I realize it would significantly complicate the module beyond the current 'validator' but,
as part of the comment spam arms race, I would rather:
allow bad registrations, but later (cron) silently remove, disable or caution the user.
I think that providing immediate feedback ("no, you can't use that word") to the spammers just helps educate them on ways to game the system and makes them try again until they get it right.
Allowing them to think they've cracked it, then leaving (taking their dummy email account with them) , but removing the trash an hour/day later may make the process a whole lot less rewarding and less of an escalation in hacking.
It becomes net judo. Instead of directly blocking the attacks, just let them waste their energy and "not be there" when they punch.
I'm not an expert in this stuff, but that's an approach I thought I'd throw out there.
Plus, a common application for this tool (I think) is to clean up a site where spammers have ALREADY struck, and you want to clean out the dud profiles. Having the scan/ban work as a batch process would make more sense there.
Related/unrelated
I'm personally a fan of Stealth moderation and silent hiding whereby we avoid letting the spammer/troll know they've been filtered from the rest of the world. They can continue to see their own contributions ... but nobody else does.
As ever, there are drawbacks to any approach. Different communities have different needs, and I am not suggesting this for drupal.org ...
Comments