PDA

View Full Version : Double login protection for duplicate IP addresses and hostmasks



Rasbelin
Mon 13th Oct '03, 4:48pm
Last winter we debated here about new measures for controlling banned users and keeping the riff raff away and maintain order. We did get the refurbished banning rod and "Tachy Goes to Coventry" feature, but I'm still missing one very benefical function for doing more effective supervision of new registrations on forums that are often victims for persons who create a bunch of double logins (especially during night hours) and the go on rampage very abusively, while no staff is present.

I have been as staff on a community which now has over 40 000 members and staff currently on a site with 900 members, plus also have seen a more raped forum which was badly staffed (no active moderation) and had almost everyday some crap being posted. So I have seen quite of the dynamics behind creating double logins and trolling with them. I don't want to claim I'm pro on it, but at least have somewhat with know-how.

The more abrupt and repeating offenders can't be stopped by any reasonable means until they get to post a few posts which indicate what they are (in the case all previous examination fails to indicate anything suspicious), plus they will anyway try again every now and then. Because tend to be fortunately a very small minority, I leave it to diplomacy and banning any accounts, as anything else would be quite farflung. Now the real issue what could be addressed are Sunday trolls (compare to Sunday drivers/gamers) which just want to have an easy ride once or twice, or do it because they are very upset because of some other poster and want to flame the person anonymously in public. These are people we could try to address better and try to limit Sunday trolling.

They don't take it too seriously and aren't pro at it, so they should be discouraged already when they start creating the DL and make it abit more time consuming which kills the fun out of it. Also it would mean that unlike setting all accounts to require moderation, only alarming cases are supervised. This could well solve the issue with more pro trolls using the weakness of AOL that you can't ban IP addresses without blocking out peaceful users too.

The idea is register.php related basically. When an account is created, vB verifies if the IP address or hostmask already matches with some user. If it does, the user is put into the moderation queue for staff intervention and a manual check that it's not a double login and potential troublemaker. If the user is clean and there's no matches (100% matches only count), the user is added to the Registered Users usergoup as usually (that would be the default one). This feature could be enabled/disabled via admin CP and you could specify the number of the usergoup into which the awaiting users should be put into (by default it would be (COPPA) Users Awaiting Moderation). Of course e-mail alerts would be available too. The functions to check for matching IP addresses and hostmasks shouldn't be an issue, so IMO this is a pretty much straight forward idea for implementation.

I did tell about my idea already on IRC at #vborg, where I was encouraged to bring up the idea officially too and not just plan to make a such hack, because it would be a worthy feature most likely.

Scott MacVicar
Mon 13th Oct '03, 6:24pm
the problem is many ISP's now use proxy servers.

So people like myself who use NTL would all be put in the moderation queue even though we're all different people because our ISP uses a proxy.

This also includes Freeserve (owned by wanadoo) and AOL who are some large ISP's.

Rasbelin
Mon 13th Oct '03, 7:38pm
Yes, that's correct. However the point is that then proxy server uses would go through an extra layer of manual validation and thus make it more anti-troll safe. Also this would be an option you can turn on and off.

Wayne Luke
Mon 13th Oct '03, 8:38pm
You already have an option to manually validate all new users. I would say that 85% of all users in the United States will be visiting through an ISP or Employment based proxy. Not about other countries but they will be fairly high as well.