tag:blogger.com,1999:blog-1033933413127832310.post2009826273352668006..comments2008-06-26T08:54:29.352-07:00Comments on Kick me in the nuts: Red ListingJon Scott Stevenshttp://www.blogger.com/profile/11867559494404858630noreply@blogger.comBlogger4125tag:blogger.com,1999:blog-1033933413127832310.post-28419766052655747472008-06-26T08:54:00.000-07:002008-06-26T08:54:00.000-07:002008-06-26T08:54:00.000-07:00a) why wow? it makes sense to me to not want to im...a) why wow? it makes sense to me to not want to impact sales. =) we require cookies to be enabled though. i wish we didn't, but in order to implement our cross domain single signon system (SSO), we had to do it. we display a nice "we require cookies page" similar to the one that gmail displays.<BR/><BR/>b) I'll make another posting at a later date about how I already tried making it more expensive for them and they (within a day) worked around it. Sure, it wasn't as expensive as firing up rhino, but it required parsing the html. Executing the javascript in rhino is just the next step for them. Not a big deal if you are a hacker and know what you are doing.Jon Scott Stevenshttp://www.blogger.com/profile/11867559494404858630noreply@blogger.comtag:blogger.com,1999:blog-1033933413127832310.post-1247456374329171432008-06-25T23:47:00.000-07:002008-06-25T23:47:00.000-07:002008-06-25T23:47:00.000-07:00a) Wow.b) Yet the attack would be made more expens...a) Wow.<BR/>b) Yet the attack would be made more expensive for them.jergendutchhttp://www.blogger.com/profile/08606437541598491954noreply@blogger.comtag:blogger.com,1999:blog-1033933413127832310.post-84706257627641508862008-06-25T09:02:00.000-07:002008-06-25T09:02:00.000-07:002008-06-25T09:02:00.000-07:00a) we don't require javascript for login (or our s...a) we don't require javascript for login (or our sites). that might have an impact on sales.<BR/>b) all spammers need to do is use Rhino (or another javascript engine) to get past that check.Jon Scott Stevenshttp://www.blogger.com/profile/11867559494404858630noreply@blogger.comtag:blogger.com,1999:blog-1033933413127832310.post-2620569402947713152008-06-25T07:20:00.000-07:002008-06-25T07:20:00.000-07:002008-06-25T07:20:00.000-07:00If your website requires JavaScript you could use ...If your website requires JavaScript you could use something similar to WordPress HashCash:<BR/>http://wordpress.org/extend/plugins/wp-hashcash/jergendutchhttp://www.blogger.com/profile/08606437541598491954noreply@blogger.com