Page 1 of 1
Registrations temporarily disabled [fixed]
Posted: Wed Aug 27, 2025 2:25 pm
by Red Squirrel
We are being attacked by bots mass registering accounts, this is generating an influx in mail traffic which is starting to get us blacklisted. Disabling registrations until I can figure out a way to block these.
Re: Registrations temporarily disabled
Posted: Sun Sep 07, 2025 6:41 am
by drmrlordx
Are new account registrations still disabled? Bot swarms suck.
Re: Registrations temporarily disabled
Posted: Wed Sep 10, 2025 12:39 am
by Red Squirrel
Yeah it's still disabled for now. I need to completely redesign the registration process to have better validation steps before the email even goes out, so I can reduce mail traffic. Just been busy with other stuff, trying to race against time to finish lot of projects before winter comes.
I am looking at implementing a POW captcha that needs to be solved when submitting the initial form, something that is computational expensive that makes it harder for bots to mass register accounts.
I will also need to setup some sort of throttle on outgoing emails to ensure no event can cause a lot to go out at once to any given provider. I think these bots actually purposely do this so they can mess with IP reputation.
Worse case scenario I may look at geoblocking IP ranges, but I feel that's kinda futile as bots typically use proxies. I rarely see the same IP twice.
Re: Registrations temporarily disabled
Posted: Mon Oct 13, 2025 6:12 pm
by Red Squirrel
I got lazy/busy with other stuff so did not look at this yet but I did not forget about it.
I still have not sent a mass email to all original members yet, but need to sort out email server reputation before I do that...
Re: Registrations temporarily disabled [fixed]
Posted: Mon Oct 27, 2025 5:05 am
by Red Squirrel
I fixed this by changing the captcha order and enabled registrations again. I don't remember why I had the captcha AFTER the email validation, but it probably makes sense to have it BEFORE. So when registering an account it submits, but requires to do a captcha separately after, before it sends the validation email. I'm hoping this step reduces the email traffic.
The captcha can be defeated by bots though so I have a few other ideas in mind that I will implement, but going to monitor this as-is just to see how well it works.