Live data from Hacker News

Botspam apocalypse

memex.marginalia.nu

311–320 of 358 posts

Re: Botspam apocalypse

#311
post #304

The only real solution to the abuse of anonymous protocols is to stop using anonymous protocols and use protocols where clients can be held accountable. But that's politically nonviable in the West.

I don't see any good reason why people can't be allowed to remain anonymous while still allowing website operators from taking measures to stop bot abuse. CAPTCHAs can already stop many bots. Other commenters have also mentioned that things like Proof of Work systems and micro-transactions could also stop bot abuse. These don't necessarily require giving up anonymity.

It's not just bots, it's troll farms as well which are "real" people destroying public discourse in bad faith.

Re: Botspam apocalypse

#312

> There has been upwards of 15 queries per second from bots. There is just no way to deal with that sort of traffic, barely even to reject it. I don't really understand, is that a lot? 15qps does not sound like a lot, especially for a blocking/rejection function.

It's 15 search queries per second, not requests per second. RPS is usually 10-20x higher.

But you said "barely even to reject it", rejecting 15 QPS should not be heavy on any resource, right? Or is the actual problem identifying the bot traffic?

Re: Botspam apocalypse

#313

End game: everything runs on US-owned services, and all users need to identify to be allowed to even raise a finger, so that "bad actors" can be kept out. All while we blame Russia and China, and say that their spambots and evil actions forced us to do this.

This actually makes sense. Or, at the very least, it wouldn't surprise me.

Another end game: some sort of ID is required to use anything (that ID being a local phone number, which can be tracked down to you).

Re: Botspam apocalypse

#314
post #290

Earlier quoted context omitted.

I'm not very familiar with all the workings of HTTP/2.0 - why would it break bots? Assuming no CloudFlare type protection, does it somehow stop someone from using curl to get (non-JS generated) content? Does it thwart someone accessing the site from something like playwright/selenium?

> I'm not very familiar with all the workings of HTTP/2.0 - why would it break bots? There's a lot of outdated garbage bots out there. Not using HTTP/2.0 is also often the default with various HTTP libraries.

So it just comes down to bot software not being compatible with HTTP 2.0 rather than any sort of HTTP 2.0 specific mechanism/feature?

Re: Botspam apocalypse

#315

While clearly bot spam is on the rise, we need to be very careful on how we choose to deal with it. Cloudflare has already introduced "proof-of-Apple" [1], where proven Apple devices get special treatment, bypassing captchas. Later we might see websites that are only accessible via Google, Microsoft, or Apple devices. If we continue down this path, we'll end up with a social credit system ruled by big tech. [1]: http…

We basically already have "social credit" systems, we just call them anti-fraud/anti-spam/reputation scores.

Re: Botspam apocalypse

#316
post #304

Earlier quoted context omitted.

I don't see any good reason why people can't be allowed to remain anonymous while still allowing website operators from taking measures to stop bot abuse. CAPTCHAs can already stop many bots. Other commenters have also mentioned that things like Proof of Work systems and micro-transactions could also stop bot abuse. These don't necessarily require giving up anonymity.

It's not just bots, it's troll farms as well which are "real" people destroying public discourse in bad faith.

Website operators could still take measures to stop abuse from troll farms as well while still allowing people to remain anonymous. A website operator like Twitter for instance could perhaps require users to make a small micro-transaction before allowing someone to make a post. Some equilibrium for the cost of a post could probably be found where most legitimate users would still be willing to pay that cost but most troll farms would not.

Re: Botspam apocalypse

#317

I work in this space at a company you've heard of - even at our scale and with our resources the proportionally larger attack incentives mean we are constantly firefighting. > The other alternatives all suck to the extent of my knowledge, they're either prohibitively convoluted, or web3 cryptocurrency micro-transaction nonsense that while sure it would work, also monetizes every single interaction in a way that is mo…

Anyone aware of any major platforms taking this approach? The Postal Service? Sure, there's junk mail, but imagine how much junk mail there would be if it were delivered for free. It wasn't until phone calls became so cheap as to be "unlimited" that we ended up flooded with billions of junk calls. Microtransactions (non-crypto, thankyouverymuch) would solve a certain number of today's problems.

Let's finally implement HTTP 402

Re: Botspam apocalypse

#318

It's annoying for sure. I deal with abuse at a large scale. I'd recommend: - Rate-limit everything, absolutely everything. Set sane limits. - Rate-limit POST requests harder. Preferably dynamically based on geoip. - Rate-limit login and comment POST requests even harder. Ban IPs that exceed the amount. - Require TLS. Drop TLSv1.0 and TLSv1.1. Bots certainly break. - Require SNI. Do not reply without SNI (nginx has 44…

> - Rate-limit everything, absolutely everything. Set sane limits. This breaks when multiple users are behind the same IP. I've seen services fail even in classroom, because the prof did something and a few tens of students followed (captchas everywhere).

Yup. This happened to us when we had rate limiting turned on our sites and ran off-site events at hotels, for example - then the hotel's IP got temp banned and our sales engineers would complain, rightfully so.

Re: Botspam apocalypse

#319
post #316

Earlier quoted context omitted.

It's not just bots, it's troll farms as well which are "real" people destroying public discourse in bad faith.

Website operators could still take measures to stop abuse from troll farms as well while still allowing people to remain anonymous. A website operator like Twitter for instance could perhaps require users to make a small micro-transaction before allowing someone to make a post. Some equilibrium for the cost of a post could probably be found where most legitimate users would still be willing to pay that cost but most…

Are you serious? The problematic troll farms are the ones backed by states and multinational corporations. Gating speech behind money only makes the problem worse.

The correct approach is to deanonymize reasonably "public" online behavior. This is the only way to hold abusers accountable, and, ironically, democratize free speech.

1 person, 1 voice.

Not 1 rich person, 100 troll accounts.

Re: Botspam apocalypse

#320

It's annoying for sure. I deal with abuse at a large scale. I'd recommend: - Rate-limit everything, absolutely everything. Set sane limits. - Rate-limit POST requests harder. Preferably dynamically based on geoip. - Rate-limit login and comment POST requests even harder. Ban IPs that exceed the amount. - Require TLS. Drop TLSv1.0 and TLSv1.1. Bots certainly break. - Require SNI. Do not reply without SNI (nginx has 44…

> - Rate-limit everything, absolutely everything. Set sane limits. This breaks when multiple users are behind the same IP. I've seen services fail even in classroom, because the prof did something and a few tens of students followed (captchas everywhere).

Black hats always find ways around rate limiting, and that's why they are more prevalent than actual users. People can literally run click farms with cheap 4g cell phones that artificially pump anything they want without consequences, while authentic posters that simply run 2 necessary accounts are penalized if they post regularly.

The only real way to properly police Internet communities is to keep them smaller so that botting is more obvious, and to involve carefully managed moderation. Reddit tried this, but also lost track of the human factors involved and now moderators collect side money and promote their own posts artificially.

The main problems facilitating the surge in bots are shammy creator funds and all the other measures sites take to boost their profit and market dominance. They have grown far too big and can no longer effectively manage their user bases effectively. Things weren't meant to be this way at all, the excessive quest for market dominance and profit has thoroughly corrupted freedom of info online in business, now many users are also following the same road map.

Post reply on HN