Interesting, but not what I intended to suggest. Using a timestamp when generating the hash needlessly complicates verification.
What I meant to suggest was that you save a timestamp when you record generated IDs. This gives you an easy way to "time out" forms, and flush abandoned forms out of your back-end database. It also sets you up for doing some analysis on things like average submit time (the gap between your generating the form, and a user submitting it). A really low submit time is an indication that there's a bot on the other end of the line.
In reply to Re: Re: Re: Thwarting Screen Scrapers
by dws
in thread Thwarting Screen Scrapers
by kschwab
For: | Use: | ||
& | & | ||
< | < | ||
> | > | ||
[ | [ | ||
] | ] |