cross-posted from: https://lemmy.cat/post/6385

It is currently possible, through Lemmy’s API, to create accounts automatically and without limit if verification by email address or captcha is not activated. I’d advise you to activate one or both of them NOW!

After registering x number of accounts (currently I could do thousands), all you have to do is list all the existing communities for each of the account to publishes one new post per community, or more. I’ll leave you to picture the mess.

(I apologise to the administrators of sh.itjust.works, I should have done the test with my own server.)

  • 𝖒𝖆𝖋@szmer.info
    link
    fedilink
    arrow-up
    4
    arrow-down
    4
    ·
    1 year ago

    +1 to that. Also the email domain matters. It’s relatively easy to set up hundreds of disposable emails on random domains vs ones like Gmail.

    Phone number is another solid anti abuse signal. SIM cards are harder to come by in large quantities.

    • T156@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      Phone number is another solid anti abuse signal. SIM cards are harder to come by in large quantities.

      Unless they use something like a VOIP, or just spoof the number. If they can do that to call other people, there’s little reason to think that they could not use that information for registration.

      The other thing to consider is that in the eventuality of a data breach, you’re going to have the phone numbers of a bunch of users floating about, which is not ideal either.

      • 𝖒𝖆𝖋@szmer.info
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Right. I meant is the SMS-based verification of phone numbers - it’s not spoofable like the VoIP Caller ID. The downside is the cost imposed by the SMS gateway.