cross-posted from: https://lemmy.cat/post/6385

It is currently possible, through Lemmy’s API, to create accounts automatically and without limit if verification by email address or captcha is not activated. I’d advise you to activate one or both of them NOW!

After registering x number of accounts (currently I could do thousands), all you have to do is list all the existing communities for each of the account to publishes one new post per community, or more. I’ll leave you to picture the mess.

(I apologise to the administrators of sh.itjust.works, I should have done the test with my own server.)

  • @PekkaOPM
    link
    English
    21 year ago

    I too played a bit with the API today and it is very easy to do everything that a user can do as a Lemmy Bot. So please take this into account when securing your Lemmy instance.

    We can also use this power to protect our users. For example a bot could send a welcome message with a link to the instance rules, the first time a user comments or posts on the instance.