non-JS
WebAssembly
Erm... technically correct I guess? But disappointing. Other solutions let you run a local command to generate the response and then paste it into a form.
I sortof understand the argument that it can look like what some malware does, but I feel like there should be an easy fix for that, like maybe just label it as an "advanced user" feature or something, so at least it's still available. I just feel like requiring wasm is a step in the wrong direction and even moreso shuts out legitimate users that don't have/enable wasm on their browser.
Yes but it doesn't actually do any work or verify anything... crawlers could follow the refresh URL immediately and get right through. And I'm skeptical that not having to actually solve a PoW could make a meaningful difference, especially if the delay from the meta refresh can be easily bypassed.