#altcha — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #altcha, aggregated by home.social.
-
Learn how to set up free bot and fake account protection with CrowdSec and ALTCHA on Ubuntu. Block fake signups, spam, and abusive bots.
Full guide here: https://ostechnix.com/build-free-bot-fake-account-protection-crowdsec-altcha-ubuntu/
#Crowdsec #Altcha #Captcha #reCAPTCHA #BotProtection #IntrusionPreventionSystem #Websitesecurity
-
Nearly three weeks in and my conclusion is pretty clear: #ALTCHA works (good enough)! 🧵
-
Ouch, #enshittification.
To anyone still on #WordPress and in need of a CAPTCHA plugin, I would always recommend using the open-source plugin called ALTCHA Spam Protection from altcha.org. If you don't know, #ALTCHA is a self-hosted alternative to your typical CAPTCHA, and it uses the proof-of-work mechanism hidden behind a single and simple checkbox instead of making your visitors pick busses or pedestrian crosses from multiple reloading photos, or align puzzle fragments with their designated places in the background images. It's alsio GDPR compliant because you aren't sharing any cookies or visitor info with third parties like Google.
So anyway, v1 of that WordPress plugin feels just perfect for a relatively small site: it's FLOSS, fully-functional, and handles not only Wordpress' stock forms, but also integrates with forms provided by some popular plugins too.
But then last autumn, came version 2 of the plugin, which, unlike v1, is a commercial product, built from a new repo, where
LICENSE.txthas no traces of the original GPL license, but instead contains a EULA, which only grants end user two freedoms regarding the code:1. Access and use the Software solely for internal development, testing, debugging, and evaluation;
2. Create Modifications of the Software solely for internal testing, debugging, and evaluation purposes.Almost immediately, the FLOSS version 1 was marked as obsolete and all development on it ceased. The only "feature" that came out with version 1.26.2 was the nagbar, recommending all users to upgrade, and conveniently skipping the fact that the new version was a different plugin entirely. Only one bugfix version (1.26.3) came after.
When I noticed the nagbar, I raised a question in the GitHub repo of the original plugin, asking about its support status. IIRC, the response was something among the lines of "this plugin can be used indefinitely, but if you want any changes, you'll have to provide PR's", which seems reasonable. Actually, there's a similar topic on WordPress' support forum for this plugin, where the author said that as well, and even recommended continued use of version 1 for those who need its functionality.
Fast forward to this May, and – cue the drumroll – version 3.0.0 of the plugin was pushed to WordPress SVN repo. Guess what: all original functionality was deleted, and the plugin was renamed from "ALTCHA Spam Protection" to "ALTCHA: Spam Protection (Installer)". Anyone who updated the plugin automatically (or clicked the update plugins button without much investigation) suddenly lost their CAPTCHA functionality and got an unwanted "installer" for the commercial plugin instead. Two days later WordPress disabled the plugin and its downloads, citing "Guideline Violation", but the damage had been done already.
Nice, yeah? But that's not all. At some point this year (likely a bit later), the original plugin's repository has vanished from GitHub as well. Luckily, someone had forked a copy before that. Well, now I have my own fork as well!
It's just really disappointing to see a good product become hostage to its author's commercial ambitions to such an extent that they will actively harm its reputation along with their own. Did the dude really think people would be more willing pay for his commercial services if he screwed them over first?
-
I've finally replaced the old-school #CAPTCHA required to sign up on https://cvecrowd.com with an open-source, #privacy preserving, #accessible, and globally compliant alternative: #ALTCHA
It relies on proof of work and I am super hyped to see whether it will prevent #bots from signing up. I'll keep you updated :)
-
Ein mögliche Alternative heute entdeckt, wer kennt und nutzt #altcha https://altcha.org/de/ ? #captcha #recaptcha #privacy #gdpr
-
𝗔𝗹𝘁𝗰𝗵𝗮:
https://thewhale.cc/posts/altcha
ALTCHA provides privacy-first spam protection with a globally compliant and accessible alternative to CAPTCHAs. Protects against spam and abuse without tracking users, complying with GDPR, CCPA, and other regulations while ensuring a frictionless experience.
