logoalt Hacker News

colesantiagotoday at 5:32 AM2 repliesview on HN

And your solution is assume everyone on the internet is a good actor?

How would you solve this at scale?


Replies

RobotToastertoday at 6:54 AM

Op basically said that the firewall rules and email confirmation alone would've mostly mitigated this.

But also Anubis is a good alternative to slow bots.

cuu508today at 5:42 AM

How about a signup flow where the user sends the first email? They send an email to [email protected] (or to a generated unique address), and receive a one-time sign-in link in the reply. The service would have to be careful not to process spoofed emails though.

Another approach is to not ask for an email address at all, like here on HN.

show 4 replies