Company
Date Published
Author
David Lumley
Word count
572
Language
English
Hacker News points
None

Summary

Clearbit faced challenges with abusive sign-ups from spam bots exploiting a vulnerability in Google's reCAPTCHA, leading them to develop their own measures to combat such activities. They identified patterns of abuse, such as multiple sign-ups from the same IP address and the use of disposable email addresses, and employed their Enrichment API to verify the legitimacy of sign-ups. By aggregating data and using machine learning algorithms, Clearbit was able to calculate risk scores and introduce incremental friction to discourage risky actors, including steps like adding reCAPTCHA for moderately risky sign-ups and requiring phone or email verification for more suspicious cases. These efforts have resulted in blocking a significant number of illegitimate sign-ups and verifying the authenticity of many new users, ultimately leading to the release of their Risk API for public use, allowing other companies to integrate similar detection capabilities.