Substack leaks the invite code in search engines

10 Likes

We might need some other way to verify who is and is not a subscriber. Anyone have any ideas?

2 Likes

Change the invite code and notify via direct mailing list? Not at all quick or convenient but a bunch of BCC emails would avoid that problem.

3 Likes

Does Locals and Substack allow for their admins to do a csv subscriber email export? If so, Lunduke could take it a step further and script assigning a unique code to each subscriber and emailing it to the address on file.

If not, I wonder if those platforms have some kind of API that could be queried to generate a code on a form on demand if they return something like subscriber=true

2 Likes

I know Substack does. Not sure about Locals.

Good catch. I’ll see what I can do about that.

8 Likes

Looks like Locals does too, at least as of 2020: How do I export member data? | Locals

1 Like

That was a good catch.
Do internet searches provide things secret things like invite codes frequently/sometimes?
If you’re going to give out some sort of secret code, is this something that you just have to consider and plan for?
Again, this is NerdWannabe asking.

2 Likes

Well I’m not completely sure about search engines, but there is a long and storied history of all sorts of secret keys, passwords etc leaking through code repositories and similar. Somebody in a company puts the key into the code, the company uses Github (or similar) to host their code repositories, for some reason the repositories are publicly available, and then somebody sees the key.

This is probably a variation on that theme.

4 Likes

We all love some ā€œfreeā€ OpenAI keys from time to time :woozy_face:

4 Likes

This has not been fixed yet.

Hey @lunduke

Can we get badges that stick to the names like the mods do?

3 Likes

Oh yeah, the lunduke badge.

(There is a newer one below which I think looks better.)

4 Likes

I might make it larger later. ĀÆ\_(惄)_/ĀÆ

Perfect, that’ll work!
All subscribers get that badge, excellent!

Would you want to further distinguish between subscribers that pay monthly/yearly/lifetime?

2 Likes

Changed it lol, it looked a bit odd with all that space. Here we are!

1 Like

I don’t really think we should as I found in another topic.

1 Like

Does discourse have custom ā€œrolesā€ that can have icons assigned to them like the ā€œmoderatorā€ roles has? This would be great to have the Lunduke logo head as the role badge for subscribers.

2 Likes

I’m pretty sure I remember custom badges being a thing you can add.

1 Like