5 ms·
Yep noticed this a long time ago and am very suspicious
by secfirstmd 5y ago
Yep noticed this a long time ago and am very suspicious
- jimmaswell 5y agoA visitor from TOR is extraordinarily more likely to be abusive. It makes total sense to put up extra barriers, which is still short of blocking TOR users altogether, which is also fair for webmasters who don't want to deal with it.
- vmception 5y agoI’ve always found it weird how people jump hoops to be apologists for Protonmail Does anybody else find that weird? “I completely misunderstood Swiss privacy laws and fell for a sales pitch from an email and VPN company that goes out of its way to track every user no matter how they sign up! Its to avoid email abuse, exclusively!”
- jimmaswell 5y agoI've never even heard of Protonmail. I just think it's silly to fault anyone for blocking/limiting TOR connections.
- cookiengineer 5y ago> A visitor from TOR is extraordinarily more likely to be abusive. It makes total sense to put up extra barriers, which is still short of blocking TOR users altogether, which is also fair for webmasters who don't want to deal with it. And why is that again? I want to understand that argument. In case of DDoS scenario: Well, too late, traffic already served and server already done the workload. In case of password brute forcing: Well, then implement a latency, or cryptographical challenge to delay it more efficiently. In case of "evil" human: Well, if a human can get past your security so easily, then your approach to security through obfuscation might be wrong. So, again, what is the scenario where a captcha helps you to avoid being "attacked" by malicious actors?
- darkhorse22 5y agoThe mindset is basically: Programming is hard so we're going to block as many non-paying customers as possible to limit the blast radius when we inevitably fuck up. And inconvenience those paying users too, because we can't figure out how to mitigate DoS attacks at the edge. And then we'll give a talk at a Next.js conference or something.
- mannerheim 5y agoWhat about the case of someone signing up for thousands of accounts?
- cookiengineer 5y ago> What about the case of someone signing up for thousands of accounts? My question is related to the specific /login page, not the registration page. I understand the benefit for blocking spammer signups, but not for the current case of the login page where users have an account already, were verified that the account/password was correct (captcha appears in second step), and then have to enter a second decryption password manually. In that scenario there's no argument on the "WHY" a captcha helps. It simply doesn't.
- drivebycomment 5y agoIt increases the cost of credential stuffing attack, which is very common nowadays.
- ipaddr 5y agoWhy would that be a problem on surface? You have thousands of users, why do they need to be unique identities? The only reason I can think of is because they want more unique identities. More unique people means a greater chance for a purchase. More mail accounts just cost more. The entire business model of free accounts requires someone paying for something extra. By unique identifying people they can limit new accounts and increase their chances of an upsale. What if they changed how they operated. Instead of looking for more unique identities why not accept multiple addresses and include an ad at the end of every free email letting the receiver know this came from protonmail. That would give a benefit for each email sent and provide more advertising and give users a reason to upsell? My guess is having that ad after every mail would bother you (the customer) more than having your identity uncovered.