Spam again :(

0 views
Skip to first unread message

Achim Nierbeck

unread,
Oct 26, 2016, 8:34:15 AM10/26/16
to 'Achim Nierbeck' via OPS4J Infrastructure
Hi guys, just wanted to let you know, 
it only took about a week or two for the spammers of our Jira to come back again. 

I instantly de-activated the account of the person to spam ... it's a pita. 

Does anyone have an idea how we can go on with this constant spamming of our Jira?
Will it help to use some oauth stuff or two-factor authentication stuff to block this?

regards, Achim 

--

Apache Member
Apache Karaf <http://karaf.apache.org/> Committer & PMC
OPS4J Pax Web <http://wiki.ops4j.org/display/paxweb/Pax+Web/> Committer & Project Lead
blog <http://notizblog.nierbeck.de/>
Co-Author of Apache Karaf Cookbook <http://bit.ly/1ps9rkS>

Software Architect / Project Manager / Scrum Master 

Achim Nierbeck

unread,
Oct 26, 2016, 8:38:14 AM10/26/16
to 'Achim Nierbeck' via OPS4J Infrastructure
Here's the link to the person in question: 

Niclas Hedhman

unread,
Oct 26, 2016, 9:26:03 AM10/26/16
to 'Achim Nierbeck' via OPS4J Infrastructure
Shouldn't Atlassian be pushed on the issue?

--
You received this message because you are subscribed to the Google Groups "OPS4J Infrastructure" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ops4j-infra+unsubscribe@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.



--
Niclas Hedhman, Software Developer
http://zest.apache.org - New Energy for Java

Achim Nierbeck

unread,
Oct 26, 2016, 9:28:57 AM10/26/16
to 'Achim Nierbeck' via OPS4J Infrastructure
Guess so ... 
and here we go again ... 


this just sucks. 

Achim Nierbeck

unread,
Oct 26, 2016, 3:05:23 PM10/26/16
to 'Achim Nierbeck' via OPS4J Infrastructure
Hi, 

I just opened a ticket at atlassian: 

btw, it looks like our license or atlassian will expire on November 3rd ... don't know what the impact will be :(

regards, Achim 

Toni Menzel

unread,
Oct 27, 2016, 7:08:54 AM10/27/16
to 'Achim Nierbeck' via OPS4J Infrastructure
Maybe it is time to leave Atlassian Cloud (or whatever it is called these days) and move to Github Issues. Yes they are limited, but thanks to Gradles recent announcement (same move!)[1] i got aware of Zenhub [2], which operates on top of Github issues. 
Wdyt?

Achim Nierbeck

unread,
Oct 27, 2016, 7:19:26 AM10/27/16
to ops4j...@googlegroups.com
Hi,

It's worth considering.
But right now we do have the complete history of our projects in jira. And a migration of that would need to be done first. 
It's the same for our wiki.

But a real Diskussion would need to take place on users first at this list only has limited users. 

Regards, Achim 

Niclas Hedhman

unread,
Oct 27, 2016, 10:02:35 AM10/27/16
to 'Achim Nierbeck' via OPS4J Infrastructure
I think the solution, at least in the short term, is quite easy; if the email is not subscribed to Google Groups, don't allow it to be post on Jira.

If possible, then additional rule could be added, that a post has to be made to the group before post is allowed on Jira.

And IF this was open source, we could fix this ourselves, instead of relying on corporations that don't care.

Niclas

Achim Nierbeck

unread,
Oct 27, 2016, 10:07:16 AM10/27/16
to 'Achim Nierbeck' via OPS4J Infrastructure
yeah ... I disabled self-sign-on again ... and added a banner to Jira ... 
Maybe in the longterm moving to GitHub does exactly that .. you need to have a github account ... oth it won't last long for spammers to register themselves there to and do the same thing on github ... it just needs the crucial amount of people using it for them to be attracted. AFAIK Apache did have the same issue and it's not solved there either ...

regards, Achim 

Achim Nierbeck

unread,
Oct 28, 2016, 7:56:55 AM10/28/16
to 'Achim Nierbeck' via OPS4J Infrastructure
So here's the feedback of Atlassian, 

in short since there is a captcha and since we don't have a email handler for "automagic" registration. 
There is nothing we can do about it[1]. It's a pita, Atlassian is aware of the issue they even have a 
ticket[2] for their system. 

So right now, we have to go the same way, as Apache does. Enabling new users only when called to do so. 

regards, Achim 

Reply all
Reply to author
Forward
0 new messages