• 0 Posts
  • 8 Comments
Joined 1 year ago
cake
Cake day: June 15th, 2023

help-circle





  • eyy@lemm.eetoLemmy@lemmy.mlProtect. Moderate. Purge. Your. Sever.
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    3
    ·
    edit-2
    1 year ago

    You’re right that captchas can be bypassed, but I disagree that they’re useless.

    Do you lock your house? Are you aware that most locks can be picked and windows can be smashed?

    captchas can be defeated, but that doesn’t mean they’re useless - they increase the level of friction required to automate malicious activity. Maybe not a lot, but along with other measures, it may make it tricky enough to circumvent that it discourages a good percentage of bot spammers. It’s the “Swiss cheese” model of security.

    Registration applications stop bots, but it also stops legitimate users. I almost didn’t get onto the fediverse because of registration applications. I filled out applications at lemmy.ml and beehaw.org, and then forgot about it. Two days later, I got reminded of the fediverse, and luckily I found this instance that didn’t require some sort of application to join.


  • eyy@lemm.eetoLemmy@lemmy.mlProtect. Moderate. Purge. Your. Sever.
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    3
    ·
    1 year ago

    Haven’t you heard of the “Swiss cheese” model of security?

    The best way to ensure your server is protected is to unplug it from the Internet and put it in an EMF-shielded Faraday cage.

    There’s always a tradeoff between security, usability and cost.

    captchas can be defeated, but that doesn’t mean they’re useless - they increase the level of friction required to automate malicious activity. Maybe not a lot, but along with other measures, it may make it tricky enough to circumvent that it discourages a good percentage of bot spammers.