this post was submitted on 19 Jun 2023
44 points (94.0% liked)

sh.itjust.works Main Community

7649 readers
13 users here now

Home of the sh.itjust.works instance.

Matrix

founded 1 year ago
MODERATORS
 

Sorry, idk how to cross post yet but I saw this? There's an exploit allowing mass registrations.

top 16 comments
sorted by: hot top controversial new old
[–] TheDude@sh.itjust.works 29 points 1 year ago* (last edited 1 year ago) (2 children)

Captchas have been enabled on this instance.

[–] can@sh.itjust.works 9 points 1 year ago (1 children)

Good to know, thank you. I wanted to tag you but wasn't sure if that was possible. Was the change made in relation to this or had you already previouslly decided to implement one?

[–] TheDude@sh.itjust.works 13 points 1 year ago (1 children)

Something I probably missed when I first spun up this instance to be honest. Should have been enabled from day 1.

[–] can@sh.itjust.works 5 points 1 year ago* (last edited 1 year ago)

Ehh, first few days I can see the benefit of having the lowest barrier to entry as possible. No one knew there was an API exploit then.

[–] snakesnakewhale@sh.itjust.works 2 points 1 year ago (1 children)

Sweet, this comment should be pinned

[–] truckkun@lemm.ee 3 points 1 year ago

comments cannot be pinned 😌

[–] Bobo_Palermo@kbin.social 7 points 1 year ago

Captcha. I don't like the idea of email verification...they provide little safeguard.

[–] carrot@sh.itjust.works 5 points 1 year ago (1 children)

Definitely captcha. Email anonymity is nice, and I don't want to sign up with my email to everything.

If there is going to be a captcha tho, use hCaptcha or one of the cloudflare ones. Google captcha is just free labor for developing AI and I don't think anyone wants to keep contributing to that.

[–] can@sh.itjust.works 2 points 1 year ago* (last edited 1 year ago)

Yeah, seeing as they've removed the current captcha form lemmy (?) they'll have to find something.

[–] death916@lemmy.death916.xyz 3 points 1 year ago (1 children)

Man they got me with this. Had 20 bot signups B4 I realized and added captcha anyone now how to ban users without them posting something.

[–] admin@thegarden.land 2 points 1 year ago

I’d like an answer for that too

[–] Zaphodquixote@sh.itjust.works -3 points 1 year ago (2 children)
[–] can@sh.itjust.works 3 points 1 year ago* (last edited 1 year ago) (1 children)

lol

edit: I don't think most people saw that I caught you in my screenshot

[–] truckkun@lemm.ee 2 points 1 year ago

then again if i captcha you, you would have to drink a beer and dance around an island called Mariana on the third night of every month.

In fact, I think I know this, but the feeling I get from the air is that you'd be better off following a trail of serendipitous stones. That path will surely find a friend for you in these dark times, to lead you through the island's waters and find some beers for you to surpass the captcha.

Yes.

load more comments
view more: next ›