Closed Zodiac1978 closed 9 months ago
It seems, that no one is interested in answering questions raised here. :(
I tried this by myself and the problem is mentioned on the linked page:
This method bypasses all blacklists, normalisation and obfuscation bypass checks.
As those spammers rotate mail names and subdomains with random characters, sending just a hash is not as efficient as sending an email in plaintext. Sending PII like mail, IP, username would be much better, but implies user action (adding this to the frontend and privacy policy).
Therefore I close this again. But now it is at least documented and ... sort of ... discussed.
We removed StopForumSpam in 2.8.0 to avoid potential GDPR issues: https://github.com/pluginkollektiv/antispam-bee/issues/180 https://github.com/pluginkollektiv/antispam-bee/pull/181
I would like to take a second look at it.
They do support hashes now: https://www.stopforumspam.com/usage
There are also discussions about it in the forum: https://www.stopforumspam.com/forum/viewtopic.php?pid=49115#p49115
Maybe @praetorim can help us to decide if this is possible.