Ask HN: How to provide a free trial without being abused?
71–76 of 76 posts
Re: Ask HN: How to provide a free trial without being abused?
#72one alternative idea to free trials from Jason Cohen's ancient 2013 microconf talk, 21:00 minute mark > another hack: lotta people have free trials. 15 day free trial, 30 day free trial. makes sense. customers want to test us out first, no one trusts anyone, that's fine. but i hate free trials actually, especially for bootstrapped companies, because you never get the money back. most people that sign up with a credit…
I heartily disagree. Maybe its just my privacy conscious european-ness but seeing how companies keep leaking data I do not went to give my data, much less my CC, to a service I'm not actually sure i will end up using.
Re: Ask HN: How to provide a free trial without being abused?
#73Earlier quoted context omitted.
It's not about the money, it's about KYC! Paying with Crypto is not solving anything for bad actors trying to do DDOS, send spam or host child porn on our servers ...
Part of my point is, demanding a lock up of funds should raise the barrier high enough that you won't need KYC - legitimate users will get their funds back (or use them to continue service) while it will be cost-prohibitive for abusers. If you want to play it safer, increase the minimum required amount and/or lock-up time accordingly. If you had a way to get this integrated easily, would it be interesting?
Re: Ask HN: How to provide a free trial without being abused?
#74Earlier quoted context omitted.
Part of my point is, demanding a lock up of funds should raise the barrier high enough that you won't need KYC - legitimate users will get their funds back (or use them to continue service) while it will be cost-prohibitive for abusers. If you want to play it safer, increase the minimum required amount and/or lock-up time accordingly. If you had a way to get this integrated easily, would it be interesting?
The thing is some abusers will be happy to pay $10 in crypto (or even $100) to be able to ddos/spam/abuse under our name ... So I'm not sure it would be enough to prevent hackers
Perhaps that is something that should be addressed, regardless of what you decide on KYC/credit cards/cryptocurrencies/etc?
Random thoughts after a little closer look, may or may not be relevant:
I see now that you host mailu/mailcow. If you give customers an e-mail address under a (sub-) domain of yours - stop that. Make customers bring their own domain, even for a trial. Or keep outgoing public SMTP out of the trial; even they do not use your domain, you probably don't want to risk polluting IP space reputation. If you still really want to let them try it and want to spend some time on it, you could spend some time restricting outgoing mail to a whitelisted email address (not domain) per account.
If you're also referring to hosting scam websites and you don't want to require trials to bring their own domain, consider making the subdomain you provide autogenerated, long, unattractive, and verbose.
If you haven't addressed all of the above, it should hopefully improve things.
For ddos/hosting illegal content, there is no shortage of places where people can get VMs and VPSes with connectivity, storage and compute for reasonable prices in various jurisdiction anonymously just a quick web search away - so even for those who don't know where they can get it for way cheaper underground, I'd assume that criminals wouldn't have a reason to burn even close to that much money for such things?
Re: Ask HN: How to provide a free trial without being abused?
#75Charging money tends to filter out bad actors.
Good luck.
Re: Ask HN: How to provide a free trial without being abused?
#76- trigger warning - Allow the whole onboarding process to be done without a CC, don't even mention that. But when a user is doing their first deploy, tell them they need a CC to complete this step. Thanks to the sunken cost fallacy, users will be more likely to proceed.
>- trigger warning - FYI the idea is to specify the nature of the trigger upfront. e.g. Self harm or whatever. That way people can judge whether they want to read the rest of the comment or not.