News:

Bored?  Looking to kill some time?  Want to chat with other SMF users?  Join us in IRC chat or Discord

Main Menu

Your anti-spam measurements are far too extreme here

Started by Ecru, September 16, 2012, 10:55:03 PM

Previous topic - Next topic

Ecru

Just letting you know, every post I've made until now has taken me at least 10 tries to get the captcha right. It's extremely difficult to read and I had to request the same image over and over again until it finally clicked.

I can understand the difficulty setting as you really don't want bots, but I was ready to just stop posting after the fifth try.

Seems that 10 posts made it so I can post without the captcha, so that's nice. Perhaps make it 3 or 5 posts instead of 10?

Deaks

Thank you for posting, 10 posts was agreed as it shows user is active we have had people coming in posting 5 posts of spam but luckily the community is fast at reporting and staff are fast at responding so at this time I cannot see it being lowered but we are always listening to community.
~~~~
Former SMF Project Manager
Former SMF Customizer

"For as lang as hunner o us is in life, in nae wey
will we thole the Soothron tae owergang us. In truth it isna for glory, or wealth, or
honours that we fecht, but for freedom alane, that nae honest cheil gies up but wi life
itsel."

Irisado

It's annoying to make it through your first ten posts here, I agree, but I don't think that it can be changed.  A few spammers still make it through the system here as it is without making life easier for them, so I have to say that I back the Staff at SMF leaving the limit unchanged.

Blame the spammers, for it is their actions that have forced this to be implemented in the first place.
Soñando con una playa donde brilla el sol, un arco iris ilumina el cielo, y el mar espejea iridescentemente

Colin

I can't agree more. I even remember how difficult it was to guess the capatcha. You know it is bad when humans can't get it right after several attempts. Hopefully in the future there will be a more effective way to deal with bots. I apologize for the difficulty you encountered.

"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin

MrPhil

As CAPTCHAs have become less and less effective against bots (and more effective against humans!), other methods will have to come to be used. These could include visual puzzles such as clock faces, Q&A, poster behavior (e.g., a whole bunch of posts in a very short time), and post content (looking for spam characteristics such as keywords, capitalization, substitution of numbers and punctuation for letters, etc.).

kingW3

Quick idea
A post moderation for first 10 posts until the first 10 posts are approved the posts after 10 posts doesn't show(for example if you post 150 times and your first 10 posts aren't approved none will show),and if approving them is a much of job for the team members you could give it to community helpers with more than 100 posts(i took 10 and 100 posts as an example).Mostly you will find at least 10 team members or smf heroes/super heroes this shouldn't be a much of a problem.
Another one
Disable links in signature and posts for the first few posts completely so if a spam bot links to any link like www. or wwwdot or www(dot) etc it will give them a error You can't post link(s) until xx posts
Still SMF support should be excluded in both cases

Kindred

post moderation - no...   WAY too much work, even for community helpers.   Just won't work and will only get new users upset at how long it takes.

Signatures and links *ARE* already disabled for new users.


We can't use "questions" here either...   because we have far too many international/non-english speakers.


basically, there is no good answer...
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

青山 素子

Quote from: Kindred on September 21, 2012, 01:51:45 PM
We can't use "questions" here either...   because we have far too many international/non-english speakers.

That's the big problem with this forum. It caters to an international audience. This makes it difficult to simply implement something "friendlier" like question/answer sets as not every member knows a single common language. Fancy picture-based tests, like choosing all the dogs in a mixed set of photos, requires localized instructions for every language you want to support. Traditional CAPTCHA at least has the benefit of being mostly language-neutral. Even if you don't use the alphabet in your native language (Arabic, Chinese, Japanese, Tawainese, etc.) you will at least have some way of typing the symbols.
Motoko-chan
Director, Simple Machines

Note: Unless otherwise stated, my posts are not representative of any official position or opinion of Simple Machines.


Ricky.


青山 素子

Quote from: Ricky. on September 25, 2012, 12:58:42 AM
But still Captcha is in English I guess..  ?

It's scrambled letters from the Latin/Roman alphabet. Every language that uses those letters can understand the purpose, more or less. Even languages that do not use those letter forms will have some way to input them on a computer because they are used in programming languages and a lot of other software. It's as close as you can get to being language-neutral for a security measure like this.
Motoko-chan
Director, Simple Machines

Note: Unless otherwise stated, my posts are not representative of any official position or opinion of Simple Machines.


Ricky.


emanuele

* emanuele takes a note about multi-language antispam Q&A...it shouldn't even be too difficult I think...they just need a new table, {db_prefix}log_comments is not the best place for that...


Take a peek at what I'm doing! ;D




Hai bisogno di supporto in Italiano?

Aiutateci ad aiutarvi: spiegate bene il vostro problema: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.

