Earlier quoted context omitted.
I don't think you understand why that captcha is there in the first place then. Cloudflare prevents a bunch of crap that site operators just don't want to deal with. Especially for smaller sites that are run by one person. Dealing with a wordpress site getting hacked because you missed an update by a day, or a bulletin bored getting swarmed with bots, or some asshat ddos'ing your site because you banned them. Suddenl…
Yeah, so centralizing the entire internet around a black box that sees all your traffic in cleartext is clearly the right solution. /s > Dealing with a wordpress site getting hacked because you missed an update by a day Maybe don't use something this vulnerable then and rely on a third party to protect you from exploits. > or a bulletin bored getting swarmed with bots Maybe require email verification and/or a captcha…
You're definitely overestimating the technical expertise/available time of a lot small time admins out there.
You don't see bots and spam on those forums either because they are actually using cloudflare, and you're just not seeing the captcha, or because in the backend they're feeding all their posts through akismet (in plain text). I don't think you're considering how many services see your posts, even when you don't trip a captcha.
email accounts are trivial to sign up for, especially for bots. I always recommend charging $1 (or local equivalent) for an account, that's a lot harder to fake.
My point in all this is that bitching that site is using cloudflare to not have to deal with crap, is a self centered view.
Saying "well it never happened to me, so it must never happen" is similarly self absorbed.
Maybe consider that your experience is not everyones experience