MyBB Community Forums

Full Version: Image Verification Mybb 1.0.3
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2
A few people have emailed me with problems using the registration verification image. I'm not sure if this has anything to do with the mybb 1.0.3 update, but I never had a problem before. They enter the correct numbers and letters, but the system keeps saying it's wrong.
I haven't been able to replicate this problem. Is anyone else having image verification issues?
It works on my forum
Please make sure they're not mistaking letters for numbers and visa versa.
Could we get rid of easily confused pairs? Even 5 and S look alike in some fonts,

A far better option would be a simple 2-digit addition problem that doesn't require carrying over. This has the added benefits of being compatible with accessibility technologies.
laie_techie Wrote:Could we get rid of easily confused pairs? Even 5 and S look alike in some fonts,

A far better option would be a simple 2-digit addition problem that doesn't require carrying over. This has the added benefits of being compatible with accessibility technologies.

I think that's an interesting solution. Doesn't seem like anyone (even outside of bulletin boards) usually use that kind of verification.
If it was too simple, the number of possible combinations would be too limited, and therefore it wouldn't be secure enough.

With a string of 8 characters randomly selected from a set of 61 (a-z, A-Z, 1-9), the current method has a lot of potential combinations (someone else can do the math Toungue).

A simple addition problem has far fewer...
image cached in users' ISP cache proxy server.
WDZ Wrote:If it was too simple, the number of possible combinations would be too limited, and therefore it wouldn't be secure enough.

With a string of 8 characters randomly selected from a set of 61 (a-z, A-Z, 1-9), the current method has a lot of potential combinations (someone else can do the math Toungue).

A simple addition problem has far fewer...

Image verification (a-zA-Z,1-9; 8 characters long) = 191,707,312,997,281 combinations.
Image verification(same as above, but removing l,I,5,S) = 96,717,311,574,016 combinations.
Two digit addition (no carry over) = 1620 possible questions with 80 possible solutions
Each additional digit multiplies the question base by 45 and the solution base by 10

Are 80 possible solutions too insecure? I thought the main goal was to determine if the user is a bot or a person.
It's also to prevent spamming creation of new accounts.
Pages: 1 2