Topic: Any SPAM and Security issues??

I am very interested in FluxBB, but SPAM and security are huge concerns. Can anyone tell me what measures are in place to reduce or eliminate SPAM and to make sure that bots and unwanted users do not ruin the forum? Does anyone currently have issues with SPAM or security that cannot currently be fixed?

Thanks,
Charles

Re: Any SPAM and Security issues??

Spam is definitely a concern.  I'm using 1.2 and a CAPTCHA plugin which prevents most automated spam, but I still get some spam, some of which is human-generated, but some of which still could be automated (hard to tell).  If Flux had a "Moderate user's first post" feature like some other forums, I imagine I could catch 99+% of spam that way before it hit the board, but there's no such feature.  For now I'm stuck with finding spam after it happens, which is a extra pain because my forum emails recent posts to a mailing list every day (homegrown script) and I might not catch the spam in time, and the email recipients are really sensitive to spam, naturally.  I'd like to upgrade to the latest 1.3 SVN version of Flux but I don't think there's even a CAPTCHA for that, so that would be a step backwards.

So in my mind, neither the latest release version (1.2.something) or the development version (1.3 SVN) is suitable if spam is a concern.  Once 1.3 gets to the RC (Release Candidate) stage then we can expect a CAPTCHA plugin, but I don't think I've seen any plans for a Moderate First Post plugin.  And there's no telling when 1.3 RC will be out anyway.  The initial release date was supposed to be around June so it's about four months late and ticking, and the developers haven't given any ETA's for when it will actually be released.

I wish I had a more uplifting answer, but I'm just trying to be honest.  Maybe two months from now we'll have an RC version, CAPTCHA, and Moderate First Post... or maybe we'll have none of those things.

Re: Any SPAM and Security issues??

Hi Michael,

Thank you for the your thorough response. I wonder if FluxBB can become a leading forum if these basic issues are not addressed. I am 100% behind the philosophy of the developers and I think the performance and default look and feel is excellent, but I do not want to spend my time tracking down SPAM. And a 4 month delay in the 1.3 RC must make everyone nervous, especially people like myself who are deciding which forum software to use. Hopefully these issues will be resolved quickly and FluxBB will gain a large following.

Thanks,
Charles

Re: Any SPAM and Security issues??

MichaelBluejay wrote:

So in my mind, neither the latest release version (1.2.something) or the development version (1.3 SVN) is suitable if spam is a concern.

I disagree. The FluxBB/PunBB 1.2.* has a wealth of anti-spam mods available - just browse punres.org - including an Akismet plugin, various other tools, various CAPTCHAS and several excellent anti-spybot mods too smile. Combine one or several of these with other sensible server management practices and you can have a very effective spam-resistant forum with 1.2. And if you want more, there are plenty of other useful anti-spam hacks around on punres, and the forum on punbb.org, not to mention Google, where you can find nice additional hacks like:

http://jivebay.com/2007/05/07/prevent-spam-on-punbb/

PunBB 1.3 also has an official anti-spam extension ready for testing. There are several solutions floating around here for FluxBB 1.3 too. So it might be too early to write off the 1.3 branch in the anti-spam department.

I am however very sympathetic to the view that 1.3 should have in its core as good an array of antispam in it as any modern forum. Nowadays, you need it.

Re: Any SPAM and Security issues??

I'm afraid I have to disagree that 1.2 has adequate antispam tools.  I checked PunRes.org and didn't see any plugin for Moderate New User's First Post.  After a registration CAPTCHA, I feel that feature is absolutely the most essential for maintaining a spam-free board, and its omission is a serious one.

Re: Any SPAM and Security issues??

Obviously it would be simple to write something that address a "1st post", so then...
What would be good criteria to check for on first post screening for affecting a protection scheme being sought here? 

(Is this a good question?)

Last edited by twohawks (2008-11-07 20:28:02)

TwoHawks
Love is the Function.
No Form is the Tool.

Re: Any SPAM and Security issues??

That is a very good point twohawks. Perhaps we could use this thread as a place to create an anti-spam feature wish list. Then we can see how many of the features are fairly easy to implement.

Re: Any SPAM and Security issues??

MichaelBluejay wrote:

I'm afraid I have to disagree that 1.2 has adequate antispam tools.  I checked PunRes.org and didn't see any plugin for Moderate New User's First Post.  After a registration CAPTCHA, I feel that feature is absolutely the most essential for maintaining a spam-free board, and its omission is a serious one.

What one classes as adequate is generally a purely personal decision. Each person is different. smile At the end of the day, the fact that spam solutions can be written and added to the base system is always better than having them in the core. There is then no common method that the spammers can target. I'm sure once 1.3* has settled down with the remaining commits, there will be just about every method of spam prevention written as an extension. smile