Skip to content
This repository has been archived by the owner on Nov 25, 2024. It is now read-only.

Default configuration is abusable by spam bots #2400

Closed
bones-was-here opened this issue Apr 28, 2022 · 2 comments
Closed

Default configuration is abusable by spam bots #2400

bones-was-here opened this issue Apr 28, 2022 · 2 comments

Comments

@bones-was-here
Copy link

And the documentation makes no mention of setting up captcha or disabling registration.

  • Poor experience for would-be homeserver admins who get exploited by automated bots as soon as their instance is discovered
  • Creates work for matrix.org abuse team, and the moderators of other communities using matrix
  • Increases the amount of system resources used by homeservers
@nakoo
Copy link

nakoo commented Apr 28, 2022

I also think it's important to mention using create-account command in INSTALL.md page. I found many users don't know the command either.

@S7evinK
Copy link
Contributor

S7evinK commented Apr 29, 2022

The example config now has registration disabled by default. We also verify that reCaptcha is enabled when enabling registration and fail to start if that's not the case.

create-account is now also added in the Getting started section.

@S7evinK S7evinK closed this as completed Apr 29, 2022
@matrix-org matrix-org deleted a comment May 1, 2022
@matrix-org matrix-org locked as spam and limited conversation to collaborators May 1, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants