Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

stuff like this is exactly why captchas are outdated...they don't stop the real spammers, and just annoy your users.

With most captchas I have to try 3-4 times before I can actually spell out what the image is showing. The only exception is ReCaptcha, those tend to be easy to decipher.

I wonder if 3-4 years down the line, everyone will continue using captchas...even when they stop working as a method to fight spam



Only if you define "work" as blocking 100% of spam.

The evidence that they work is right in front of you. The incremental cost of posting 1000 spam comments went from basically zero to $1.39.

I use ReCaptcha on my sites and, as far as I can tell, the only spam getting through is humans (typically with .cn hostnames) manually entering the CAPTCHA. Meanwhile it's blocking 100s of dumb, automated attempts.


It depends on what you are doing it for, if you've found site(s) that don't use rel=nofollow $1.39 for 1000 users is a pretty good deal, especially if the CAPTCHA is stopping the vast majority of spammers from making the link juice worthless.

I'd pay $1.39 for 1000 links from sites that haven't been spammed to death with out thinking about it.


You should be using something unique to your site in addition to the widely-used countermeasures. Until your site is worth targeting explicitly, that little bit of custom code can make it uneconomical to spam your site.

You can also join with others who work to stop this kind of spam. For example, Project Honeypot ( http://www.projecthoneypot.org/ ) offers honeypots to trap all kinds of spammers, including comment spammers.

If you're expecting some kind of 100% solution to spam, I doubt that will never happen. The best anyone can do is combine a bunch of decent solutions, preferably in unique combinations, and hope to reduce spam to a manageable level. If one countermeasure blocks 50% of spam and another 70% and another 90% and their failures are independent, you're down to 0.5 x 0.3 x 0.1 = 1.5% of spam getting through. Chain enough partial solutions together and you get something better than any one alone.


Only if those partials don't overlap. If your 70% solution also blocks the same 50% then it's not .5*.3 it's just .3


The assumption was that the solutions were chained and that they would never see the things that failed before that. But I guess I only stipulated that the failures were independent, when the math I wrote meant that the successes should be independent, as well.


They do stop real spammers, as a real spammer works on extremely high volume and the cost of doing the captcha is way too expensive to do at the numbers they are at.

I do agree that they are outdated.


Agreed, "spammers" are not the people who use CAPTCHA breaking.

The people that use it have very specific purposes in mind. Spamming through CAPTCHA'd systems makes little sense as it costs too much. That said, there are many businesses, large and small, that use breakers to engage in commerce.


Actually, I managed a reasonably large scale free email operation and spammers DO spend money solving captchas.

We had this issue with spammers where after sending 50 emails a day we would ask users to solve a captcha after each email sent. That didn't work.

Upon further investigation and adding some code to track keypresses, we discovered the reason: it had been humans all along, sending spam semi-manually from a cybercafe/sweatshop in Nigeria using an add-on like Roboform as an aid. And yes, these were the usual H3rb4l V14gr4 spammers as well as some Nigerian Princes.

While there is poverty, Captchas are necessarily broken.


Interesting, good to know :)


Spammers are the ones who use it extensively and that's why such a service was born. The percentage of people using it for other purposes would be infinitesimally small.

You can't directly attach value to the money they spend on this. They create accounts on many services like Gmail, Yahoo, Hotmail, etc for email spamming and they need to use these services for the tools that they purchased to work. These tools basically automate everything except the captcha solving part.


Captchas are not outdated. They are good against brute-forcing password for example: 10 unsuccessful login attempts -> please use captcha. Since brute-forcing takes millions or tens of millions of attempts, it becomes uneconomical.


Another method is to pause for an exponential delay after each failed attempt. This makes it prohibitively slow to brute force.


The benefit of the captcha method is that your account can't be DOSed -- the legitimate user can still get in by entering one captcha, which is much better than, say, having to wait for an hour.


Who do you consider "the real spammers"? Stopping a majority of spammers is what makes my life easier.


Like screen savers on LCDs?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: