Please. Captcha by default. Email domain filters. Auto-block federation from servers that don’t respect. By default. Urgent.

meme not so funny

And yes, to refute some comments, this publication is being upvoted by bots. A single computer was needed, not “thousands of dollars” spent.

  • ch1cken@kbin.social
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    Email domain filters

    please no, email filters are ridiculously easy to bypass.

    Lets say you go with a whitelist all, and blacklist malicious email domains approach: i.e, temp mail and the sort are blocked. This is badness enumeration, it does not work. What does an attacker do? host their own mail server and create infinite emails, or use a lesser known temp mail service, you cannot block them all.

    Lets suppose you go with a blacklist all, and whitelist popular email services approach. Wonderful, now a significant number of people cannot signup, you’ve successfully bottlenecked lemmy’s growth. This also does nothing, theres temp mail services which somehow give you a gmail address. An attacker would just use that.

    Use captchas, they serve a purpose, aren’t snake oil and (usually) don’t prevent genuine humans from signing up. But don’t go extreme on email restrictions.

    • chiisana@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      This right here.

      Op, if you’re not ready to moderate, don’t spin up your own server or do your own private instance. If you’re going to moderate, do it properly and don’t spew bad ideas while hiding behind a dumb “alert” throwaway.

      • T156@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        To be honest, I’m surprised that that username was allowed (or not reserved). It seems like it would introduce a risk where people could pose as Lemmy developers or something along those lines.

      • le__el@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        Actually, hello.1@gmail will go to hello1@gmail.

        The one you are thinking I believe is hello+1@gmail will go to hello@gmail

    • Shinhoshi@infosec.pub
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      2
      ·
      1 year ago

      BTW, it might be more inclusive language to use “allow list” and “block list”

      • TrueDahn@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        I can’t imagine being so obsessed with race politics as to think that purely technical terms like “white list” and “black list”, which have never had any connection to race relations whatsoever, are somehow non-inclusive.