-
„This Is Why We Can't Have Nice Things“ – selbstverwaltetes Newsletter-Bestell-Formular führte natürlich in kurzer Zeit zu nervigen Spam-Attacken. Mit #altcha habe ich jetzt mal eine Datenschutz-konforme (und selbstgehostete) Lösung eingebaut – ich hoffe, das hilft dann auch längerfristig ... https://dezolat.de/ #webdevelopment #php #silverstripe
-
So glad I didn't go for #cloudflare turnstile as a captcha for my #AI slop blocker extension signup.
Though, I have to check whether #resend uses cloud flare 🤔 unfortunately email sending was the one thing I couldn't do either from my VPS or from my #homelab
-
Glad I used #Altcha running on my own server to protect the account signup #API for my #AISlop browser extension. Unfortunately I can't log in to my #digitalocean account to check on my droplet because of #Cloudflare 🙄
-
#ALTCHA and #Favicons approved for the #FSF #FSD and more accomplished at last Friday's FSD meeting: https://u.fsf.org/488
-
Voilà une autre de nos dernières créations en interne : un logiciel pour créer facilement des formulaires sur des sites statiques, nommé lsforms (pour Libre Static Forms) :
https://git.lacontrevoie.fr/lacontrevoie/lsformsCet outil, écrit en langage #Rust, intègre notamment un captcha accessible basé sur #ALTCHA !
Il est notamment utilisé pour notre formulaire de contact :
https://lacontrevoie.fr/contact/Les contributions sont les bienvenues !
-
Nous avons développé le plugin keycloak-altcha, un captcha pour #Keycloak basé sur #ALTCHA :
https://git.lacontrevoie.fr/lacontrevoie/keycloak-altcha
https://altcha.org/Il ne nécessite pas de résoudre un puzzle ou de cliquer sur des feux de signalisation, mais simplement d’attendre quelques secondes : c’est un captcha « proof-of-work ».
Il fonctionne de la même manière que le plugin Anubis, utilisé par de nombreux logiciels libres ces derniers mois.
Nous accueillerions volontiers des contributions au code :)
-
Lightweight open source reCaptcha alternative
https://github.com/altcha-org/altcha
#HackerNews #Lightweight #open #source #reCaptcha #alternative #open-source #reCaptcha #altcha #cybersecurity #webdevelopment
-
Nous venons de développer en interne une extension pour générer des captchas sur Keycloak !
https://git.lacontrevoie.fr/lacontrevoie/keycloak-altchaElle utilise ALTCHA, un captcha « proof-of-work » : 100% accessible pour les personnes malvoyantes, validé sans interaction.
L’extension n’envoie aucune requête externe, elle génère elle-même le captcha.
Puisse cette extension être utile à d’autres !
-
Je cherchais une alternative libre (et qui ne repose pas sur un service tiers) à reCAPTCHA et cie.
J'étais tombé sur ALTCHA:
https://altcha.org/captcha/C'est une bibliothèque toute simple, qui repose sur une preuve de calcul, permettant de bloquer les bots simplistes ou d'augmenter le coût pour les bots plus poussés.
Je l'ai mis en prod chez un client y'a 1 mois.
Pour l'instant les retours sont positifs. À priori ça n'a bloqué aucune personne, et le spam s'est arrêté. -
#Altcha is a free, open-source
captcha alternative -
Une découverte récente : ALTCHA un captcha alternatif gratuit et open-source
-
Nie używałem Ninja Forms, #Altcha ma plugin do #wordpres-a:
https://github.com/altcha-org/wordpress-plugin
Może coś z tym wykombinujesz.
-
-
ALTCHA is a free, open-source CAPTCHA alternative that protects your website from spam and abuse.
Their SDK makes it very easy to get started.