cross-posted from: https://lemmy.cat/post/6385

It is currently possible, through Lemmy’s API, to create accounts automatically and without limit if verification by email address or captcha is not activated. I’d advise you to activate one or both of them NOW!

After registering x number of accounts (currently I could do thousands), all you have to do is list all the existing communities for each of the account to publishes one new post per community, or more. I’ll leave you to picture the mess.

(I apologise to the administrators of sh.itjust.works, I should have done the test with my own server.)

You are viewing a single thread.
View all comments View context
2 points

If you don’t have your own domain, it’s hard to generate mass email addresses, at least with large providers.

So if someone uses his custom domain to mass-generate emails, it’s easier to delete all accounts that use this same email provider.

permalink
report
parent
reply
0 points

https://duckduckgo.com/?q=10+min+mail+api&t=fpas&ia=web

There are enough options out there. No need selfhost.

permalink
report
parent
reply
1 point

True, but if it’s from a known provider, you can block those as well (and they probably have their own mechanisms to deal with service abuse).

permalink
report
parent
reply

Lemmy

!lemmy@lemmy.ml

Create post

Everything about Lemmy; bugs, gripes, praises, and advocacy.

For discussion about the lemmy.ml instance, go to !meta@lemmy.ml.

Community stats

  • 202

    Monthly active users

  • 1.1K

    Posts

  • 14K

    Comments

Community moderators