logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Re: RFC: CGI::Application::Plugin::CAPTCHA: msg#00136

lang.perl.modules.cgi-appplication

Subject: Re: RFC: CGI::Application::Plugin::CAPTCHA

* Michael Peters <mpeters@xxxxxxxxxxxxx> [2005-08-26 17:35:04-0400]
> Dan Horne wrote:
> > It would be nice if whatever solution is selected can run under Windows too.
> > Many memory-based caching systems are specific to *nix systems and don't
> > work with MS (particularly the IPC ones). What about supporting the
> > Cache::Cache API, and then let the developers choose which Cache::* module
> > suits?.
>
> Ok, before we go down this road, can anyone give me a good reason that
> we need to permanently store these images or even cache them? The
> CAPTCHA phrase should be random enough that we would never use the same
> image twice in a reasonable amount of time right?

After following this thread, I feel I have to jump in here to give
my 0.02EUR. First of all, I think CAPTCHAs are horrible in every way
possible:
* Images are just bad:
Either the images are completely unreadable (see my blog
entry[1] on that), or they are "too easy" to crack[2].
* False sense of security:
"Spammers can pay a programmer to aggregate these images and feed
them one by one to a human operator, who could easily verify
hundreds of them each hour." [3]
* Punishment for the wrong group of people:
Visually impaired people (or heck, Links/Lynx users for the
matter) really wouldn't like CAPTCHAs for it clearly just bans
them. Audio files need to be created too (and I think in the US
there's even a law about this? Correct me if I'm wrong).
After recently coming back from the Asian continent, I can also
tell you browsing the web with images turned off (thanks FireFox!)
is more a necessity than a pleasure. Internet speeds (if even) are
extremely slow, CAPTCHA images would be punishing those people too
(or anyone with a slow connection).
* Annoying:
Certainly not the last reason: CAPTCHAs are beyond annoying.
Just because _you_ seem to have some problems keeping spammers out,
you force me (the user/client) to do all sorts of tricks for you.

So yeah, I don't really like such systems ;-) I'd rather see
different solutions to stopping spam or whatever reason was behind
your CAPTCHA idea.

But, besides me disliking it, I strongly belief the images have no
need on the server. A single encrypted string in the user's session
(database/file) would be sufficient IMHO. The use only needs to see
the image once, right?

1. http://menno.b10m.net/nb/archives/2005/04/22/T16_56_47/index.html
2. http://sam.zoy.org/pwntcha/
3. http://www.w3.org/TR/turingtest/#security
--
B10m
'Google is Evil'
-rw-rw-rw- 1 satan demons 0 Jun 06 06:06 google

---------------------------------------------------------------------
Web Archive: http://www.mail-archive.com/cgiapp@xxxxxxxxxxxxxxxxx/
http://marc.theaimsgroup.com/?l=cgiapp&r=1&w=2
To unsubscribe, e-mail: cgiapp-unsubscribe@xxxxxxxxxxxxxxxxx
For additional commands, e-mail: cgiapp-help@xxxxxxxxxxxxxxxxx




<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
krysalis.sandbo...    web.zope.zwiki/...    gnome.apps.gnum...    xfree86.newbie/...    editors.vim/200...    mozilla.enigmai...    boot-loaders.gr...    network.vnc.ult...    redhat.release....    java.geronimo.u...    os.netbsd.devel...    horde.wicked/20...    linux.lsb.discu...    ietf.ips/2005-0...    alsa.devel/2002...    user-groups.lin...    package-managem...    debian.devel.da...    security.cyrus....    video.gstreamer...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe

Navigation