• FizzyOrange
    link
    fedilink
    arrow-up
    3
    ·
    9 hours ago

    I guess an easy fix for that particular issue is to severely rate limit mentions. E.g. if a user mentions more than 100 users in 1 hour then delay them and flag the account. Then you can whitelist it if it’s a legit CI bot or whatever.

    • Colonel Panic
      link
      fedilink
      arrow-up
      1
      ·
      9 hours ago

      this could be gamed though - mention 99 users, switch accounts, rinse and repeat

      • FizzyOrange
        link
        fedilink
        arrow-up
        1
        ·
        9 hours ago

        I assume there’s some barrier to creating accounts that makes it difficult? If not there’s pretty much nothing they can do.