this post was submitted on 18 Jun 2023
19 points (100.0% liked)

Lemmy

12506 readers
33 users here now

Everything about Lemmy; bugs, gripes, praises, and advocacy.

For discussion about the lemmy.ml instance, go to !meta@lemmy.ml.

founded 4 years ago
MODERATORS
 

cross-posted from: https://lemmy.cat/post/6385

It is currently possible, through Lemmy's API, to create accounts automatically and without limit if verification by email address or captcha is not activated. I'd advise you to activate one or both of them NOW!

After registering x number of accounts (currently I could do thousands), all you have to do is list all the existing communities for each of the account to publishes one new post per community, or more. I'll leave you to picture the mess.

(I apologise to the administrators of sh.itjust.works, I should have done the test with my own server.)

you are viewing a single comment's thread
view the rest of the comments
[–] maf@szmer.info 0 points 1 year ago

+1 to that. Also the email domain matters. It's relatively easy to set up hundreds of disposable emails on random domains vs ones like Gmail.

Phone number is another solid anti abuse signal. SIM cards are harder to come by in large quantities.