Post by Stefan Wintermeyer

Das aktuell größte technische Problem beim Betrieb von vutuv sind die Fake-Accounts. Robots die sich einen Account anlegen und dann entweder gar nichts machen oder auf Spam-Webseiten verlinken. CAPTCHAs sind a) nicht mehr das, was sie mal waren und b) super blöd zu benutzen (da verliert man ja direkt die Lust auf alles). Ich überlege schon, ob ich inaktive neue Accounts nach 2 Stunden automatisch lösche. Bin für jegliche Ideen dankbar.

1

Wäre das Erzwingen von 2FA eine Möglichkeit? Gefällt vielleicht nicht jedem, aber das schränkt die Bots stark ein, denke ich.

1

2FA ist leider für viele normale User eine zu große Hürde. Ich will niemanden dafür bestrafen, sich sich so sehr mit der Technik aus zu kennen.

3

Replying to @wintermeyer

Würde es sich dennoch anbieten, OTP optional zu implementieren? ^^’

2

Replying to @lukas_schieren

Gib mir mal bitte ein Anwendungsbeispiel. Welcher User will OTP und kann/will nicht Passkey benutzen? Warum?

1

Replying to @wintermeyer

I find TOTP to be necessary when I’m accessing an account on a browser that I don’t control, like at a library. There, I can copy the TOTP code from my smartphone, but can’t install a credential manager on the desktop.

Although the previous example is likely more common, I’ve also required this when accessing secure government installations.

This post is part of a conversation with 13 posts. Read it from the start

Other formats