Revealing creator emails to web scrapers

Summary

Whose smart idea was it to reveal creator email addresses to the entire public internet without any form login required to see the address? And even when logged in the email should not be given away without completing a captcha and even then it should not be in plain text to make it computationally taxing to scrape creator emails. This design decision just shows the blatant lack of any form of foresight on part of the developers who made the website. Ever since I registered with fab.com I get tons of spam, some of it very sophisticated (ingesting images of my models) asking me to go off-side and register with a 3rd party ā€˜service’ that will steal my 3D models. The point of these scams is to extract work from creators.
In my opinion, you should completely remove the email address from ā€˜https://www.fab.com/sellers//about’ and make it so that if someone wants to contact a creator they have to log in and use the messaging system within fab so the spam is visible to the website (it can be blocked).

What type of bug are you experiencing?

Other

URL where the bug was encountered

Steps to Reproduce

Open a private tab in any browser, go to any creator’s about page, say:

And you can see the full email address displayed. Not even a passing attempt is made to obfuscate this private information from web scrapers. How is it possible that since 2009 Google has a captcha service to obfuscate email but here, purely by design decision you just show the full details to the entire world?

Expected Result

Your email should not be displayed. If you do have to display a creator’s email, make it so an outsider has to create a fab.com account to see it at very least.

Observed Result

You guys have absolutely zero foresight, no understanding of cyber-secutiry, and of how scammers obtain your information for phishing purposes, therefore you allow the /about field to display an un-obfuscated email address of every creator. For comparison, on say YouTube it has to be manually enabled by the creator allowed, and even then it’s hidden behind a captcha.

Platform

Firefox the problem is not specific to a platform. It’s a design issue on part of engineers who made the website.

Operating System

Pop OS (Linux). The problem is not specific to an operating system. I’m just an engineer so I use Linux, but you can reproduce the issue on any platform.

Upload an image

Additional Notes

Make it optional to display your email address on the /about page and off by default. If it’s enabled, obscure the email so that it’s not easy to programmatically extract - present it as an image, replace the @ with a random symbol, add visual noise, create a javascript computational challenge in the user’s browser, ask for a captcha to be filled twice, rate-limit the request by making the user wait, maintain a ban list of IP addresses.
Furthermore there is the problem of creator pages https://www.fab.com/sellers/ not having any form of scraping protection like a computational challenge inside the browser, progressive lazy loading. I had people scrape all of the thumbnail images and then present me with their own websites with my portfolio on them.
You can easily stop the revenue stream of scammers who send phishing emails to creators to extract work from them and re-sell their models.

STOP MAKING IT EASY FOR SCAMMERS TO FIND YOUR EMAIL

As a trader on Fab, my understanding is that EU law requires my business contact details, including my email address, to be publicly accessible. For that reason, I use a separate public-facing email address with filtering and spam protection enabled. I would still welcome stronger anti-scraping measures, but I do not think Fab can simply hide trader contact details.

If you hide all contact information and personal data, how can you communicate with buyers?
The proliferation of online scammers has always been rampant.

But you also have to respect your buyers. I often get confirmation via email before purchasing. There’s just no convenient system within the Fab itself that could replace that.

The old marketplace used to have an ā€œask a questionā€ option. Now, it’s only available through a forum post, and even then, few people even know about it, and many don’t even create one.

Yes, I wonder how I can communicate with you now without giving you my email address. It must be some form of magic. I also wonder for 26 years how on online forums and such you could private message users to tell them something, but we can’t replicate that feature with current technology and therefore have to display the user’s email address to the entire public internet without any form of obfuscation from programmatic abuse.

I expect them to have a messaging feature within the website rather than going off-platform to communicate. This way users who spam can be banned.

I don’t mind my email being displayed to actual buyers. The problem is that

  • it’s displayed EVERYONE on the public internet
  • it’s displayed regardless whether they have an account on the website or not
  • there is no captcha to see the email, therefore both PEOPLE and BOTS can see your address.
  • no even token attempt is used to obfuscate the email from programs scraping websites like presenting the text as an image, making it computationally taxing for the browser.

I hate posting on the internet because all of the corporate apologists from Reddit come out of the woodwork defending things that are obviously wrong. I wonder why the reCAPTCHA Mailhide tool came out around 2007, it must have been because web users like to play mini-games - not because 80% of the traffic on the internet consists of bots.

