Message Boards

Liferay.com should require email validation...

thumbnail
David H Nebinger, modified 11 Years ago.

Liferay.com should require email validation...

Liferay Legend Posts: 14915 Join Date: 9/2/06 Recent Posts
So the recent forum spam attacks highlight the difficulty of blocking spam attacks.

The solution, to me, seems to be pretty simple. If liferay.com required email validation before allowing posting to the community areas (the forum, the wiki, etc.), I think that would go a long way towards blocking some of the simple spambots out there.

Without email validation, it is just too easy to create a new account and start posting to the community areas, so easy even a bot could do it.

It is well known that captchas are easy to bypass using current AI and image processing tools, so that's not a good way to validate a new account is for a user versus a bot...
thumbnail
James Falkner, modified 11 Years ago.

RE: Liferay.com should require email validation...

Liferay Legend Posts: 1399 Join Date: 9/17/10 Recent Posts
David H Nebinger:
So the recent forum spam attacks highlight the difficulty of blocking spam attacks.

The solution, to me, seems to be pretty simple. If liferay.com required email validation before allowing posting to the community areas (the forum, the wiki, etc.), I think that would go a long way towards blocking some of the simple spambots out there.

Without email validation, it is just too easy to create a new account and start posting to the community areas, so easy even a bot could do it.

It is well known that captchas are easy to bypass using current AI and image processing tools, so that's not a good way to validate a new account is for a user versus a bot...


It has been considered in the past, but the spam level was almost non-existent then, and the feeling was we wanted to minimize the on-ramp to the community. But it may be time to revisit this... also we are considering a for-pay spam prevention thingy. We'll get it sorted soon though! I am sick of cleaning these up emoticon
thumbnail
Hitoshi Ozawa, modified 11 Years ago.

RE: Liferay.com should require email validation...

Liferay Legend Posts: 7942 Join Date: 3/24/10 Recent Posts
Make it pretty quick because it seems we got some more again.
thumbnail
David H Nebinger, modified 11 Years ago.

RE: Liferay.com should require email validation...

Liferay Legend Posts: 14915 Join Date: 9/2/06 Recent Posts
James Falkner:
David H Nebinger:
So the recent forum spam attacks highlight the difficulty of blocking spam attacks.

The solution, to me, seems to be pretty simple. If liferay.com required email validation before allowing posting to the community areas (the forum, the wiki, etc.), I think that would go a long way towards blocking some of the simple spambots out there.

Without email validation, it is just too easy to create a new account and start posting to the community areas, so easy even a bot could do it.

It is well known that captchas are easy to bypass using current AI and image processing tools, so that's not a good way to validate a new account is for a user versus a bot...


It has been considered in the past, but the spam level was almost non-existent then, and the feeling was we wanted to minimize the on-ramp to the community. But it may be time to revisit this... also we are considering a for-pay spam prevention thingy. We'll get it sorted soon though! I am sick of cleaning these up emoticon


Whatever the solution is, I hope it gets integrated into the core so those of us running Liferay as an internet site can leverage the same solution...
thumbnail
Amos Fong, modified 11 Years ago.

RE: Liferay.com should require email validation...

Liferay Legend Posts: 2047 Join Date: 10/7/08 Recent Posts
I don't think email verification would help much. We use the same captcha as google so the spammers probably have a ton of valid email addresses they could use.
thumbnail
David H Nebinger, modified 11 Years ago.

RE: Liferay.com should require email verification...

Liferay Legend Posts: 14915 Join Date: 9/2/06 Recent Posts
Email verification (word I should have used instead of validation) is more than just using a valid email address. It's following an embedded link in an email issued from liferay.com back to liferay.com thus verifying that the email address provided is not only live and valid, but also that a user is there to deal with the response.

They could use any of their millions of valid addresses, but unless they also had access to the inbox to receive the message, parse out the URL and use it to surf back to liferay.com, those millions of valid email addresses would not be worth much as they couldn't be verified...
thumbnail
Amos Fong, modified 11 Years ago.

RE: Liferay.com should require email validation...

Liferay Legend Posts: 2047 Join Date: 10/7/08 Recent Posts
You may be right. But I figure if they can automate creating accounts and posting spam, they could automate email verification too. At least for this guy it didn't seem to help https://drupal.org/node/877404.

In our case it may help though. I guess it depends on how advanced our spammer is.