Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Captchas are not just ddos protection, and even if it were, the botnets don't send tons of spam from any single device. Otherwise it's too easy to identify and block.


That's why you use something like this, where each request incurs a cost for the attacker so it doesn't matter if the origins are distributed.


The attacker doesn't have to calculate the puzzles in one central place. It can do that on the hacked devices.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: