# Five downloads in under a minute

Security galaxy · Cédric Merlin, CTO · https://merlin-cedric.fr/en/securite/captcha/

Blocking bots on a public form without a third-party captcha: single-use signed token, decoy field, a rate limit that survives redeployments.

## The problem

A bot was downloading a website’s free guides through its public form: six in two days, five of them in under a minute.

## The constraint

Block the bots without a third-party captcha that tracks visitors.

## What I did

1. **Audit.** A captcha was in the code, but had never been turned on.
2. **Signed token.** The server signs each form, and a token works only once.
3. **Decoy field.** Invisible to a human, filled in by bots.
4. **Rate limit.** It holds even after a redeployment.

## The result

Bots fail, and visitors notice no difference.

## Stack

HMAC, Node.js

---
Page: https://merlin-cedric.fr/en/securite/captcha/ · Contact: contact@merlin-cedric.fr
