u/No_Honeydew_2453

Fake account creation getting past our basic checks, what signals actually work at signup?

Big wave of fake account creation getting past our basic checks. Disposable email detection and IP blocking aren't really doing much anymore. What signals actually work at the signup stage?

reddit.com
u/No_Honeydew_2453 — 2 days ago

AI agent bots hitting our platform and standard detection isn't catching them. Anyone else seeing this?

Anyone dealt with AI agent bots hitting your platform? Starting to see traffic that doesn't look human but isn't triggering our standard bot detection. Any idea what to do about it?

reddit.com
u/No_Honeydew_2453 — 4 days ago
▲ 0 r/webdev

Anyone else treating CSP violations as a deployment issue now?

We started getting enough CSP violations in production that I stopped treating them as just security reports. A new analytics script, payment widget or third-party SDK gets added and suddenly something breaks because it isn't covered by the existing policy.

Do you test CSP changes in CI/staging, run Report-Only first, or just deal with violations when they show up in production?

reddit.com
u/No_Honeydew_2453 — 6 days ago