• 0 Posts
  • 26 Comments
Joined 1 year ago
cake
Cake day: June 15th, 2023

help-circle














  • Fair, though this is also where the double-edge sword of discoverability steps in too. Many people complain about the lack of it on decentralized systems, but centralized systems have a nice catalog of users for bots to message with little effort.

    I’ll admit that lack of discoverability isn’t a perfect solution since there are other ways for spammers to discover users. E-mail is a great example of a large, long running, decentralized system that has increasingly suffered from spam since its inception due to mass data collection of addresses. However if you’re really careful about who you share your address with, it’s possible to still avoid most of it. I give out unique e-mail address to companies and spam tends to only come in on a few, often because they were breached or are otherwise “leaky” about their user’s data. Dropbox is by far the worst offender.


  • I’ve seen pictures of rooms with walls full of Android cell phones on shelves all hooked up by USB for power and remote control. They can load apps, register accounts, and interact with content inside the app while appearing as legitimate mobile users. That’s why moves like Reddit restricting API access only hurt legitimate users and lazy bot farms, cause the hardcore bot farms have been using the official app on real phones all along.



  • Oh actually it’s worse than that. There are online companies that offer online SMS services that can receive messages from real phone numbers by essentially telling your carrier you want text messages forwarded to them. Obviously they usually make you prove that you own the number before requesting forwarding, but there’s ways around that. I’ve known several people who’ve had their online accounts broken in to because someone hijacked their phone number’s SMS in order to perform password resets or bypass 2FA.