deso-protocol / frontend

DeSo frontend
MIT License
267 stars 136 forks source link

Many Signup Issues Recently #211

Open addanus opened 3 years ago

addanus commented 3 years ago

@maebeam @lazynina

As seen in the pulse discord newbie and discussion channels...

There seem to be a lot of issues with front end not moving forward with the verify phone number process.

Related? Somehow accounts are being created with a 0.0000000 balance even with submission of BTC. As a result, no transactions are allowed. The public key is valid as we are able to send Bitclout, but only after .21 CLOUT was sent was one user able to update profile. Sending .01 got them further but wasn't enough... and I'm running out of charity clout :D

Is there any chance these issues are due to the current Bitclout price?

maebeam commented 3 years ago

We've been fighting a lot of bot traffic on the sign up flow. If you could have these users email node.admin@bitclout.com with their IP addresses that would help us identify where we're blocking false positives.

I'm also happy to send you some more charity clout to help onboard these new users. Thank for being so helpful!

ItsAditya-xyz commented 3 years ago

@maebeam I wonder how the bots are bypassing the phone number verification criteria to get starter CLOUT. Can't we have captcha while verifying phone number ? This really is a serious issue since a lot of people aren't able to create their account and writing email to get started to use a social media isn't what many people will likely do.

maebeam commented 3 years ago

We have a captcha and the bots are solving it

addanus commented 3 years ago

The bots just need a valid account to send earnings to (and invest from). It's easy enough for bot creators to make legit accounts - with name and funding by sending clout instead of auth'ing via phone number. Then they just provide the seed phrase to the bot and let it do its automation. Easy enough

Had a chuckle at "bots bypassing phone number verification" - pretty sure they're not sentient yet... just the red hats doing their hacking thing most likely.