Hacker News new | ask | show | jobs
by pooriaazimi 5004 days ago
The problem is, it's always in the form of "x + y = ?", which makes it ridiculously easy to bypass with an script.

At least that's what I initially thought. But after some more digging it seems that x and y are hard-coded to be 2 and 3, respectively.

I opened the registration page in 4 different browsers with different IP addresses (my own, my VPS, and a couple borrowed from Tor) and in all cases the "security" question was "What is 2 + 3?"

Unbelievable.

1 comments

Ten minutes to implement, stops nearly all automated attacks that aren't specific to this site, much less user hostile, and far fewer accessibility issues.

Believable.

Not to mention a placeholder for a more advanced captcha to eventually be deployed.

Extremely believable.