This entry is old and may contain information that is not up-to-date.

Exposing the correct position for each round to the client is certainly not a good idea

You are currently exposing the correct position (lat, lng) for each round through the publicly visible api. There are alot of users and bots that are abusing this and I don't think it's even necessary.
The client doesn't need to know the correct position for the round, just validate the position on the server side. That woud probably eliminate 90% of the bots.



  • It also might be a good idea to require email verification, because you can create fully functional accounts, just by posting to a random email to /signup ...
    That makes botting even easier.

