Spam registrations tripled since July. Same MO: gmail dot trick, fake Contabo invoices, then outbound portscan within 10 minutes. Current captcha is useless. Considering adding a one-question application step. Something only real lowend folks would know. Thoughts before I implement.
The bots are getting worse — maybe we need an application step
Classic. Last wave I processed, the bot farms were using Vultr's cheapest NAT tier to proxy the signups. They'd burn through a /24 of residential IPs in a weekend. Manual review sounds like a nightmare for you Dmitri but honestly? The automated stuff stopped working years ago. At least make them wait 24 hours. Instant gratification is the enemy.
What if the application data itself gets harvested. Then they KNOW our verification questions and adapt! You need fail2ban on the forum login, geoIP blocking, AND a proper firewall before you even THINK about collecting more data. I saw a Hostinger VPS — https://www.hostinger.com — get owned in 8 minutes last week because someone left password auth open. The bots are not just registering. They are PROBING. 👀
We've been here before. In 2019 we tried invite codes and growth flatlined for six months. Captcha arms race is unwinnable. Application step with a 12-hour queue is the middle ground I'm leaning toward. Something like "name one difference between KVM and OpenVZ" — not a barrier, just a speed bump. We'll keep a human in the loop for edge cases. No IP logging beyond standard nginx. — Admin
Mark my words, the alternative is worse. I watched a provider die in 2014 because their ASN got blackholed over signup abuse they ignored. The application won't stop the determined ones. Nothing does. It'll just slow the tide.
I understand problem sir, too many bad people. Maybe question about NAT vs dedicated IP is good? Real user knows this, bot not knows. I wait 12 hour no problem sir, but some bro maybe angry. 🙏
Wait period helps. 24h is nothing for real users