this post was submitted on 16 Jan 2024
165 points (87.3% liked)
Technology
59357 readers
5404 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
It's trivial to create new accounts and emails to verify those accounts. It is not trivial to get a new phone number since virtual numbers are blocked by the verification process.
Is it really that trivial, especially while having to spend your own money to do so?
And can't that be detected in the same way that virtual phone numbers are detected by Discord currently?
You get your ISPs email address, and you could have your Google address, what else?
Granted, a phone number is better than email for verification, but plenty of websites work off email verification today successfully.
What are you talking about? There are endless services where you can get a free email address without spending a cent. Verifying that an email is genuine is a much harder ask than you might think.
Fair enough, but then how is it used today successfully by websites?
That's the thing, it's not. Lots, and I mean lots of sites are plagued by bot activity. The ones hardest hit are the ones that only have email validation.
I could go to Google and create a new account right now, absolutely free.
Hell, I could write a script that creates a million for me for barely any money, just paying a CAPTCHA farm a nominal sum to solve the robot tests for me. This is why sites like discord are plagued with advertisement bots, the bar to entry is literally nothing.
Phone numbers cost money to create, and are in finite supply. Even PAYG (pre paid numbers for you Americans) numbers require you to go outside and purchase a SIM card from a store. They aren't foolproof, but they stop the vast majority of fake accounts.
But those other websites that suffer the same kind of issues work successfully without asking for a phone number, just via email verification. I don't see why Discord should be any different.
I understand all of those ramifications, and not arguing against it.
However, it's moving the onus of dealing with the issue from the website owners to the users who use the website. It causes the users to lose their anonymity, and allows their website usage to be tracked and sold. That's a step too far.
How else is the platform owner to prove that the account is linked to an actual person without defeating the check being trivial? They can't without something being tied to you. An email address may have been a good one to use back when AOL gave out addresses as part of their subscription service, but the availability of free email has destroyed this possibility. Out of the many things that could be asked for you to provide, a phone number is the least nefarious.
You reserve the right to not give your phone number to Discord. You do not need to give Discord your number in order for you to be able to use it. Likewise, the server owner reserves the right to ask Discord to only allow accounts that have been verified to not be burner accounts. Email verification does not do this, and the time limits on membership only go as far as slowing down accounts used in bad faith in a server, whether that be scams, trolling or otherwise.
Like many things in life, it's a trade-off. You value your right to privacy more than being granted access to this particular server. The server owner values the reduced ability of trolls and bad actors over the loss of membership from users like you. Unfortunately you cannot have your cake and eat it too.
The only alternative I can think of is just buying a pre-paid number and a cheap second hand phone and using that only to verify with services. It's good for 2FA too as it makes you immune to SIM swap attacks.
As the owner of a 2000+ user server, this setting is an absolute necessity because yes, disposable email accounts are plentiful and Discord still does a poor job of detecting them. Server raids still happen, and temporarily restricting access to non-verified accounts helps mitigate this.
However, Discord's phone number verification blocks most VoIP or burner numbers from being registered. It's one of the few things Discord does pretty well these days, IMO.
I host my own email. I have literally billions of email addresses available if I want them and getting billions more only costs however much I can get a new domain registration for, which isn't often more than $10. I already own a dozen domains or more and I can have any username I want at any of those domains for any email at no additional cost.
Now I'm not some dickhead harassing people online or spamming discord servers, but I will admit that Wendy's once had a deal where you could get a free frosty for creating a new account and I had free frosty coupons for weeks before they realized that email only verification for unique users was a losing proposition and they switched to requiring that new accounts attach a phone number.
Email verification only works if you've got nothing to lose. As soon as there's anything on the line, you'd better look for something more concrete like a phone number, a credit card, or a government ID. Personally I'm more comfortable with Discord having one of those pieces of info before the other two, but that's just me, you do you.