Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

I’m curious, what’s the best option for protecting web forms if not using reCAPTCHA? Specifically for things like account sign ups?


It depends what value there is in an account, but for a service I run, I just let the bots sign up accounts.

Accounts don't really cost me anything, and they get automatically deactivated if they didn't get any activity in the first 30 days anyway. Activity on my service costs money, so if someone wants to make a bot that pays me money, I have no problem with that.

The only time I'd consider implementing something like reCAPTCHA is if I was giving something away for free (e.g. a free trial) such that a signup actually had a cost for me.


I was more concerned about triggering activation emails to people


If you collect email addresses, then yeah that's a concern. Then again, if you send a single activation email and never send another email unless the link is clicked, there's no value to the bot in signing up accounts, so it's unlikely to be a major problem.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: