGNTxsE4Yd+ > wo8An2zcFsPPaxpzbB75lYlnFCAg1o8q > =glct > -----END PGP SIGNATURE----- > >