PDA

View Full Version : Human verification



nrc
07-29-19, 12:50 AM
I've been battling a wave of SPAM forum registrations lately and I'm all up in the Control Panel like...


https://www.youtube.com/watch?v=3xYXUeSmb-Y

I almost posted this in the AAPL vs. GOOG vs. MSFT thread since it goes into another Google rant. You've been warned.

Normally SPAM registrations aren't a big deal because I check what few registrations we get before activating them. It's just a pain when they become a flood.

I had switched away from reCaptcha for human verification a few years back because spammers pretty much had it beat. Stupid little questions were more effective. My stupid little questions were useless against this latest onslaught so I assume the answers got recorded in a database somewhere.

So my first thought was to try reCaptcha again. Of course Google runs reCaptcha so there was that to consider. But they created version 2 and their stupid little "find the stoplight" "find the crosswalk" puzzles are everywhere on the web for human verification so it must be effective, right?

Nope. Their own dashboard shows they were successful in identifying spammers less than 50% of the time. I know this because every one of the registrations in that time was spam. Then it occurred to me. Of course they're not successful in stopping spammers. Half the spam registrations we get are from Gmail addresses!

But wait! Google now has reCaptcha v3. Evidently this now grades a user on how likely they are to be a spammer by their activity on your site. And to gather that information they want you to bury these reCaptcha 3 widgets all over your site so they can measure. Google already has more instrumentation buried throughout the web than anyone else through their ad networks. Now they're extending more tentacles through their Human verification network. Do think it will cut down on the number of spam registrations from Gmail? Wouldn't we have seen that already if they're using it there?

So I took a different tack. I've added a plugin to the forum that now requires that the user verify their email before they're permitted to register. This should cut down on the number of bogus registrations that are created and never verified (75%). Hopefully the fact that they have to enter a code from the email to proceed with registration will limit it further. After that there's just one very simple, site specific question. We'll see how that goes.

As I read the plugin information, it sounds like this may also impact email changes by existing users. So if you need to change your email, you'll probably go through a similar email validation process. As always if you encounter any problems please post, PM, or use the "Contact Us" link at the bottom.

SteveH
07-29-19, 09:09 AM
Thanks Richard, good luck.

WickerBill
07-29-19, 11:51 AM
https://i.imgflip.com/rxv4p.jpg

nrc
07-30-19, 06:24 PM
I suppose a hundred or so new accounts posting links in every forum would liven the place up a bit.

I'm kind of curious if these are the usual commercial spam bots or whether this is someone prepping bots for political or malware purposes. It seems like a change in behavior but it's probably just because my challenge questions were cracked.

chop456
07-30-19, 11:00 PM
it's probably just because my challenge questions were cracked.

If the answers frighten you, Richard, then you should cease asking scary questions.

WickerBill
07-31-19, 08:49 AM
You didn't feel like new challenge questions would hold them at bay for a while? Needed to go further?


Like "Pluralize the word 'cactus'" or "What is 14-7 when you add three?" or "WHOM DO YOU SERVE??"

nrc
08-09-19, 01:36 AM
We'll see. I had to back out of the mail validation first option because I was getting too much back scatter from bounced messages from that option.

One of the problems with VB verification questions is that when you set multiple you have no way of knowing what question was answered when someone registers. So you come up with several good questions and when the answer to one of them gets entered in the spammer's database registrations start coming in and you don't know which one is now known. So to stop the noise you have to change all the questions.

So I've started with a single very simple question specific to the site under the theory that however these questions get answered, it's not aware of the site that the question came from. We'll see how that goes.

devilmaster
08-09-19, 05:42 AM
So I've started with a single very simple question specific to the site under the theory that however these questions get answered, it's not aware of the site that the question came from. We'll see how that goes.

Is the answer Danica? :gomer:;)

nissan gtp
08-09-19, 10:29 AM
Glad I got in before the tests started.

EDwardo
08-09-19, 10:03 PM
Let's hope that these incursions aren't Russian troll farms attempting to sway opinions on Indycar.

nrc
08-09-19, 11:06 PM
Glad I got in before the tests started.

:laugh: For you good folks we'll grade on a curve. :thumbup:

nrc
08-09-19, 11:08 PM
Let's hope that these incursions aren't Russian troll farms attempting to sway opinions on Indycar.

Eksellent raski on Sunday, comrades! The People's racing facility was filled to capacity and television ratings are sure to be in line with our new five year plan. :tony: