Opened 14 months ago

Last modified 14 months ago

#18628 new bug

registration problems on https://dev.haiku-os.org/

Reported by: vicky Owned by: nielx
Priority: normal Milestone: Unscheduled
Component: Website/Trac Version: R1/beta4
Keywords: Cc:
Blocked By: Blocking:
Platform: All

Description

Hi, I'm just registered on dev.haiku-os.org , butI almost gave up:

  1. I try with username "vic", but it says:

"Warning: Username vic doesn't match local naming policy."

  • but it doesn't explain what is that policy.
  1. I change to "vic5" - it reports same warning
  1. after chaning to "vicky":

"Warning: Are you human? If so, try harder!"

  1. I change os name from haiku to Haiku, and it now says:

"StopForumSpam says this is spam (username [78.05])" and asks capcha (which I passed, and I'm here).

I bet some other users just gave up.

vic

Change History (3)

comment:1 by waddlesplash, 14 months ago

Component: - GeneralWebsite/Trac
Keywords: registration account removed
Owner: changed from nobody to nielx

We get a lot of spam attempts and the filters do catch most of them. Previous experiments with turning them down let a lot more spam through.

I don't think much is going to change here until if/when we integrate Trac into the SSO system, but who knows when that will be.

comment:2 by pulkomandy, 14 months ago

I think nielx is looking into an update to Trac 1.6, which first requires updating some plugins to Python 3.

The first message should at least be improved (apparently usernames need to be at least 5 letters long? is that it? I have no idea)

StopForumSpam trying to detect spam just on username is a bit strange too. Is that really an effective way to do it? Especially as some of the spammers do get through anyway.

And, as mentioned earlier, one reason we are a target for spam is that, despite quickly deleting the messages from Trac itself, the spam is still archived by freelists on the haiku-bugs mailing list, which serves the SEO purposes of the spammers. Until we do something about that, we are a target worth spending time on for the spammers, and they will put effort into circumventing spam protection measures.

comment:3 by vicky, 14 months ago

I should mention that around step 4, I tried simply resubmitting several times without chaning anythging -- just because I had no idea what to change! -- and after 3-4 times it showed the spam message.

Note: See TracTickets for help on using tickets.