Scr.im » Share your email in a safe way. Get less spam.(scr.im)
scr.im
Scr.im » Share your email in a safe way. Get less spam.
http://scr.im/
8 comments
How about coining it "cargo cult captcha"[1] :) It seems there are lots of futile CAPTCHAs popping out these days.
[1] http://en.wikipedia.org/wiki/Cargo_cult
[1] http://en.wikipedia.org/wiki/Cargo_cult
Quoting their FAQ:
" The Captcha (humanity check) is way too simple, I can bruteforce it with a script!
It's exactly how it should be. It's not an unbreakable locker. We prefer simple captchas, ease of use and convenience over undecypherable and cumbersome enigmas. "
Not convinced...
" The Captcha (humanity check) is way too simple, I can bruteforce it with a script!
It's exactly how it should be. It's not an unbreakable locker. We prefer simple captchas, ease of use and convenience over undecypherable and cumbersome enigmas. "
Not convinced...
Sorry, the CAPTCHA is completely pointless. Here's why:
1. Go to http://scr.im/test
2. Click the upper right box
3. If you receive an error page, click "Try Again" and go to step 1.
4. You should arrive at this step in approximately 9 tries (on average) taking less than 15 seconds.
What the heck is the point of a "human test" if it can be automatically attacked by a bot with literally no effort at all. The funny thing is that there is a more traditional CAPTCHA at http://scr.im/test?failsafe=1 that is much more secure.
Why is the default CAPTCHA pointless? Because it attempts to test for "human-ness" without requiring any human action what so ever. Click a link, the same link, over and over until it is correct is what a bot will do. On the flip side, using your eyes to interpret slightly out of skew characters is decidedly much harder for anything other than a "human" to do.
1. Go to http://scr.im/test
2. Click the upper right box
3. If you receive an error page, click "Try Again" and go to step 1.
4. You should arrive at this step in approximately 9 tries (on average) taking less than 15 seconds.
What the heck is the point of a "human test" if it can be automatically attacked by a bot with literally no effort at all. The funny thing is that there is a more traditional CAPTCHA at http://scr.im/test?failsafe=1 that is much more secure.
Why is the default CAPTCHA pointless? Because it attempts to test for "human-ness" without requiring any human action what so ever. Click a link, the same link, over and over until it is correct is what a bot will do. On the flip side, using your eyes to interpret slightly out of skew characters is decidedly much harder for anything other than a "human" to do.
[deleted]
I still don't get why anyone would want to use this service. First, if you've had an e-mail for long enough, chances are you are already getting spammed like hell. Second, if you really really wanted to keep your e-mail free from spam, you would use a truly unbreakable captcha.
IMHO, the only viable solution to spam nowadays is filtering - not prevention.
IMHO, the only viable solution to spam nowadays is filtering - not prevention.
Yeah, I don't understand how that helps with the goal of protecting my email...
If anything, it will do the opposite.
https://encrypted.google.com/search?q=http://scr.im/
95,000 results. Easily scriptable. Any spammers out there want a list of email addresses of people who are interested in spam protection?
https://encrypted.google.com/search?q=http://scr.im/
95,000 results. Easily scriptable. Any spammers out there want a list of email addresses of people who are interested in spam protection?
Quickly scanning a few randomly selected search result pages revealed exactly zero links to email addresses protected by scr.im.
You didn't look very hard then, there's loads.
He explains it in the FAQ.
The explanation (CAPTCHAs should be simple for humans; we don't say it's unbreakable) still doesn't address the underlying problem. It is too easy. I have no idea how to do image recognition and yet I could use this to scrape the addresses.
Moreover, this service has a great potential to use real human language and context to protect the addresses and provide easy and accessible test.
Just let me type a freeform question and an expected answer.
If I posted the link here and it asked you to enter the city I live in, everyone reading this comment here on Hacker News could easily figure it out.
Breaking this solution in general would be infeasible for bots.
Moreover, this service has a great potential to use real human language and context to protect the addresses and provide easy and accessible test.
Just let me type a freeform question and an expected answer.
If I posted the link here and it asked you to enter the city I live in, everyone reading this comment here on Hacker News could easily figure it out.
Breaking this solution in general would be infeasible for bots.
A captcha is something which can tell the difference between a human and a computer. What he's using is something other than a captcha. Not sure what it is, but it isn't a captcha. What it definitely is though is a massive waste of time.
Maybe give reCAPTCHA Mailhide a try if you want to use a system with a more sophisticated Captcha system for this kind of thing: http://www.google.com/recaptcha/mailhide/
Could this instead be turned into a challenge response system.
mailhide+ would give you a disposable email, the person sending would use that, get back a captcha link, solve the captcha and your email is forwarded on. Optionally the sender is then whitelisted for sending to your address, further options would reply with your direct email address once the challenge had been completed.
This would mean that you'd have an email address to give people when asked for an email address (rather than a website).
mailhide+ would give you a disposable email, the person sending would use that, get back a captcha link, solve the captcha and your email is forwarded on. Optionally the sender is then whitelisted for sending to your address, further options would reply with your direct email address once the challenge had been completed.
This would mean that you'd have an email address to give people when asked for an email address (rather than a website).
Challenge/response emails have largely been dropped. If you implement such a system you end up on blacklists for generating backscatter. If SPF/DKIM ever become ubiquitous then we'll be able to look at using those sorts of systems again.
The FAQ doesn't explain why sharing your e-mail address on that site is safe.
After I started using gmail, 99.9% of my spam started getting filtered out. Now I can post my email wherever I like. It sure beats making customers jump through an extra hoop to contact me.
I think an effective system would be using html5/flash that grabs an image and requires a user to do some movement with their mouse. i.e. select a house with a broken window, followed by a house with red windows and followed by a house with smoke coming out of it.
since it's flash/html5, I figure its going to be a lot harder to automate a way to break it.
since it's flash/html5, I figure its going to be a lot harder to automate a way to break it.
This is a clever idea. The 1 in 9 captcha test was a poor decision, but if he forced everyone to type in a reCAPTCHA instead I think it would be a good service. Simple and effective enough. I wish I had thought of it.
As giu said. This already exists:
http://www.google.com/recaptcha/mailhide/
scr.im is just a much worse version of mailhide
http://www.google.com/recaptcha/mailhide/
scr.im is just a much worse version of mailhide
[deleted]
It apparently treats '+' as invalid in an email, too.
Waste of a great domain name. :/
http://scr.im/test
Are you joking? There is a 1 in 9 chance of getting the captcha right if you pick completely randomly. If I was writing a program to scrape these addresses your entire captcha system might add 2 minutes of programming time to the job.