Bot accounts increase

Sort:
PrivatePilotBartram

I am seeing the increase of Bot accounts recently, I have been reporting them and sure enough a week or too later I get the "we've taken action" response. Which is always a good thing.

The issue is it appears to be happening too frequently and considering there is a "I am human" captcha when you sign up to chess.com It is a little puzzling.

I play against one person on random and then a series of games through out the day the ones with out profile pictures are always predictable, they will play the same opening the exact same way if you allow them.  They OK but when you " Leave them obvious" and I do mean obvious game winning chances and they pretend to miss it or not notice its brings up questions.  If it would happen once or twice I would put it down to coincidence (although I don't believe in them.)  It goes the same way every time, you can start off ok, they will stick to the plan, they will play good perhaps too good for 1300s they come up with strong attacks and then always blunder something oblivious because they don't want to give away they are computers. However it is consistent random names, random games. the same process. 1 day I can play against the Queens gambit, never accepting it I put Bishop to f5. and not once has anyone ever taken d5 with c4 pawn. Now that is all anyone is doing.  Soon as I reported the last one for doing it. Now suddenly the openings changes. 

It's too predictable, too obvious for it not be Bot accounts.

 

Besides to rant of the problem, I wanted to propose a potential to prevent bot accounts. I wanted to discuss the idea of adding two step auth to chess.com and when you go to play you have to confirm it is you requesting the games. That access lasts until there is a stop of say 15-30 mins between games then you would have to re-authenticate.  So you would not have to do it for every game but after took a break.  The Human test on the sign up page is clearly not working.   So I believe a validation of a human presence is warranted,

Ruhaan_MD

ya there should be some human verification like CAPTCHA when people make accounts on chess.com 

Ruhaan_MD

and there should be some security features for clubs 

PrivatePilotBartram
ruhaan_MD wrote:

ya there should be some human verification like CAPTCHA when people make accounts on chess.com 

There currently is but it is clearly not working and it is easy to bypass such as using ABP or Injection method. One reason a stronger method with 2-step like phone is better you cant bypass a physical person on a phone.

Spot_Playing_Chess
PrivatePilotBartram wrote:
ruhaan_MD wrote:

ya there should be some human verification like CAPTCHA when people make accounts on chess.com 

There currently is but it is clearly not working and it is easy to bypass such as using ABP or Injection method. One reason a stronger method with 2-step like phone is better you cant bypass a physical person on a phone.

Some apps let you have recovery codes, in case say your battery is dead when you need to sign in, and such a code could be entered into the bot, but it would at least slow them down a bit.

PrivatePilotBartram
Spot_Playing_Chess wrote:
PrivatePilotBartram wrote:
ruhaan_MD wrote:

ya there should be some human verification like CAPTCHA when people make accounts on chess.com 

There currently is but it is clearly not working and it is easy to bypass such as using ABP or Injection method. One reason a stronger method with 2-step like phone is better you cant bypass a physical person on a phone.

Some apps let you have recovery codes, in case say your battery is dead when you need to sign in, and such a code could be entered into the bot, but it would at least slow them down a bit.

 

Granted, the back up codes for logging into the accounts. So there for to prevent miss use of that. If anyone uses a back-up code. They don't get access to play games.

Chess.com is already using Cloud servers similar to Discord. The back-up code allows you access to the account however you can not purchase/spend Nitro until you authenticate properly or it sends additional emails to authenticate to enable full access.  So it is feasible for it too apply here.  Back-up codes gets you a "safe-mode access to your account nothing else"

VN_Yuta

great 

 

VN_Yuta

good 

 

VN_Yuta

i agree

 

Bb8fan1

Yes, this is getting very annoying

Martin_Stahl

This really isn't a beta type topic. 

 

That said, two factor authentication doesn't prevent cheating. Most  of the cheating is done by actual members using engines and not completely automated bots.  And that type of process would end up inconveniencing honest members more than it does to stop people from cheating.

 

Also, @erik has previously stated, that it's not going to be implemented for non-privileged accounts: https://www.chess.com/clubs/forum/view/2-step-authorization-at-login-feature?comment=44799748#comment-44799748

 

This forum topic has been locked