YouTube hides your creator email behind a captcha.

1 Like

That is true, but YouTube is not an equivalent comparison. A creator’s business-enquiry email on YouTube is optional, whereas Fab must display contact information for verified traders selling to EU consumers.

Hi @blenderUserSkfab,

Your seller profile shows a contact email to buyers because sellers on Fab are responsible for providing customer support, per the Fab Distribution Agreement. This also helps meeting transparency obligations under applicable regulations.

During profile setup, you’ll see a notice that this contact info is shared publicly.
We’d recommend using a business email rather than a personal one for this.

How you show the contact details matters: you don’t have to put it in plain text visible without login for bots to scrape. I would make it so that if you view the contact page and you don’t have an account on Fab then it says ā€˜please create an account on Fab to see the contact details’. That would cut out like half of the spam. Furthermore, while logged in, if a user tries to go to 100 contact pages in, say 10 minutes, I would rate-limit them, make the page load slower. Next I would make a javascript computational challenge in the browser of the user, so that if they load the contact page, their computer has to work for it (which means automation tools will be computationally taxing to run). Then there would be a button to reveal the email address. When you click it you should have to fill in one captcha or two (some random number) so it’s harder to write a machine vision program to beat this. Finally when the address is revealed it should be revealed as an image not plain text with some randomness to it like visual noise to confuse bots.

A comment on a different post, from 6 months ago. I have been getting a lot of spam and phishing emails, every single day, since emails were made public like this. On a good day I get 3-4 emails.

Yes, sellers are responsible for providing support to customers, but seller emails aren’t shared only with customers/product owners or logged in users, they are shared publicly with the internet so unregistered visitors and bots can directly copy/scrape them, which naturally increases spam and phishing, and then we get this yellow warning on seller profiles every couple of months saying ā€œWe’re currently observing a phishing campaign targeting Fab creators.ā€ā€¦ I’m genuinely not sure how repeating such a warning could help with anything.

Company registration details + an email that is revealed only to customers or logged in users is more than enough to meet applicable regulations worldwide.

As mentioned in my old comment, this was never a problem on the UE Marketplace.

1 Like

I agree. It is also in a way - a double standard.

When I, as a registered signed-in user update my 3D models and upload them to Fab, I have to complete a captcha, which shows Epic already has working tools to block automated spam when it serves them.

But when it comes to protecting me as a creator from programmatic spam, those same tools are not being used: the email is displayed to everyone on the internet regardless whether they are a user or not and there is no captcha to see it.

This just shows the priorities of people running the website. Also there should be some form of programmatic challenge in the user’s browser for viewing someone’s portfolio if they are not a logged in user - so a program can’t just scrape all of the 3D model images and names.

I also bet there is no hashing (fingerprinting) of the content.


@ElenaNizhnik
We are responsible for after-sales service, sure, but you are responsible for our data. CGTrader doesn’t share our email addresses; they have an internal messaging system on the site, which can actually be useful in the event of a dispute with a buyer.
Shirking all responsibility except for cashing the check—long live the modern world.
And now here I am chatting with an AI that gives me completely useless, irrelevant answers without actually engaging with the topic. Long live the future.

1 Like

Here’s a scam from this morning. The links upon inspection reveal a completely unrelated site, even though they look like they are pointing to Fab.

There are no real users on the internet any more, just bots talking to other bots to pretend someone actually engages with the content, to provide social proof.

Again, I’m repeating this because it will get buried between AI spam: it’s kind of funny how Epic protects itself from bots uploading models with captcha upon captcha but not us, the creators and our contact details. Anything and anyone on the public internet can get our email address, they don’t need to have an account or be a human. A program can just go through all creator profiles and scrape all contact details, then hurl spam designed to hijack accounts. Make sure you have 2-factor authentication set etc.

And finally, like on Reddit (the worst website on the internet), whenever you ask a legitimate question, all you get is real life NPCs and bots derailing the discussion thread by attacking straw-man arguments. On the rare occasion that I interact with people who buy models from me, I enjoy that interaction, because it isn’t another machine pretending to be a human and I’m genuinely interested in what they have to say and how they use the assets I create. Protecting a creator’s email address from spam bots by putting it behind a captcha has nothing to do with the artist’s willingness to interact with their audience.