5 ms·
It's a good point that some spam "bots" could be human. I was running a free email site when we saw a lot of strange account creation. We had recaptcha enabled
by talison 17y ago
It's a good point that some spam "bots" could be human. I was running a free email site when we saw a lot of strange account creation. We had recaptcha enabled and knew it hand't been cracked.
It turned out (based on IP address analysis) that the accounts were being created by humans in the Philippines and then handed over to spammers in Dubai. Ah globalization...
If you have an efficient spam vector, it's not unusual to see low-wage humans manipulating the system to get around captcha.
- jasonkester 17y agoThis is a lot bigger than you'd expect. Nearly all the spam that makes it into the database on my sites is human-powered. It's maybe only 1% of the total attack volume, but because simple checks knock out nearly all the noise, it becomes the most significant fraction that you have to deal with.
- ErrantX 17y agolimit it to 1 account creation per IP per hour :) Yeh they can use a ton of proxies to get round that but I bet it cuts the account creation right down. And it shouldnt affect 99.999999% of "real" users.
- jasonkester 17y agoAh, but there's the rub. Extrapolating from my comment above, your number one job is to make spammers feel successful when they fail. If you reject new accounts like this, you'll force them to write those little proxies to get around your system. The better thing to do is to simply notice what they're doing and flip the IsSpammer bit on all those new accounts (including the first one.) That way you can correctly classify any content they may post from those accounts in the future.
- ErrantX 17y agoThere's the age old argument of which system to go for: Passive (my suggestion) or Active (yours). Probably both have merits but I am inclined to agree yours is the better way :D