Combination View Flat View Tree View
Threads [ Previous | Next ]
toggle
David H Nebinger
Liferay.com should require email validation...
September 5, 2012 1:23 PM
Answer

David H Nebinger

Community Moderator

Rank: Liferay Legend

Posts: 11295

Join Date: September 1, 2006

Recent Posts

So the recent forum spam attacks highlight the difficulty of blocking spam attacks.

The solution, to me, seems to be pretty simple. If liferay.com required email validation before allowing posting to the community areas (the forum, the wiki, etc.), I think that would go a long way towards blocking some of the simple spambots out there.

Without email validation, it is just too easy to create a new account and start posting to the community areas, so easy even a bot could do it.

It is well known that captchas are easy to bypass using current AI and image processing tools, so that's not a good way to validate a new account is for a user versus a bot...
James Falkner
RE: Liferay.com should require email validation...
September 5, 2012 1:43 PM
Answer

James Falkner

Community Moderator

Rank: Liferay Legend

Posts: 1406

Join Date: September 17, 2010

Recent Posts

David H Nebinger:
So the recent forum spam attacks highlight the difficulty of blocking spam attacks.

The solution, to me, seems to be pretty simple. If liferay.com required email validation before allowing posting to the community areas (the forum, the wiki, etc.), I think that would go a long way towards blocking some of the simple spambots out there.

Without email validation, it is just too easy to create a new account and start posting to the community areas, so easy even a bot could do it.

It is well known that captchas are easy to bypass using current AI and image processing tools, so that's not a good way to validate a new account is for a user versus a bot...


It has been considered in the past, but the spam level was almost non-existent then, and the feeling was we wanted to minimize the on-ramp to the community. But it may be time to revisit this... also we are considering a for-pay spam prevention thingy. We'll get it sorted soon though! I am sick of cleaning these up emoticon
Hitoshi Ozawa
RE: Liferay.com should require email validation...
September 5, 2012 2:30 PM
Answer

Hitoshi Ozawa

Rank: Liferay Legend

Posts: 7949

Join Date: March 23, 2010

Recent Posts

Make it pretty quick because it seems we got some more again.
David H Nebinger
RE: Liferay.com should require email validation...
September 5, 2012 2:34 PM
Answer

David H Nebinger

Community Moderator

Rank: Liferay Legend

Posts: 11295

Join Date: September 1, 2006

Recent Posts

James Falkner:
David H Nebinger:
So the recent forum spam attacks highlight the difficulty of blocking spam attacks.

The solution, to me, seems to be pretty simple. If liferay.com required email validation before allowing posting to the community areas (the forum, the wiki, etc.), I think that would go a long way towards blocking some of the simple spambots out there.

Without email validation, it is just too easy to create a new account and start posting to the community areas, so easy even a bot could do it.

It is well known that captchas are easy to bypass using current AI and image processing tools, so that's not a good way to validate a new account is for a user versus a bot...


It has been considered in the past, but the spam level was almost non-existent then, and the feeling was we wanted to minimize the on-ramp to the community. But it may be time to revisit this... also we are considering a for-pay spam prevention thingy. We'll get it sorted soon though! I am sick of cleaning these up emoticon


Whatever the solution is, I hope it gets integrated into the core so those of us running Liferay as an internet site can leverage the same solution...
Amos Fong
RE: Liferay.com should require email validation...
September 5, 2012 7:11 PM
Answer

Amos Fong

LIFERAY STAFF

Rank: Liferay Legend

Posts: 1898

Join Date: October 7, 2008

Recent Posts

I don't think email verification would help much. We use the same captcha as google so the spammers probably have a ton of valid email addresses they could use.
David H Nebinger
RE: Liferay.com should require email verification...
September 5, 2012 8:46 PM
Answer

David H Nebinger

Community Moderator

Rank: Liferay Legend

Posts: 11295

Join Date: September 1, 2006

Recent Posts

Email verification (word I should have used instead of validation) is more than just using a valid email address. It's following an embedded link in an email issued from liferay.com back to liferay.com thus verifying that the email address provided is not only live and valid, but also that a user is there to deal with the response.

They could use any of their millions of valid addresses, but unless they also had access to the inbox to receive the message, parse out the URL and use it to surf back to liferay.com, those millions of valid email addresses would not be worth much as they couldn't be verified...
Amos Fong
RE: Liferay.com should require email validation...
September 5, 2012 10:43 PM
Answer

Amos Fong

LIFERAY STAFF

Rank: Liferay Legend

Posts: 1898

Join Date: October 7, 2008

Recent Posts

You may be right. But I figure if they can automate creating accounts and posting spam, they could automate email verification too. At least for this guy it didn't seem to help https://drupal.org/node/877404.

In our case it may help though. I guess it depends on how advanced our spammer is.