- cross-posted to:
- lemmy_admin@lemmy.ml
cross-posted from: https://lemmy.cat/post/6385
It is currently possible, through Lemmy’s API, to create accounts automatically and without limit if verification by email address or captcha is not activated. I’d advise you to activate one or both of them NOW!
After registering x number of accounts (currently I could do thousands), all you have to do is list all the existing communities for each of the account to publishes one new post per community, or more. I’ll leave you to picture the mess.
(I apologise to the administrators of sh.itjust.works, I should have done the test with my own server.)
- Pekka ( @Pekka@feddit.nl ) 4•1 year ago
I was playing a bit with the API today and yea it might even be a bit too easy at the moment. You can easily use that army of Lemmy bots to upvote all your posts.
We should probably make it very clear in tutorials and setup guides that no email verification and no captcha is very insecure.
- 𝖒𝖆𝖋 ( @maf@szmer.info ) 2•1 year ago
+1 to that. Also the email domain matters. It’s relatively easy to set up hundreds of disposable emails on random domains vs ones like Gmail.
Phone number is another solid anti abuse signal. SIM cards are harder to come by in large quantities.
- PenguinLover ( @PenguinLover@lemmy.ml ) 2•1 year ago
This is indeed not an ideal situation, but I guess on most instances this isn’t possible. I agree instances should require a captcha of some sort for signing up.
- Zeerooth ( @zeerooth@lemmy.antemeridiem.xyz ) 6•1 year ago
Unfortunately lemmy devs removed captchas recently https://github.com/LemmyNet/lemmy/issues/2922 so email verification and/or rate limiting is probably the only real option for protection.
- EthicalAI ( @EthicalAI@beehaw.org ) 2•1 year ago
That’s a major bad call. Companies like Google who maintain Captcha know the state of AI and will update captcha continuously to adapt.
- Pekka ( @Pekka@feddit.nl ) 1•1 year ago
With tools like this (https://nopecha.com/) existing they might be right. This is not even the only tool, it really looks like captchas are no longer useful because of AI.
- pitninja ( @stu@lemmy.pit.ninja ) 1•1 year ago
I saw some small instance owners saying they were going to enable open registration and I couldn’t help thinking how bad an idea that sounded all around… For exactly a situation such as this inevitably emerging.
- ShortN0te ( @ShortN0te@lemmy.ml ) 0•1 year ago
Not sure how email verification should help. Just add a couple of line to role a email address and then open the verification link.
If you don’t have your own domain, it’s hard to generate mass email addresses, at least with large providers.
So if someone uses his custom domain to mass-generate emails, it’s easier to delete all accounts that use this same email provider.
- ShortN0te ( @ShortN0te@lemmy.ml ) 0•1 year ago
https://duckduckgo.com/?q=10+min+mail+api&t=fpas&ia=web
There are enough options out there. No need selfhost.