Discuss! Plugin Ant Local Human-Machine Verification (ALTCHA V2)
Xiaoyi's local human-machine verification uses the ALTCHA V2 protocol. Both the verification components and challenge computation are deployed locally on the site and do not rely on third-party CAPTCHA platforms.
Support Discuz! X3.5, X5.0, X5.1
PHP version requirements:Must be PHP 8.1+ or above
The site must be enabled and requires HTTPS (you can ask Ai how to enable it).
Based on ALTCHA V2, PBKDF2/SHA-256
Run completely locally without calling third-party authentication services
Supports verification scenarios such as registration, login, posting, and replying.
Supports authentication difficulty, security policies, topics, and key configuration
ALTCHA V2 (an open-source project from a well-known international company)https://github.com/altcha-orgLocal deployment advantages
Xiaoyi's local human-machine verification uses the ALTCHA V2 protocol. Both the verification components and challenge computation are deployed locally on the site and do not rely on third-party CAPTCHA platforms.
Main advantages:
• Better privacy: User verification data, IP addresses, and behavioral information do not need to be sent to third-party CAPTCHA services.
- Fully local operation: Does not rely on external services such as Google reCAPTCHA and Cloudflare Turnstile to avoid unavailability of overseas networks or interfaces.
• Cost savings: There is no need to purchase a third-party CAPTCHA package, and there is no limit on the number of calls.
- Faster loading: No need to load external scripts and cross-site resources, resulting in a more stable domestic access and mobile experience.
- Suitable for domestic sites: Unaffected by third-party service access speeds, regional restrictions, or changes in service strategies in China.
- Controllable: Site owners can adjust PBKDF2 computational difficulty, security policies, authentication topics, and keys.
- Compatible with Discuz's native verification mechanism: can be used in scenarios such as registration, login, posting, and replying.
- Easy auditing and maintenance: Challenge generation, verification, and configuration logic are all local to the plugin, allowing website owners to manage them independently.
- Reduce bulk machine commits: Browsers need to complete certain PBKDF2/SHA-256 calculations, which can increase the cost of bulk registration and automatic commits.
Working mode
The user's browser first completes the local compute challenge for ALTCHA V2, and then the server verifies the result using the local key. Once verified, Discuz proceeds to register, log in, or post.
Please note
ALTCHA V2 is a human-machine verification and computational challenge mechanism, and is not an absolute anti-robot system. It is recommended to cooperate with:
- Discuz form checksum formhash
- IP/account frequency limits
- Registration and posting review policies
- Set PBKDF2 difficulty reasonably
- HTTPS and security key configuration
This allows for improved overall anti-brushing capabilities while maintaining privacy, speed, and cost advantages.
V1.1.1
- Fixed an issue where the system's native "Security Verification + Input Box + Replace" verification code was still displayed even though this verification component was enabled on the recharge card password page.
V1.1
Fix a style error

If this plugin is still not enabled in the forum after setting it up, please check the forum backend - Security - Verify if this plugin is enabled.
