Subscription bombing and how to mitigate it
bytemash.net
Subscription bombing and how to mitigate it
1–10 of 199 posts
Re: Subscription bombing and how to mitigate it
#2Re: Subscription bombing and how to mitigate it
#3As a user, I would prefer no welcome email at all.
Re: Subscription bombing and how to mitigate it
#4> If a bot creates an account with someone else’s email, the victim gets one email, if they ignore it that’s the end of it. The welcome email and everything after it only fires once the user verifies. As a user, I would prefer no welcome email at all.
Re: Subscription bombing and how to mitigate it
#5The Internet was carefully designed to withstand a nuclear war and this approach, being adopted en masse, is slowly turning it into a shadow of its former self. And despite the us-east1 and multiple Cloudflare outages of last year, we continue to stay blind to this or even rationalize it as a good thing, because that way if we're down, then so are our competitors...
Re: Subscription bombing and how to mitigate it
#6> If a bot creates an account with someone else’s email, the victim gets one email, if they ignore it that’s the end of it. The welcome email and everything after it only fires once the user verifies. As a user, I would prefer no welcome email at all.
Re: Subscription bombing and how to mitigate it
#7Re: Subscription bombing and how to mitigate it
#8Editing to add: almost 100% of these emails came from the same e-commerce product, I'll have to look up which. But every site i got an email from was running the same off the shelf template.
Re: Subscription bombing and how to mitigate it
#9A good old Honey Pot helped us at All Quiet "a lot" with those attacks. Basically all attacks are remediated by this. No need for Cloudflare etc.
Re: Subscription bombing and how to mitigate it
#10A good old Honey Pot helped us at All Quiet "a lot" with those attacks. Basically all attacks are remediated by this. No need for Cloudflare etc.
Can you expand on that? A separate honey pot sign up page invisible to real users, or something else?