ara.t.howard wrote:
>
>  - image has an encoded timebomb in it: attacker has only 60s for 
> post.  this just rules out brute force attacks.

 From when does it start counting?  If I've read a blog post and then 
try to comment, it's likely I've already used more than 60 seconds.  In 
fact, probably most of the time I take more than 60 seconds to comment 
by itself.

I think a good protection scheme will take into account several factors, 
assign them points for failure (or passing), and once a threshold has 
been reached, fail the entire thing (or pass it, if you chose that route).

Sam