Hacker News new | past | comments | ask | show | jobs | submit login

What about the case of someone signing up for thousands of accounts?



> What about the case of someone signing up for thousands of accounts?

My question is related to the specific /login page, not the registration page.

I understand the benefit for blocking spammer signups, but not for the current case of the login page where users have an account already, were verified that the account/password was correct (captcha appears in second step), and then have to enter a second decryption password manually.

In that scenario there's no argument on the "WHY" a captcha helps. It simply doesn't.


It increases the cost of credential stuffing attack, which is very common nowadays.


Why would that be a problem on surface? You have thousands of users, why do they need to be unique identities?

The only reason I can think of is because they want more unique identities. More unique people means a greater chance for a purchase. More mail accounts just cost more.

The entire business model of free accounts requires someone paying for something extra. By unique identifying people they can limit new accounts and increase their chances of an upsale.

What if they changed how they operated. Instead of looking for more unique identities why not accept multiple addresses and include an ad at the end of every free email letting the receiver know this came from protonmail. That would give a benefit for each email sent and provide more advertising and give users a reason to upsell?

My guess is having that ad after every mail would bother you (the customer) more than having your identity uncovered.


I don't think they have a problem with a user creating two or three accounts. It's a problem if someone creates thousands of email accounts to send spam with.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: