Botspam apocalypse
21–30 of 358 posts
Re: Botspam apocalypse
#22This kind of botspam is usually pretty easy to address with redbean using the finger https://redbean.dev/#finger and maxmind https://redbean.dev/#maxmind modules. The approach I usually recommend people isn't so much ip reputation, which can be unfair, but rather it allows you to find evidence of clients lying to you. For example, if the User-Agent says it's Windows with a language preference of English, but the TCP…
My laptop is lying all the time. I change my UA, preferred language, my ip, mac and so on, because of tracking, terrible dev assumptions and personal preferences. Yet, I'm a very good web citizen. Because of this, I often have to solve the same captcha many times before it thinks I'm human.
Re: Botspam apocalypse
#23I wonder if proof-of-work would help. Suppose every form submission requires an expensive calculation, calibrated to take about 1 second on a typical modern computer/smartphone. For human users, this happens in the background, although it makes the website feel slower. But for bots, it dramatically limits how many submissions each botnet host can make to random websites.
Re: Botspam apocalypse
#24Does this extend to societies as well? One can think of a membrane that has selective permeability to ideas but resists antisocial actors and concepts. Alexander Bard has talked a lot about social membranics (it's a bit hard to search for).
As odious as the web3 charlatanry is, I'm starting to yearn anything that raises the transaction costs for the dumbest bots. I remember reading something about new ideas with distributed moderation at some point--maybe someone can refresh my memory.
Re: Botspam apocalypse
#25Re: Botspam apocalypse
#26I wonder if proof-of-work would help. Suppose every form submission requires an expensive calculation, calibrated to take about 1 second on a typical modern computer/smartphone. For human users, this happens in the background, although it makes the website feel slower. But for bots, it dramatically limits how many submissions each botnet host can make to random websites.
"mCaptcha uses SHA256 based proof-of-work(PoW) to rate limit users." https://github.com/mCaptcha/mCaptcha
I wonder why this approach hasn't been widely adopted?
Re: Botspam apocalypse
#27I wonder if proof-of-work would help. Suppose every form submission requires an expensive calculation, calibrated to take about 1 second on a typical modern computer/smartphone. For human users, this happens in the background, although it makes the website feel slower. But for bots, it dramatically limits how many submissions each botnet host can make to random websites.
Re: Botspam apocalypse
#28What is the reason behind bots spamming marginalia? What’s the motivation? What do they gain? I always wonder about these things.
Re: Botspam apocalypse
#29Earlier quoted context omitted.
"mCaptcha uses SHA256 based proof-of-work(PoW) to rate limit users." https://github.com/mCaptcha/mCaptcha
Nice! Yeah, mCaptcha looks like just what I had in mind. I wonder why this approach hasn't been widely adopted?
Allowing abusers to freely abuse would cost even more power than just forcing them to do the work.
Re: Botspam apocalypse
#30Secure Scuttlebutt[1] doesn't have a lack of moderation / spam issue and it is completely decentralized and without monetary fees nor proof-of work. Why can't centralized services do better?
[1]: https://ssbc.github.io/scuttlebutt-protocol-guide/#follow-gr...