euantorano

Definitely agreed with the OP. I just signed up and I'll be lucky to make it to five posts thanks to the fact I have to fill in this captcha every single time I do try to post. I had to listen to the audio captcha to be able to make any kind of sense of the last one I got...

floridaflatlander

Quote from: euantorano on October 05, 2012, 03:22:24 PM
Definitely agreed with the OP. I just signed up and I'll be lucky to make it to five posts thanks to the fact I have to fill in this captcha every single time I do try to post...

It's worth it.

Quote from: euantorano on October 05, 2012, 03:22:24 PM
... I'll be lucky to make it to five posts thanks to the fact I have to fill in this captcha every single time I do try to post. I had to listen to the audio captcha to be able to make any kind of sense of the last one I got...

Press ctrl+ to help you read the letters better

ctrl0 to return to regular text.

Colin

I have better than 20/15 vision and I still had serious trouble transcribing those characters. It is by no means clear.
"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin

floridaflatlander

Quote from: Colin on October 05, 2012, 04:45:46 PM
I have better than 20/15 vision and I still had serious trouble transcribing those characters. It is by no means clear.

Odd, mine are pretty bad and I can read them without enlarging them.

青山 素子

Quote from: Colin on October 05, 2012, 04:45:46 PM
I have better than 20/15 vision and I still had serious trouble transcribing those characters. It is by no means clear.

Quality of vision isn't really a huge factor when you're looking at distorted letterforms as opposed to small/large stuff.
Motoko-chan
Director, Simple Machines

Note: Unless otherwise stated, my posts are not representative of any official position or opinion of Simple Machines.


MovedGoalPosts

Cathpas are a pain in the butt to humans, yet seem to be easily read by bots.  So all they deter is the legitimate user, and not those they are supposed to deter.  The one on here, I recall is very hit and miss whether a person can correctly decipher it.

I can understand the difficulty of using verification questions on a multilingual site.  No doubt there are also other various antispam measures being employed by SMF behind the scenes, but when the antispam measure is deterring the legitimate user, some different defence has to be found.

John Wodden

I agree with you  :D
Quote from: Ecru on September 16, 2012, 10:55:03 PM
Just letting you know, every post I've made until now has taken me at least 10 tries to get the captcha right. It's extremely difficult to read and I had to request the same image over and over again until it finally clicked.

I can understand the difficulty setting as you really don't want bots, but I was ready to just stop posting after the fifth try.

Seems that 10 posts made it so I can post without the captcha, so that's nice. Perhaps make it 3 or 5 posts instead of 10?
I agree with you

LiroyvH

((U + C + I)x(10 − S)) / 20xAx1 / (1 − sin(F / 10))
President/CEO of Simple Machines - Server Manager
Please do not PM for support - anything else is usually OK.

青山 素子

Motoko-chan
Director, Simple Machines

Note: Unless otherwise stated, my posts are not representative of any official position or opinion of Simple Machines.



Kindred

Well, it uses the latin alphabet and arabic numerals....

but other than that, no Captcha is not in english specifically
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

floridaflatlander

As for this regular member, I much rather it be a small pain to someone new or with a few post and keep out as much crap as possible.
I would hope that they could look at the greater good and see it benefits them and all of us to keep that spam sh*t off of here.
How many members are here and how quickly are questions answered?
This forum is a great resource and I can only imagine how many spam attempts are made here and how tempting a target smf is.

MrPhil

It is a bit culturally biased. It uses the Latin alphabet and Arabic numerals, so if you're not used to handling them, being able to recognize distorted forms might pose a problem for some people. Of course, Greek or Cyrillic or Hebrew or Arabic or Chinese... would be a problem for me to recognize (or type in), although it certainly would throw the bots for a loop! Presumably if you're on a computer, you have at least passing familiarity with the Latin alphabet and your keyboard should have some way to type in its letters, so that shouldn't be a major hurdle. Needless to say, the instructions for what to do need to be in an appropriate language.

If bots are too good now at recognizing Latin letters, there are alternatives. You could show clock faces (different styles, different orientations) and ask what time it is (accept answers within 5 minutes or so). You could show abstract shapes and ask for the user to select from a list (using mouse or tab/enter). Note that either of these could pose a problem for visually handicapped people, unless great care was taken in providing an audio equivalent.

lotman

Quote from: kingW3 on September 21, 2012, 01:33:59 PM
Quick idea
A post moderation for first 10 posts until the first 10 posts are approved the posts after 10 posts doesn't show(for example if you post 150 times and your first 10 posts aren't approved none will show),and if approving them is a much of job for the team members you could give it to community helpers with more than 100 posts(i took 10 and 100 posts as an example).Mostly you will find at least 10 team members or smf heroes/super heroes this shouldn't be a much of a problem.
Another one
