Live data from Hacker News

Botspam apocalypse

memex.marginalia.nu

191–200 of 358 posts

Re: Botspam apocalypse

#191
Does anyone know how google/linkedin manage to block bots who are using SSO?

Trying to login to a linkedin account using a google account from an automated browser(like puppeteer+puppeteer-stealth or fakebrowser), will open a white empty window instead of the normal google login window, I could be a limitation of those libraries, but I doubt it, smells like something they detect, maybe looking into might lead some interesting insights on how to limit modern bots.

Re: Botspam apocalypse

#192

Earlier quoted context omitted.

It depends on your audience and regions you're most interested in. But if you're aiming for the EU, gcore labs may be interesting. Akamai is not bad, but a bit enterprisey - I don't think they even had an official api the last time I used them?

None of those are free, though.

If you're not paying, what's the product they're selling?

Re: Botspam apocalypse

#193
I run a website for a small company. The site has been around since the mid-1990s, and bots are a minor annoyance, but not a problem.

We also use some simple heuristics to reject obvious bot traffic.

One of the simplest is to have a form field that is hidden via CSS. Humans don't see it and it stays blank. Bots fill it in.

Bots tend to fill in every form fields with random garbage, even checkboxes. Validating checkboxes rather than checking they have a value is another good way to detect bots.

Many bots have a hard time with CSRF tokens in hidden fields.

Many bots also don't handle session cookies properly. If someone submits a registration form without an existing session, we reject it. (So we don't get as far as checking the CSRF token.)

After a certain number of failed attempts to register or login, we block the IP for a period of time.

Re: Botspam apocalypse

#194

"The rest are forced to build web services with no interactivity, or seek shelter behind something like Cloudflare, which discriminates against specific browser configurations and uses IP reputation to selectively filter traffic." Interactivity is not a must-have. The world's first general purpose computer, ENIAC, was not built for "interactivity". It was built to calculate ballistic trajectories, which were otherwis…

>>> Automation is not reserved for those providing "services". It also should be available to those using them. Yes ! I call this software literacy. And yes - no matter how cool the JS on a major site, the fact that the sites goals are to keep me there and clicking and my goals are to get what I want with minimal action are in conflict. I would suggest that bots are actually not a problem. For most things I would lik…

> Telling me as and when that I need to visit the dentist

Isn't that simply your calendar? Sure, you want it automated; but it doesn't need internet access, it doesn't need to crawl or search, I don't know why you refer to it as a 'bot'.

To my mind, the idea of personal 'bots' was that you could give it some general instructions such as "Let me know when the content at any of these URLs changes", and then leave it running. Were they also called agents?

Re: Botspam apocalypse

#195
> There has been upwards of 15 queries per second from bots. There is just no way to deal with that sort of traffic, barely even to reject it.

I don't really understand, is that a lot? 15qps does not sound like a lot, especially for a blocking/rejection function.

Re: Botspam apocalypse

#196

For my forum with 500k users a month I just added a registration captcha related to my niche. E.g. for a Dark Souls forum it would say "what game is this forum about?" And if you got it wrong the validation would include "tip it's just two words D rk S*ls". This reduced spam by over 99% and didn't annoy people with recaptcha. If someone was unable to get past that captcha (it still happens I have logs!) I figured the…

re: someone was unable to get past that captcha - this reminded me a story I heard back in ICQ times about some human who couldn't pass anti-bot question: "What planet do we live on?"

Fair enough… one can only speak for oneself, after all.

Re: Botspam apocalypse

#197

> If Marginalia Search didn't use Cloudflare, it couldn't serve traffic. There has been upwards of 15 queries per second from bots. 15 RPS is very far from an apocalypse.

It's bad if it's your dead-average Wordpress site that has 10 PHP workers, each page load being >1s. Easy DoS.

Yeah but WordPress is an extreme example. Every time a WP blog is posted to HN without a static-page-ifier (caching layer that basically turns the dynamic pages into static ones), it dies within minutes. Normal software doesn't seem to have that problem.

I traced it once, and I got to admit there was not an obvious bottleneck (this was 2015 or so). Just millions upon millions of calls into deeper and deeper layers for things like translations or themes. Wrapping mysql_query in a function that caches the result (to avoid doing identical queries) helped a few % I think, but aside from major changes like patching out the entire translation system for single-language sites, I didn't spot an obvious way to fix it. You'd need to spend a lot of time to optimize away the complexity that grew from suiting a million different needs, contributed by thousands of people across many years.

Re: Botspam apocalypse

#198
post #21

I wonder if proof-of-work would help. Suppose every form submission requires an expensive calculation, calibrated to take about 1 second on a typical modern computer/smartphone. For human users, this happens in the background, although it makes the website feel slower. But for bots, it dramatically limits how many submissions each botnet host can make to random websites.

This is an old idea known as hashcash. https://en.wikipedia.org/wiki/Hashcash

Newer variations (such as argon2) are tunable so you can include memory footprint and cpu-parallelism. There also are time-lock puzzles or verifiable delay functions that negate any parallelism because there's a single answer which can't be arrived at sooner by throwing more cores at the problem.

Re: Botspam apocalypse

#199

"The rest are forced to build web services with no interactivity, or seek shelter behind something like Cloudflare, which discriminates against specific browser configurations and uses IP reputation to selectively filter traffic." Interactivity is not a must-have. The world's first general purpose computer, ENIAC, was not built for "interactivity". It was built to calculate ballistic trajectories, which were otherwis…

Some part of it is loss in the process.

I run a website about immigration. I'd love to reinstate comments and get valuable feedback from people who just tried my advice. Bots just make it too time-consuming.

Re: Botspam apocalypse

#200
I­ g­e­t­ p­a­i­d­ o­v­e­r­ 92 D­ol­la­r­s p­e­r­ h­o­u­r­ w­o­r­k­i­n­g­ f­r­o­m­ h­o­m­e­ w­i­t­h­ 2 k­i­d­s­ a­t­ h­o­m­e­. i­ n­e­v­e­r­ t­h­o­u­g­h­t­ i­'d­ b­e­ a­b­l­e­ t­o­ d­o­ i­t­ b­u­t­ m­y­ b­e­s­t­ f­r­i­e­n­d­ e­a­r­n­s­ o­v­e­r­ 15k­ a­ m­o­n­t­h­ d­o­i­n­g­ t­h­i­s­ a­n­d­ s­h­e­ c­o­n­v­i­n­c­e­d­ m­e­ t­o­ t­r­y­. t­h­e­ p­o­t­e­n­t­i­a­l­ w­i­t­h­ t­h­i­s­ i­s­ e­n­d­l­e­s­s­... S­­i­­m­­p­­l­­y g­­o t­­o t­­h­­e B­­E­­L­­O­­W LINK a­­n­­d s­­t­­a­­r­­t y­­o­­u­­r w­­o­­r­­k..

EDIT: bad joke but maybe someone will get a chuckle.

Post reply on HN