Your sign-up form is a weapon

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A SaaS founder describes discovering their sign-up and forgot-password forms were being exploited in a subscription bombing attack — where bots register real victims' emails across many sites to flood their inboxes and bury important security alerts. The attack was low-volume (1-2 sign-ups/hour) and designed to evade rate limiting. The fix involved tightening firewall bot detection, adding Cloudflare Turnstile (integrated via Better Auth's built-in CAPTCHA plugin), and restricting all emails except the verification email until the address is confirmed. The post argues that any sign-up form that emails unverified addresses is complicit in this attack, and urges developers to treat CAPTCHA and email gating as baseline requirements, not optional tasks.

8m read timeFrom bytemash.net
Post cover image
Table of contents
What is subscription bombing? #How we spotted it #The pattern #Designed to be invisible #The damage isn’t to you #What we did #Wrapping up #

Sort: