Suggestions for the future on your web site: (was cookies, and before that Re: Dreamhost hijacking my prefix...)
rsk at gsp.org
Wed Jan 23 08:45:42 UTC 2013
On Mon, Jan 21, 2013 at 02:23:53AM -0600, Jimmy Hess wrote:
> that sort of abuse is likely need to be protected against
> via a captcha challenge as well,
Once again: captchas have zero security value. They either defend
(a) resources worth attacking or (b) resources not worth attacking. If it's
(a) then they can and will be defeated as soon as someone chooses to
trouble themselves to do so. If it's (b) then they're not worth the
effort to deploy. See, for example:
Now I'll grant that captchas aren't as miserably stupid as constructs
like "user at example dot com"  but they really are worthless the
moment they're confronted by even a modestly clueful/resourceful adversary.
 Such constructs are based on the proposition that spammers capable
of writing and deploying sophisticated malware, operating enormous botnets,
maintaining massive address databases, etc., are somehow mysteriously
incapable of writing
perl -pe 's/[ ]+dot[ ]+/./g; s/[ ]+at[ ]*/@/g; print $_, "\n";'
and similar trivial bits of deobfuscation code.
More information about the NANOG