I
I
IdFox2017-11-09 08:55:34
Access rights
IdFox, 2017-11-09 08:55:34

How to block multiple users from one account?

Hello everyone
Tell me the algorithm for solving the problem
We have a website with unique information, the information is closed by subscription
Access is provided for 1 month to the account who bought this access, everything is simple This is
not the first time we see how many different people are sitting under one account
Well, that is, okay 2- 4 people, it’s not critical yet, but it’s already clear that there are 10 different people each . This, of course, is guesswork , of
course, but I would like a clearer evidence base
How it’s done now - we look at three parameters at the regional level)
It is clear that, for example, if (3) with a spread throughout Russia or the world, there is one person through multiple proxies or, most likely, different real users.
But when, for example, the region is Moscow + region, there is no specifics ...
Only on IP + browser and their combinations to watch and guess on the tea thick ...
We thought to make a binding via SMS, but Wirth. there are always numbers on sale
Verification code by SMS or send soap if you suspect - well, you can also transfer this information to each other (well, that is, only if access is difficult)
How can you track such user behavior or at least complicate it as much as possible?
Thanks for any hints

Answer the question

In order to leave comments, you need to log in

5 answer(s)
V
Vladimir S, 2017-11-09
@IdFox

if the access is paid, then block the user in case of suspicion, and let him prove that he came in.
on the other hand - if he paid for access / content - then formally he can use (view) it as he pleases (from any IP / browsers, etc.)
look on the internet there is a script - which quite accurately determines the user - fingerprintjs2 this one is like

K
Kirill Gorelov, 2017-11-09
@Kirill-Gorelov

I would do the following.
1. I added a little authorization module on your site. Also checked, whether the user is authorized or not. If authorized, then do not let him in until he logs out of the account.
--Not a great option, but still worth a try.
2. Authorization via SMS. Yes, it can be costly, but it works.
First of all, I would start from the first option.

K
Kuzma Shpagin, 2017-11-09
@demon72

Are people really different? Or maybe I came from home - this is one SP, I'm going to work in a bus / metro / car, Internet mobile - another SP, I'm sitting at work - the third SP. And the SP dynamics and, as it were, are not always the same. Yes, and the IP can be issued differently. And about the browser ... At home, chrome, in mobile Yandex / native phone, at work firelis / chrome / Yandex / ie (depending on what is open), for example.
By the way, it determines me from the Internet mob in a neighboring city, although it is 500 km away. Here you have 3 people already. This must also be taken into account.
And so it is not clear why you need it. I don't think the content is so valuable to be parsed or copied. Moreover, in addition to your content, there is enough in public.

B
Bjornie, 2017-11-09
@Bjornie

Firstly, it is worth specifying in the rules for using the service a prohibition to transfer the username and password to other people. Those. upon registration, the person agrees to this.
Notifications: Next, you can send notifications that you have suspicions of violating the rules for using the service. Here you can easily indicate the reason. But you must be sure that it is.
Social networks: Still, as an option, you can make authorization through the social. networks. And if the account is registered on the social. network, then the warehouse is unlikely to give access to it. Although there is an option that the account will be fake.
Sessions: Prohibition of simultaneous sessions, if a new session is authorized, then delete all others.
SMS and sessions:SMS authorization and one active session. If a lot of people sit on the pool, then this will make it difficult to use the service due to the constant need for authorizations.
The maximum number of different connections : determine the type of client: its browser, IP, in general, any trace. And if there are many such sessions (p. sessions) in N time, then this is a chance to send a notification (p. 1).
In general, the first point is the most important, you can think further.

R
Renat Iliev, 2017-11-09
@IzeBerg

Give access to the site only with 2 active sessions: 1 mobile, 1 PC. Well, you can add another PC session, for example, a working PC. If more is activated, disable the oldest session.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question