site banner

Are there guards against similar usernames?

I tried to make "Z0rbaTHut" and the UI blocked me, but when I modified the request and forced it to sign up anyway, the account got made.

Unfortunately I lost the original web requests showing that "Z0rbaTHut" was not allowed so I am not 100% sure I found an explicit bug. (But maybe an implicit bug in that we should discourage homographic attacks?)

2
Jump in the discussion.

No email address required.

There is some sort of mechanism for automatically detecting and marking suspected alt accounts. I haven't dug too deeply into exactly how it works or what it does though.

Practically speaking, the guard is going to be "we ban you if we think you're being a dick about it". There's maybe room for more later, but it's not a priority when we can just spend some admin power on it.