Disable links in signature and posts for the first few hxxp:collieart.com [nonactive] posts completely so if a spam bot links to any link like www. or wwwdot or www(dot) etc it will give them a error You can't post link(s) until xx posts
Still SMF support should be excluded in both cases

I agree with you. ..


live627


Colin

"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin



KitLightning

Hmm the captcha haven't bothered me for three years and it still doesn't :P

Colin

I found it slightly frusterating, but you won't have to  deal with it after one more post.
"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin

KitLightning

Does that mean I can have a sassy avatar after this post :D

LiroyvH

((U + C + I)x(10 − S)) / 20xAx1 / (1 − sin(F / 10))
President/CEO of Simple Machines - Server Manager
Please do not PM for support - anything else is usually OK.

KitLightning


mashby

It's a 120X120 px square animation. Avatars are limited to 100px square and have a file size limitation, too. :)
Always be a little kinder than necessary.
- James M. Barrie

KitLightning


Unruler

I can definitely agree that it's more of a capcha's problem, some letters are just way too similar like u v g y so I cannot tell what the are. Perhaps you should go for capital letters.

And that avatar is terrible btw  :P

MorozAlex

#39
Well i find these letters enough clear and in other case you can listen to the audio version of a captcha. Keep up good work!
__________________________________________________________________
greenavis.com
-Alex Koz

medicdude

The correct title for your topic is: "Your Captcha is too hard to read here".

The correct recommendation is to implement a captcha alternative such as PlayThru hxxp:areyouahuman.com [nonactive]

Have nice day.

emanuele

Quote from: medicdude on December 17, 2012, 08:25:11 AM
The correct recommendation is to implement a captcha alternative such as PlayThru areyouahuman.com
1) if the spambots learn how to play with canvas, those games are easier to solve than a captcha (I can do as many errors I want and I can continue without any sort of halt),
2) have you tried the audio? English is not my first language, but for several years English has been my day-to-day working language and still I can't understand *anything*, absolutely anything (okay, I got a 4 now, but it was just luck).

Of course captcha are not very effective ( :P), but the most important thing is usually to have something "different", whatever it is should be something that is not spread enough to be worth the time to understand how to bypass it.


Take a peek at what I'm doing! ;D




Hai bisogno di supporto in Italiano?

Aiutateci ad aiutarvi: spiegate bene il vostro problema: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.

karalahana

QuoteThe correct title for your topic is: "Your  is too hard to read here".

:) I think this Captcha must be standart all smf forums

enypsrozar

Quote from: Irisado on September 19, 2012, 09:15:10 AM
It's annoying to make it through your first ten posts here, I agree, but I don't think that it can be changed.  A few spammers still make it through the system here as it is without making life easier for them, so I have to say that I back the Staff at SMF leaving the limit unchanged.

Blame the spammers, for it is their actions that have forced this to be implemented in the first place.

No way, limit is 10 before catchpa is removed? Crap, I thought it was 100. Relief!! And I didn't know you got spammers here. Yes I'm new! Still looking at stickies and tutorials to get a feel of place, there's a lot of info to go through.

Irisado

Quote from: enypsrozar on February 04, 2013, 09:26:44 AM
No way, limit is 10 before catchpa is removed? Crap, I thought it was 100. Relief!! And I didn't know you got spammers here. Yes I'm new! Still looking at stickies and tutorials to get a feel of place, there's a lot of info to go through.

There are plenty of spammers which still make it through the net, so just think how many more would break through without the measures which currently exist.

Anyway, as you're discovering, it doesn't look as though it will take you too long to reach the magic ten, and it's a refreshing change to see somebody reading the stickies too :).
Soñando con una playa donde brilla el sol, un arco iris ilumina el cielo, y el mar espejea iridescentemente

enypsrozar

#45
Quote from: Irisado on February 04, 2013, 12:21:28 PM
Anyway, as you're discovering, it doesn't look as though it will take you too long to reach the magic ten, and it's a refreshing change to see somebody reading the stickies too :).

True. In another SMF forum you need 100 posts before the catchpa is removed :o . And they have just upgraded to a 2.0.2, so they are really behind already.

Quote from: Irisado on February 04, 2013, 12:21:28 PM
There are plenty of spammers which still make it through the net, so just think how many more would break through without the measures which currently exist.

They manage to get through even with the 100 post minimum and [edit.] and they still manage to get through. Frustrating to deal with. I haven't seen a single spam attack on this forum yet. (lol, it's my first night on) ::) Lol, yeah, I'm still reading the stickies -- there's heaps, lol. O:)

Kindred

oh, there are still a fair number of spammers that get through. Luckily, we have a team who tries to keep on top of it - and we have a community who report the spam when they notice it.

Unfortunately, the best ways to prevent spam are not necesarriyl available to this community - primary method: questions instead of CAPTCHA. Unfortunately (in 2.0) questions do not support the multilingual nature of our site. secondary methods: The best of these use third party services - which is something we try to avoid on this site.
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Advertisement: