5 ms·
Looks like you can use OATH TOTP, which can be easily automated. I don't understand how this is an effective countermeasure against bots.
by NowhereMan 5y ago
Looks like you can use OATH TOTP, which can be easily automated. I don't understand how this is an effective countermeasure against bots.
- samwillis 5y agoThis ads friction to the process of automating the buying process. Preventing bots is an endless cat and mouse game, every protection you put in place will be circumvented eventually. You just have to keep changing tactics and adding new layers. That’s what they are doing here. Realistically the best protection that they could put in place is a rate/qty limit on the credit card being used. It can still be automated by using stolen cards, or one of the services that instantly creates new card numbers for you. But again it adds friction. Also limiting the number of orders to delivery addresses would be a easy mitigation. It wouldn’t surprise me if they are doing both of those already though.
- wyager 5y agoThis seems like an especially trivial-to-bypass mitigation.
- samwillis 5y agoIt may be “trivial” to someone with a high level of expertise. But the number of moving parts required in that automation does add a significant barrier to most the of “script kiddies” that are using bots. You still need to automate account creation and setting up of a TOTP token, that’s not “easy” for a lot of people.
- spookthesunset 5y agoLike the poster said, it’s whack-a-mole. These trivial mitigations at least filter out low-effort script kiddies. People gaming the system “for real” will put incredible effort into getting around your countermeasures. You always have to be one step ahead of them.
- azinman2 5y agoWhat would you suggest?
- nomel 5y agoLow device limit per phone number/payment card, with the standard checks for VOIP would probably make things painful enough for most. Heck, outsource the bot checking and require a Facebook/Gmail/Apple/Twitter/whatever login. Intrusive as heck, but it works relatively well since those companies have already whacked a million moles.
- yjftsjthsd-h 5y agoLimits per shipping address?
- kube-system 5y agoMaybe, but it's also just a good idea to do anyway, so might as well.
- p1necone 5y agoYou'd be surprised at how big of an effect "trivial" mitigations like this have when you're defending against what amounts to a sea of script kiddies. With a problem like this eliminating 80% of attackers gives you 80% of the benefit, it's not an all or nothing thing.
- deleted 5y ago[deleted]
- colechristensen 5y agoA lot of bots are written by really unsophisticated people though, often just following online guides. Raising the bar lowers the number of adversaries. You can never eliminate the risk, but it's just one more point of friction which is also a not-so-unreasonable speed bump to enable for real users.
- b112 5y agoMaybe, but, no one gets my mobile number, not my bank, no one. It's not in my name, I pay cash for it, I share my contacts with no one, etc. I won't have it linked to me, and with how you can so readily be location tracked when someone knows your number, I am astonished so many people give it out. So there goes the easiest 2fa....
- colechristensen 5y agoOther people share your contact though, unless you exclusively associate with people equally paranoid. You simply can’t have an anonymous phone number these days unless you actively switch numbers all the time which if you get accused of something will be used as evidence against you.
- b112 5y agoI have a voip number forwarded for incoming. I have no caller id for outgoing. Thus, even with google having my name linked to a number, it does not link to my cell phone. Reply to comment below: No one gets my real mobile number, so that is solved. Why would I care if my VOIP number is in address books. That's the point of it, and why I have it I'm not trying to hide from the government, I am preventing Google, FB, etc from linking my mobile to me, and preventing random people from tracking my location, which is trivial when they know your mobile number.
- giantrobot 5y agoIt only takes one contact to have your real number in your name, or even better also associated with your VoIP number in their address book, to lose your "anonymity".
- udia 5y agoI agree, 2FA seems unrelated to stopping bots. It really seems like some form of rate limiting and captcha should have been used instead.
- cft 5y agohttps://2captcha.com/ https://2captcha.com/
- kube-system 5y agoI love the "workers banned" stat. It's bots all the way down.
- gaius_baltar 5y ago> $0.50 for 1-2 hours, depending on service load. Where in the world do they plan to hire people for these rates? In India, the country with lowest the Big Mac Index as in [1], it would take 6.48h for the human-bot to pay for a Big Mac. And this excludes energy and internet bills and money transfer fees. The numbers just don't work. [1] https://en.wikipedia.org/wiki/Big_Mac_Index#Figures https://en.wikipedia.org/wiki/Big_Mac_Index#Figures
- bluGill 5y agoThat isn't the labor rate, that is the solve rate most captha are easy to automate. You are buying the image recognition and their random click like a human algorithm. Probably even have some intentional wrong clicks like someone who misses... they have a few humans (who make more than that rate) but only for the new ones that they haven't seen before, once they know that one it is automated. I post the above in hopes that you realize captca isn't useful for anything and stop annoying me with them.
- TameAntelope 5y agoAnd yet they're effective, so I wonder what the disconnect is.
- londons_explore 5y agoPerhaps for buying a ras-pi specifically, they'll require SMS verification. SMS is hard to create large numbers of fake accounts because getting access to large numbers of phone numbers that aren't all in the same block is pretty hard.
- pauldd7 5y agoThere are several services that offer exactly this for 6-20 cents per verification, with a wide variety of numbers and geos, VOIP or Real ATT/Verizon Mobile etc, and easy to use API's.
- evan_ 5y agoYou're misreading, you have to "verify" your account first as well as set up MFA. Verifying just consists of confirming your email via a one-time token. Setting up MFA presumably just makes sure there's no impetus to hack a bunch of old accounts.