Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve spam prevention #4223

Open
srtalbot opened this issue Aug 28, 2024 · 9 comments · May be fixed by #4265
Open

Improve spam prevention #4223

srtalbot opened this issue Aug 28, 2024 · 9 comments · May be fixed by #4265
Assignees

Comments

@srtalbot
Copy link
Contributor

srtalbot commented Aug 28, 2024

Threat level to protect against

Spam prevention level 2: We can stop a malicious actor who is writing a custom script to spam a single (or multiple) GC Form(s).

ITSG-33 controls: SC-5, SI-10

User stories

As a program administrator processing form responses
I need to focus my time on legitimate responses
So that I can decrease the processing time of requests

As someone using assistive technology like, Voiceover, JAWS, or Dragon Naturally Speaking
I need to be able to verify that I am not a robot or a malicious actor
So that I can submit the form

As someone with low technical proficiency who doesn't know much about bots or spam
I need to understand what I am being asked to do and why
So that I can successfully and confidently verify that I’m a human and submit my form

@thiessenp-cds
Copy link
Contributor

I'll be exploring the different CAPTCHA options with the hope of finding one that fits our needs. I'll record this adventure in this CAPTCHA Google Doc.

@thiessenp-cds thiessenp-cds linked a pull request Sep 11, 2024 that will close this issue
@Abi-Nada
Copy link

Currently: working on a proof of concept for Hcaptcha. Proposal should be up by this week. Once we determine the approach, we'll create a card to iron out acceptance criteria for implementation.

@Abi-Nada
Copy link

Book time with product on the recommendation, to iron out costing, etc.

@thiessenp-cds
Copy link
Contributor

@Abi-Nada
Copy link

Abi-Nada commented Sep 25, 2024

Next steps:

  • Does ESDC have access to hCAPTCHA
  • Pete to follow up with Todd, potentially include Ioana and SR? Can add Calvin as optional :)
  • Look at pricing for Turnstile and FriendlyCaptcha
  • Brief Josh

@Abi-Nada Abi-Nada assigned srtalbot and unassigned thiessenp-cds Sep 25, 2024
@Abi-Nada
Copy link

Abi-Nada commented Oct 7, 2024

To do:

  • Contact Todd
  • TurnStyle, FriendlyCaptcha : @thiessenp-cds to meet and get more info
  • Briefing to Josh

@Abi-Nada
Copy link

Abi-Nada commented Oct 9, 2024

Pete meeting with TurnStyle and FriendlyCaptcha this week

@srtalbot
Copy link
Contributor Author

Email to SSC regarding CAPTCHA procurement sent

@srtalbot
Copy link
Contributor Author

Follow-up emails sent, will reach out at the director level if there is no response in another week.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants