Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This sounds like a very nice compromise actually. I'm surprised it helped with abuse though, since there's a lot of email providers that are easier to create an account with than gmail.


It's trivial to defeat though, all you need is your own domain and an email provider that supports catch all email addresses.


A big part of handling abuse is to recognize that you cannot win - all you can do is better. And a big part of abuse is just raising the bar of sophistication required to abuse you. We went from "any random script kiddie with a gmail account gets infinite accounts easily" to "now someone has to use a custom email domain" (which is easy for us to just banhammer the domain), which both requires sophistication and money. And it makes the banhammer-swing more on par with the amount of effort they have to put in to evade it - banning the domain means go find another domain and pay another registrar fee.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: