there goes the neighbourhood (launchpad is getting owned by spammers)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Launchpad itself |
Fix Released
|
Critical
|
Unassigned |
Bug Description
Spammers are now (?) registering as users on launchpad, filling
homepage_content with spam and then sending it out spam mails linking
to their Launchpad user page, e.g.
<https:/
We're already getting complaints about this to abuse@ type addresses
and it's safe to assume that as a result launchpad.net URLs are going
to start adversely affecting the spam "score" of otherwise legitimate
emails.
A simple check of the person table showed nearly 600 users with
'prescription' in their homepage_content entry and (from a quick
glance) none of them looked legitimate.
IMO, we need to urgently:
a) make the controls on signing up for Launchpad stronger; e.g. by
using recaptcha rather than the incredibly weak mathcaptcha we
have right now.
b) clean out all the existing bogus accounts to reduce the damage
done to launchpad.net's "reputation" (in terms of spam and search)
Related branches
- Данило Шеган (community): Abstain (release-critical)
- Henning Eggers (community): Approve
-
Diff: 358 lines (+183/-15)9 files modifiedlib/lp/registry/browser/person.py (+42/-3)
lib/lp/registry/browser/tests/karmaaction-views.txt (+1/-1)
lib/lp/registry/browser/tests/person-views.txt (+121/-4)
lib/lp/registry/browser/tests/poll-views.txt (+1/-1)
lib/lp/registry/stories/person/xx-admin-person-review.txt (+4/-0)
lib/lp/registry/stories/person/xx-login.txt (+2/-0)
lib/lp/registry/stories/person/xx-reg-with-existing-email.txt (+5/-0)
lib/lp/registry/templates/person-index.pt (+3/-3)
lib/lp/testing/views.py (+4/-3)
Changed in launchpad: | |
assignee: | nobody → Curtis Hovey (sinzui) |
status: | New → In Progress |
importance: | Undecided → Critical |
Changed in launchpad-registry: | |
milestone: | none → 3.1.12 |
tags: | added: current-rollout-blocker |
Changed in launchpad-registry: | |
milestone: | 3.1.12 → 3.1.13 |
Changed in launchpad-registry: | |
status: | Fix Committed → Fix Released |
Changed in launchpad: | |
assignee: | Curtis Hovey (sinzui) → nobody |
Complete agreement from me. I filed bug 493960 a few days ago.