Topic-icon A personal consideration about G+ Login

Active Subscriptions:

None
10 years 7 months ago #36685 by alegag
Hi!
I've seen the new Google+ integration (and i think is a great feature! Also for all that users wich have not to confirm email activation code but are logged simply and quicky).
Question is.... how about spammers?
For example, registering on FB is required a confirm through email link on Gmail i've seen a lot of spammers getting for free one email account in less of 2 minutes and just autenticated on Gmail, G+, Ad Words and all others services.
They could confirmo phone (but not required), they can confirm secondary email address (but also that not required).
So....... is not "dangerous" that kind of auto/autentication?
Plugin have onboard some settings that can verify Ip, Verified email and several combination wich makes safe the sign up on our website with this feature?
Many Thanks for your answer/support
The topic has been locked.
Support Specialist
10 years 7 months ago #36725 by alzander
Alessio,
It's a valid argument, but one we aren't going overboard to prevent right now. Yes, it's pretty easy to get a Google account. However, they do have mechanisms to report bad accounts. In the month we've been using G+ on this site, and the few weeks of reports from users, spam hasn't been an issue yet. That's certainly not a long-term trial nor exhaustive, but it says that it's not an immediate problem.

As we add more authentication providers (Twitter coming in about a month and LinkedIn late this year), I can see having individual options for activation per provider instead of the one setting we have right now. It still won't be perfect, and there are even spammy Facebook accounts, though rare.

There are also plugins for detection of spammy IP addresses and/or email addresses. We use SpamBotCheck on this site for normal Joomla users, but it doesn't check for users registering through a social network using JFBConnect. If it spam becomes an issue, we'll definitely add more features to JFBConnect to allow better verification of certain networks (so that G+ users may have to go through email activation while FB users wouldn't). Additionally, I'd gladly reach out to the SpamBotCheck developers and implement support for JFBConnect and recommend that, as it's a great plugin. However, for now, it just hasn't been an issue.

Obviously, if you're seeing 'bad' behavior on your site, or have any suggestions or feedback, we'd love to hear it. Facebook has been very good about policing their accounts (though it's estimated that at least 10% are fake accounts), which has made things easy. As we expand into new social networks, we'll have to re-think some general assumptions we may have, and your feedback, like above, is invaluable in this process.

Thanks,
Alex
The topic has been locked.