ara.t.howard wrote: > > - image has an encoded timebomb in it: attacker has only 60s for > post. this just rules out brute force attacks. From when does it start counting? If I've read a blog post and then try to comment, it's likely I've already used more than 60 seconds. In fact, probably most of the time I take more than 60 seconds to comment by itself. I think a good protection scheme will take into account several factors, assign them points for failure (or passing), and once a threshold has been reached, fail the entire thing (or pass it, if you chose that route). Sam