RE: RE: SEO SPAM BOT THAT EXPLOITS ECENCY // BOT DE SPAM DE SEO QUE EXPLOTA ECENCY
You are viewing a single comment's thread from:

RE: SEO SPAM BOT THAT EXPLOITS ECENCY // BOT DE SPAM DE SEO QUE EXPLOTA ECENCY

Words
366
Reading
2 min
Listen
Play
3M

Appreciate the writeup, but the central premise doesn't hold up and misleading.

We act on your reports. We don't just receive them - we work them: we look for the pattern behind these accounts and close the gaps iteratively. We closed another one from your recent reports today, in mattermost chat we talked about this. Framing this publicly as an unaddressed "threat" on the same day we were acting on your reports misrepresents what is an ongoing, working collaboration.

There's no SEO incentive. Ecency noindexes content from new accounts - search engines are told not to index it, and links from non-indexed pages pass no ranking value. Whatever this actors attempts, they get zero SEO benefit through Ecency. "SEO spam botnet that hacks Ecency" describes a payoff that doesn't exist.

"Hacked" is wrong. No vulnerability, no breach, no unauthorized access - a free onboarding service used at scale is abuse of a public service, not a cybersecurity incident. And by your own analysis this is a single actor with a repeating signature (new account → one templated post → outbound link → abandoned), which is the opposite of a distributed "botnet."

On our controls: the post says we have "only email verification and basic CAPTCHA." Not accurate. We run email verification, VPN/Tor detection, and IP quality checks at signup, alongside CAPTCHA - the IP-rotation theory in your post is exactly what those checks exist to catch. You can check our recent transparency report on how many of those never pass our checks. @ecency/ecency-operational-transparency-infrastructure-insights

Where you have a real point: if some links are phishing, that's a genuine user-safety issue - but it's moderation, not an "SEO botnet." A consistent signature is detectable, and first-post-with-outbound-link is the proportionate place to tighten. Not phone/ID verification, which conflicts with our no-biometric stance and punishes every legitimate new user for one spammer.

One clarification: "any account created via the faucet is doing spam" isn't true - the faucet onboards real users daily. If you mean the spam accounts came through the faucet, that's fair and far narrower.

If a gap is still open, the fastest path to closing it is the channel where you were reporting weekly, this post doesn’t help.