Protecting against gmail dot trick in Discourse

Great thanks @sam and sorry I didn’t follow up on this yet.

Yes it still seems quite viable to make a lot of accounts using this trick (2.5.0.beta1).

For example, using the username+{randomstring}@gmail.com trick, someone created 748 accounts in the last 10hrs. They already have thousands of accounts on this single gmail address.

Pretty much the only way for me to be able to remove them from the admin area is manually going to each account individually to suspend and/or delete them. It’s not very viable because the guy can pretty much just press a button and make a lot more accounts. :drevil:

They pretty much seem to have an unlimited supply of IPs, so IP bans/limits are pretty much futile in this case.

Also, still consistently getting quite a lot of registrations using the gmail dot and + tricks.

Cheers!

3 Likes