Captcha check for registration needs improving.

Bug #493960 reported by Henning Eggers
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Launchpad itself
Invalid
High
Unassigned

Bug Description

We are dealing with increased creation of spam accounts lately. The simple "A + B" captcha is obviously not strong enough to keep them out.

See some examples:
https://answers.edge.launchpad.net/launchpad/+question/93140
https://answers.edge.launchpad.net/launchpad/+question/93104

Revision history for this message
Henning Eggers (henninge) wrote :

I was so bold to set this to high. Would be great if we could find a replacement captcha quickly. After all, the infrastructure is there, isn't it?

description: updated
Revision history for this message
Francis J. Lacoste (flacoste) wrote :

Well, no captcha is going to prevent manual registration by spammer.

Do we have any evidence that these accounts were not created manually?

Changed in launchpad-foundations:
status: Triaged → Incomplete
Revision history for this message
Francis J. Lacoste (flacoste) wrote :

And no, there is no infrastructure in place here that would make easier the integration of a third-party visual captcha.

Revision history for this message
Henning Eggers (henninge) wrote :

The "infrastructure" I referred was the fact, that we already use a captcha. So we have the process of "Display captcha", "Compare captcha" and "Repeat with new captcha if failed". Sure, I did not expect a drop-in replacement.

At least it is (was) pretty obvious that they were created by the same person as they all looked the same with varying URLs and Account names. Spam is only effective en masse, so I don't see anybody going through the manual trouble, especially when our captcha is so easy to circumvent.

But maybe that is just my impression.

Revision history for this message
Francis J. Lacoste (flacoste) wrote :

Well, either they filled it by hand, or they wrote a script targetting us. Not sure it's worth investing time in either cases.

Revision history for this message
Curtis Hovey (sinzui) wrote :

Launchpad now uses Ubuntu's SSO.

Changed in launchpad-foundations:
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.