PDA

View Full Version : Preventing automated registrations: Last idea.


Davey
03-17-2003, 12:39 PM
This is "the" last idea I could think of.
It's simply a case of switching a few current things around.
Here it goes:
Idea
Use email authorization as step 1 instead of after filling out the form.
When the link is activated from the email, the user can then continue registration process.
This way, the user can start posting immediately without the frustration of waiting for an email.
How does it sound?
And now, will it go okay? Can it be carried out?

Dave.

PS: Notes:
Perhaps allow for 3 days waiting for activation rather than 1 (to allow for slow email accounts).
Do not mark the user as registered in any way until email confirmation (so that the boards cannot be flooded excessively, and I'm not saying the sending emails cannot be flooded, but this would be only minor next to 1000 queries being made immediately, look at the difference).
Remember stuff like email bans, IP bans, etc., so that this cannot be bypassed before the user knows (i.e.: after confirming).
That is all.

filburt1
03-17-2003, 12:52 PM
What's the difference between sending the e-mail before registration and sending it after? It will still take the same amount of time.

Davey
03-17-2003, 12:58 PM
It's not time though, is it.
The hacker flooding with bots is not interested in time, he's interested in flooding your server.
So you're authorizing before the board knows the user is there, then once activated correctly, all will be added.
Okay then maybe it's not quicker for the user, but it should save your server heaps of bother.
And hey, isn't it better than the current methods/not?

Dave.

filburt1
03-17-2003, 02:09 PM
I guess I don't get what you're saying then...:confused:

Erwin
03-17-2003, 08:56 PM
How can a person post immediately without waiting for the registration email? I don't understand.

Abbas
03-17-2003, 10:26 PM
Why is this still being discussed? The latest version of vB (2.3.0) comes with image verification anyway. Perhaps not everyone can support it.... but most servers should.

filburt1
03-17-2003, 10:33 PM
I don't know about you but in the US we have the first amendment to the constitution.

Okay, lame comparison, but bots always find a way.

Davey
03-18-2003, 02:11 PM
Simple terms: How can a bot authorize an email?
Not possible.
You are placing authorization BEFORE signing up in order to secure your forum being flooded with new registrations.
Users can post straight away (unless you change the permissions to make them very tight).
But the main thing about this hack is authorizing before signing up.
If the user's email is not legitimate, they cannot verify can they?
Therefore they aren't actually added to the database and displayed on the homepage until they have proven themselves.
Get it now?

Dave.

PS:
@Abbas: You said it straight away.
Not everyone can support image verification.
And I cannot, since I am running it on Windows.
But the bottom line is, this has to be a method EVERYONE can use. Otherwise it's not fair.