META: Fix the signup procedure?

Valerio Messina efa@iol.it
Thu Aug 12 10:36:12 GMT 2021


On 8/11/21 1:26 PM, Russell VT via Cygwin wrote:
> Can one of you powerful folks, please, fix the signup approvals and make it
> a bit more difficult to signup and account that is "allowed" to post on
> this list?

as now the subscribe procedure is a simple:
0) open the web page: https://cygwin.com/mailman/listinfo/cygwin/
1) fill form with name, email and pass
2) press the Subscribe button
3) receive a confirmation mail
4) follow the link in the mail
5) press the subscribe button in the new web page
all steps are easily script-able with 'curl'
So in my opinion first thing to do is to add a CAPTCHA [1] in the step 1


I tried to contact the list admin sent from IP: 8.43.85.97
that is <noc@redhat.com> asking for removal of spammers once we received 
every spam, but spamming continue.


I also noted a big increase in spam directed to my email, once I made a 
post to the list. This is probably related to the fact the list archive 
is freely available to web spiders at:
https://cygwin.com/pipermail/cygwin/
with email sender visible as first line once you open an mail.
So second action to do is report the 'name' of sender but not the email 
in those pages, or at least blacken the domain part @domain.tld


[1] https://en.wikipedia.org/wiki/CAPTCHA

thank you,
-- 
Valerio


More information about the Cygwin mailing list