The Ease of Bypassing Steemit's 'Account Approval'.

in spaminator •  last year

After all of the articles I have been reading, and even writing, recently, I thought it would be interesting to see how hard it is to bypass Steemit's account approval. To do this, I created 15 accounts, and the results are quite interesting. The short answer? Steemit's account approval period doesn't seem to mean anything. 14 accounts made it in within a week, and the 15th has been approved but receives and error each time I try to actually get the password for the account.

To conduct this experiment, I created groups of accounts using different methods, to try and identify how (if at all) they identified accounts to be flagged.

I created three accounts on one IP, then moved to another for the next three, and so on until I hit 15 accounts total. This seemed to have no affect at all on the account approval process, which seems reasonable. It is reasonable to assume a family at the same home might be signing up all at once. I will create more accounts in future to further test this, but this was just a preliminary test.

When I created this account, nothing at all was needed in terms of identification. No email, and no phone number. Now however, both are needed. How to bypass this? Easy. It took me on average 3-5 minutes to create one account (including every step, phone number and email accounts too).

Firstly I looked for an email service that didn't require a phone number, of which I found a variety. Yandex, and Tutanota were three which I spent the most time with, as they were very simple and fast to set up. Each account takes only a matter of minutes to set up. Next though is the phone number, which would seem like a bigger problem. But..... A simple 'receive SMS online' Google search comes up with hundreds of sites which you can 'borrow' phone numbers from to create any type of account. Great to create accounts you don't want to be associated with, or spam accounts.

After both of those steps are done, the account is pretty much created! Now just wait for the approval period. I am curious to hear other users opinions though, has anyone actually been declined an account? Why?

14/15 accounts (possibly 15/15) all using fake numbers, emails and (in some cases) the same IP, passing the authentication period makes me think that nothing actually happens in that time. It's just a 'funnel' to let new users into Steemit.

What will I do with these accounts? I have no plan, and nor do I think I ever will for them. They will just sit there unused. However, the results are quite interesting, and it makes me believe that there actually isn't anything (or a very poor) authentication process. If anyone wants to make thousands of accounts for spam, I don't see them having any problem at all. They wont be stopped.

In this current state, spam is going to be an ever growing problem... One that I think can't be dealt with. Once again, the moderators need to act. They are the only people who can stop it, no 'Steem spam' bot or group can stop spammers who have full freedom on this platform.

I am going to relate it to viruses. There are thousands of anti-viruses out there, and many are made by incredibly big and powerful companies, Microsoft even. But can they stop viruses and different forms of malware from spreading? No. Once they learn about the malware they can prevent it in future, but they can't prevent the new viruses people will create. Spam and Steemit is much the same, if there is no preventative method to actually stop spammers from getting on the platform, spam will keep coming. Much will be stopped by the spam bots and vigilantes, but spam will always be ahead. Especially when money is on the line.

You can also use anonsteem or steemconnect to create an account. Though, it's pretty obvious which account spondor3d the creation of your alt with steemconnect.


I had no idea about these two sites. I guess they are easier, but also easier to track which users are associated.. But interesting! Thanks for the comment :)


If you pay anonsteem with LTC or BTC then your steem account as as anonymous as your LTC/BTC.


That's interesting... And I guess that those accounts are instant too? No account approval period?


None. The process is near instantaneous. I've created a few accounts for people this way.


Thanks so much. That helps.

Meanwhile, my friend created an account two weeks ago and it's still not activated yet! is who he will be.


Yeah, it seems to be completely random how long it will take... I had some accounts take 4 hours and some around a week.. All created at the same time!

thanks for sharing this. 15 accounts. i tried to set up a second and I could not. I did use a different email and that was about a month ago. Maybe I should try again

Unfortunately, spam will always be ahead. That's the nature of an ever-escalating, human-backed architecture that profits by simply being and being in front of people.

(You can probably think of this in a better context by thinking about ecologies. You can never just have an ecology of plants that grow, live, and die. If energy is entering the system, you will get plants that parasitize other plans. Given long enough, you get animals that feed upon plants and which are, in turn, fed upon. An environment that lacks that dynamic is dying, leaking energy into entropy.)

In retrospect, that's kind of depressing.

I'm curious how much the "active engagement" requirements on Steemit are going to suppress how much of that spam actually ends up in front of someone. Making it cheap and easy to create an account doesn't necessarily mean that the content that account creates will get seen by people, or by many people. Unfortunately, this also is a pressure that works against new users getting into the community. After all, at the beginning, everyone is indistinguishable from a spam account.

I'm a new user, here, so I don't have an immense amount of understanding of how the dynamic works. I hope to gain one. We'll see how that goes.