manton
manton

I don’t like captchas and will never force them on my customers. With AI, captchas will become increasingly useless anyway. See also, John Mulaney: “I’ve devised a question no robot could ever answer…Which of these pictures does not have a stop sign in it?”

|
Embed
Progress spinner
paulca@mastodon.social
paulca@mastodon.social

@manton — This might be of use as a secondary layer github.com/BaseSecrete/active_

|
Embed
Progress spinner
manton
manton

@paulca That looks good, thanks! I don't use Rails but maybe I can adapt the ideas.

|
Embed
Progress spinner
paulca@mastodon.social
paulca@mastodon.social

@manton — Yeah, hash cash is conceptually extremely simple, and you have the ability to dynamically increase the difficulty in response to repeated failed attempts. Very clever.

|
Embed
Progress spinner
SteveSawczyn
SteveSawczyn

@manton Thank you for not embracing CAPTCHAs, they're an accessibility nightmare. Getting locked out of something or other because of an inaccessible CAPTCHA is sadly a frequent occurrence for me. CAPTCHAs suck the joy right out of an experience.

|
Embed
Progress spinner
In reply to
jade
jade

@manton The tech to replace CAPTCHAs is already here with the Privacy Pass Protocol and, by extension, Private Access Tokens. Essentially, use device data points to build entropy that’s indicative of human behavior.

For reference:
- WWDC22: Replace CAPTCHAs with Private Access Tokens
- Cloudflare: Private Access Tokens: eliminating CAPTCHAs on iPhones and Macs with open standards

It seems only Apple and Cloudflare are pushing for these standards; more adoption is needed.

|
Embed
Progress spinner
manton
manton

@jade I completely forgot about that WWDC session! Thanks.

|
Embed
Progress spinner