4 ms·
Very nice list of countermeasures. I agree that doing these small things like hidden input fields really go a long way. I would add to that: - block signups/c
by sparkling 4y ago
Very nice list of countermeasures. I agree that doing these small things like hidden input fields really go a long way.
I would add to that:
- block signups/comments from known throwaway email domains
- block known datacenter IP ranges, at least for POST requests. Honestly on our sites 50% of spam was coming from AWS EC2 IPs
- use a proxy/vpn/bot detection service like https://focsec.com https://focsec.com
- emptyparadise 4y agoBut then you end up forcing people to use Gmail.
- EdwardDiego 4y agoYup, in adtech, "IP is an AWS block" was a bot 99.999% of the time. The 0.001% was that person using EC2 as a proxy or VPN server.
- mobilio 4y agoIt's not only AWS. Also happens on Azure and GCP.
- EdwardDiego 4y agoTrue, but at the time, 3 - 4 years ago, Azure and GCP IPs were minimal. Guess the fraudsters were vendor locked lol.
- Zak 4y agoPlease don't make blocking VPNs plan A. Between snooping ISPs and public wifi networks that have indiscriminate content filters, I'm on a VPN about half the time. Many other legitimate users are as well.
- account42 4y ago> block signups/comments from known throwaway email domains Throwaway email services have caught up to the point where even bigger players don't manage to block them, i.e. they rotate the domains used for the emails.