Joerg Jaspert <joerg@debconf.org> wrote:
> Captchas *DO* help, wiki.debconf.org spamrate dropped a hell of a lot
> since it uses captchas.

wiki.debconf.org is a bit of a different situation.  Anyway, it
doesn't seem to require captchas to interact, which is good.  Its
registration captcha also seems to be a numeracy test, rather than the
more common eyetest.

In general, however, captchas block some abuse, but also some
legitimate contributors, which I think is very harmful, worse than the
spam.  Please no anecdotes and blunt contradictions - see
http://www.w3.org/TR/turingtest and the many other explanations.

We need to try to design out abuse, as far as is possible.  This is
sort of analogous to the approach of Secure By Design in architecture.
See http://www.securedbydesign.com/

> email confirm is a must anyway if we go and sent mail to them...

Oh well, at least we agree on that!

