Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Donation interface is fairly vulnerable to form stuffing. Consider Captcha #7

Open
echarlie opened this issue Feb 26, 2021 · 3 comments

Comments

@echarlie
Copy link
Member

No description provided.

@mutantmonkey
Copy link
Member

mutantmonkey commented Feb 27, 2021

Do you have a CAPTCHA to suggest that doesn't compromise user privacy? I would like to stay far away from reCAPTCHA.

If possible, I think I would also like to hint on things like User-Agent rather than adding invasive and user-visible measures like a CAPTCHA.

@echarlie
Copy link
Member Author

echarlie commented Mar 1, 2021

If I had my way, we would not allow online donations of less than 20USD or something substantial enough to deter card testing.

Also, since we're already sending data to stripe, I don't think it further compromises user privacy to adopt a captcha solution or somesuch.

We need to evalutate options here.

@mutantmonkey
Copy link
Member

mutantmonkey commented Mar 2, 2021

I believe that we get a lot of donations less than $20 unfortunately.

Right now we don't send any donation user data to Google. If we adopt reCAPTCHA, then we start doing so.

@echarlie echarlie transferred this issue from wuvt/wuvt-site May 28, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants