Hacker News new | ask | show | jobs
by wyager 1550 days ago
This seems like an especially trivial-to-bypass mitigation.
5 comments

Like the poster said, it’s whack-a-mole.

These trivial mitigations at least filter out low-effort script kiddies. People gaming the system “for real” will put incredible effort into getting around your countermeasures. You always have to be one step ahead of them.

It may be “trivial” to someone with a high level of expertise. But the number of moving parts required in that automation does add a significant barrier to most the of “script kiddies” that are using bots.

You still need to automate account creation and setting up of a TOTP token, that’s not “easy” for a lot of people.

You'd be surprised at how big of an effect "trivial" mitigations like this have when you're defending against what amounts to a sea of script kiddies.

With a problem like this eliminating 80% of attackers gives you 80% of the benefit, it's not an all or nothing thing.

What would you suggest?
Low device limit per phone number/payment card, with the standard checks for VOIP would probably make things painful enough for most. Heck, outsource the bot checking and require a Facebook/Gmail/Apple/Twitter/whatever login. Intrusive as heck, but it works relatively well since those companies have already whacked a million moles.
Limits per shipping address?
Maybe, but it's also just a good idea to do anyway, so might as well.