We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38878
    • 255 Posts
    That's a little farther than I got.;) I d/l'ed the ayah code and ran it fine outside modx. Thinking about all the addons recaptcha is integrated into such as quip, formit, etc took the wind out of my sails a bit. I guess there's no secret sauce there;)
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      Well, since I can't clone myself and my time is severely limited (bad eyes) so I have to prioritize strictly, and this is, I'm afraid, not too close to the top of my priorities list right now, it may be a while before I come up with a drop-in plugin. Somebody else may do something with it before I get to it, we can hope.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 38878
        • 255 Posts
        I guess if there's value, someone will take the time. Maybe the AYAH folks can rectify their overlooking of the best CMS around and get it done. *cough*

        /lectio divinas
          • 37059
          • 368 Posts
          As a first-time user, I was somewhat underwhelmed by Are You Human. Perhaps I'm stupid, but when asked to "feed the baby", I picked the first food item I saw - a carrot, fed that to the baby, and then clicked the verify button - which accused me of being a bot. Turns out, you have to feed two food items to the baby. If this had been a third-party website and not a demo, I would have been pretty irritated.
            Jason
            • 28042 ☆ A M B ☆
            • 24,524 Posts
            Well, I got an email from them "congratulating" me on the activity they saw on my account. I was not particularly thrilled at this blatant admission that they track their user's activity. I won't be using it.
              Studying MODX in the desert - http://sottwell.com
              Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
              Join the Slack Community - http://modx.org
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              Now this one definitely has promise.

              http://dice-captcha.com/
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 37059
                • 368 Posts
                Looks kinda easy to crack - counting dots is easier than OCR, and I hear most character CAPTCHAs can already be cracked.
                  Jason
                  • 38878
                  • 255 Posts
                  The debate on whether or not image captchas are crackable or not isn't really the point of this topic. Everything is "crackable" with enough incentive. The intent of image captchas like this is to raise the bar on automated exploits while keeping it low for humans.

                  The issues with the AYAH as sotwell put it is that it is hosted only by them (strike 1), and that they are tracking usage (strike 2).

                  I agree this dice thingy looks more "secure" to me because it doesn't have two strikes against it. Worth looking into when it becomes available. Of course they list WP, Joomla, and Drupal. No mention of MODX yet. FWIW, I sent them an email to "suggest" it. We will see. [ed. note: harveyev last edited this post 14 years ago.]
                    • 28042 ☆ A M B ☆
                    • 24,524 Posts
                    Unfortunately the dice also just struck out as far as I'm concerned. I asked him when it would be available, and got this in reply:

                    Do you have Zend Encoder/IonCube installed? Because I'm going protect my code with Zend Encoder and/or IonCube.

                    It's his code, and certainly his decision, but I don't work that way. Not only for philosophical reasons, but also because I'm not going to put unknown code on any site of mine or my clients.
                      Studying MODX in the desert - http://sottwell.com
                      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                      Join the Slack Community - http://modx.org
                      • 37059
                      • 368 Posts
                      Quote from: harveyev at Sep 12, 2012, 05:01 AM
                      The debate on whether or not image captchas are crackable or not isn't really the point of this topic. Everything is "crackable" with enough incentive. The intent of image captchas like this is to raise the bar on automated exploits while keeping it low for humans.

                      I believe crack-ability is an important issue, and highly relevant to this topic. I quote from the OP, describing the issues with current technologies:

                      As the bots get smarter to crack captcha, the captcha words need to become more obfuscated to stay one step ahead of the bots.

                      I don't expect any CAPTCHA to be "un-crackable" - but dice with dots to add up? Really? Maybe I'm wrong, but that seems like a leap backwards in obfuscation. It's hard to imagine something easier for even the worst OCR algorithm to handle than counting some dots.

                      Just my $.02USD.
                        Jason