It's not ideal, but past a certain point, as a saas operator you're caught between a rock and a hard place. The best I've been able to come up with is a "do you think this is a mistake" button, which spammers tend to not click.
Still not nice to know that I'm treating people like second-class Internet citizens. At the same time, my available time is extremely limited, so lessor or two evils - for me - it is.
I think it's really important to have an "appeals process." Many of our customers don't use Sift to block users unilaterally, but rather to ask for further verification. For example, if the Sift score is high, they might call the user to verify their identity. That's a great way to get rid of most of the fraudsters, while giving good users a "way out" for those cases where the algorithms get it wrong.
Do you have anything to say to those users, as an operator of a large SaaS provider that deals with fraud/spammers daily?
A quick point of order: I am definitely not "an operator of a large SaaS provider" ;)
Now, affected users can get in touch directly with me - the owner of the website - and I generally respond in a matter of minutes. That's way better than a lot of the big companies out there, but I recognise it's a result of my small size.
I agree that it sucks for the legitimate users, but for reasons I won't go into, the site in question is never going to scale to anything mass market.
Also, as I said, my time is limited, and I'd much rather be spending my time on stuff that improves services for users and makes a better product than on writing systems to tell the difference between spammers and legitimate users. Remember, my scale is tiny and, frankly, if I lose a few customers because of this, that's money well spent.
It sounds like the person I'm asking is doing the exact same thing, but they haven't scaled up to the tens of billions yet. I'm asking how he intends to scale his model.
Heh, as I alluded to in my reply to your other comment, for TweetingMachine at least, I have zero intent of scaling; tt's a small tool, and will remain a small tool (can't even remember if I've done any work on it in the whole of 2012) whilst I focus my energies elsewhere.
So, being quite so harsh was a means to an end. At the same time, if I experience abuse of any of my other services, it'll definitely be a marker I'll use for more manual investigation.
That's a huge issue, and it's part of our motivation to use machine learning to combine lots of signals. It's not fair to the legitimate users in Nigeria and other countries to be blocked entirely from booking airline tickets, posting blogs, or booking reservations, but that's the status quo. It's hard to blame the site owners; given the number of attacks, and the difficulty of building a good detection system, it's the best they can do given the time and resources available.
Our hope is that by pooling data and technology across all sites on the internet, we can build a better system that keeps the bad users out without causing "collateral damage" and harming perfectly legitimate users.
And in response to the grandparent, we absolutely look at timezone! It's a great signal. We've found 3am is the most popular time to create a fake account. But note that creating an account at 3am, all by itself, is not enough to condemn you. It has to be combined with many other behavioral signals.