It is plain silly to require phone number verification as a 'security mechanism'
It is plain silly to require phone number verification as a 'security mechanism'
https://code.gab.com/gab/social/gab-social/-/blob/develop/RE...
At a more technical level, do we need a 4xx code for "memory holed"? Was this an oversight of the IETF, or should Medium and other discerning and socially responsible content providers use the other available 4xx codes?
Here, 404 "not found" is a pretty lie.
We could start off with the basic 400 "bad request". This is closer to the truth. In fact, it is too close to the truth because it means "client error". (Is it a crime yet to click on "not found" articles?)
So, ok, let's try 401 "unauthorized". This is still better than "not found" but, again, just a bit too honest.
But, really, Medium.com should be responding with 403 "Forbidden". This is the unvarnished truth from the mouth of the server.
403 - Forbidden: "The request contained valid data and was understood by the server, but the server is refusing action. This may be due to the user not having the necessary permissions for a resource or needing an account of some sort, or attempting a prohibited action e.g. creating a duplicate record where only one is allowed)."
Pretty much every service does this. Try signing up for a Google, Facebook, or Twitter account without providing a real phone number. Usually if it works at all, the account created will be rapidly blocked until you do provide one.
A captcha is more than enough.
Is a captcha enough? I've never worked in bot/spam mitigation for a large public platform before, so I don't really know. Based on how universal phone number requirements are for these services, and how much trouble they seem to have gone to in order to block using easily purchased numbers, I'm going to guess that captchas aren't enough.
who ever said that "security" meant yours? ¯\_(ツ)_/¯
why?