Forum Moderators: phranque
It seems like the first thing we should do is setup one of these graphical "challenge" systems where the user has to enter a security code that is usually displayed as distorted text, etc. Sites like Yahoo, Overture, etc. use this type of system. I think it originated at [captcha.net...]
My question is, is there a product/script etc. available that we can use to implement this functionality at our site, or is this script custom and Overture, Yahoo, etc. are paying their super duper programmers to develop this stuff?
The bad news:
[perlmonks.org...]
Be sure to read the comments at the bootom of the "bad news" link as it discusses how these systems are not fool proof.
You would be better served emailing the person a link with a one-time valid session ID string URL they must follow which features this sort of challenge/response system but I could be just paranoid.
For every system there is a weakness, and those willing to find and exploit it.
-ben