Live data from Hacker News

So Reddit has decided that plain HTML is unsafe

cole-k.com

561–570 of 681 posts

Re: So Reddit has decided that plain HTML is unsafe

#562

As somebody who did plenty of scraping for his own little projects, lets just say that reddit their security concerns are just PR for "we do not want to keep supporting old.reddit". While yes, you can not simply scrap new reddit as easily as a pure html scraper is cheaper to run. And while the new reddit its js "slow down" scraping as it need to run over a headless browser. Do you slow scraping down a lot? No. Becaus…

> "we do not want to keep supporting old.reddit" the second old.reddit goes is the second I stop using that site it's already very obviously chock full of slop and AI bullshit, with some subs having long unavoidable lists of "your post was removed because you did not verify" trails that imply that automated posters found a thread and went hard but add in privacy crushing bs -- no reason to be there anymore. Back to o…

It's also like the only place left on the internet to reliably find real people reviewing things with real opinions.

Re: So Reddit has decided that plain HTML is unsafe

#563
post #315
post #288

Earlier quoted context omitted.

I'm a moderator on a moderately popular and active subreddit, and I can assure you that there is an unreasonable amount of bot activity on reddit. They range from just spam (usually obvious) to bulk astroturfing. We try to stop what we can, but plenty gets through.

Any ideas to mitigate?

Inside of Reddit itself? Not with the tools we're given from Reddit. We know Reddit has internal tools to block spam/bots, so I believe what we see is the most sophisticated ones (they're not too sophisticated mostly, but they're not the zero effort bulk spam that reddit catches easily).

Something that would make things far easier for mods would be if the posters hashed IP was shown/made available to mods. Thats mostly for more localized bad actors/astroturfers and not large spam/scam rings with proxy networks.

Things we've done that have made a difference with the tools we've got from Reddit:

1) we don't allow new accounts or ones with negative accounts to post in our subreddit

2) any posts that match criteria or hit the front page are automatically put in a mode where you must have a positive subreddit karma over a threshold to post. This helps filter out brigading and low effort shit posting from front page plebs

3) we're using a reddit app that allows us to remove posts from people that have posted in identified subreddits. Right now we're just experimenting with this and we're in a data collection mode, but we can see that the people its catching (while some of our most prolific posters) are also some of our most problematic posters, so I think we're going to go from data collection to just straight up having the bot remove comments from people that post in those troublesome subreddits.

Re: So Reddit has decided that plain HTML is unsafe

#564

Earlier quoted context omitted.

My mother tried to buy something on Amazon yesterday. It wouldn't let her check-out until she'd entered a code sent via WhatsApp. Which she doesn't have and doesn't want. She'll be buying her tat on eBay in future. I dream that Amazon will lose lots of sales and backtrack, but I don't suppose they will.

Are you sure it was actually via whatsapp, and not just a six digit code sent via regular SMS to the phone number on record for her account? It's possible whatsapp on her phone has simply hijacked the SMS client functionality and set itself as the default.

If I forget to pause my VPN before going to Amazon's website, I can't log in with just username and password, I get a page telling me they've sent a code to WhatsApp (which I don't have) with a button to click if I want an SMS instead. Clicking that button never works (error message that I've 'requested too many OTPs') but opening the Amazon app on my phone shows a modal saying 'someone who knows your password is trying to log in... etc' and asking me to approve. They're definitely trying to use WhatsApp by default for sending verification codes.

Re: So Reddit has decided that plain HTML is unsafe

#565

I don't buy the “scraping” protection when appending .json to any reddit URL still gives you the data. Example: https://www.reddit.com/r/whatisit/comments/1v3mzl6/what_is_t...

They officially started blocking json access awhile ago, it broke all the apps for viewing reddit without an account (RDX, Stealth, Geddit). I'm not sure on the exact details of what is and isn't still accessible, I just know it broke a lot.

Re: So Reddit has decided that plain HTML is unsafe

#566
post #536

I always wondered how Reddit justified the old.reddit effect. If your new design is so awful that a large percentage of users refuse to use it, and prefer the (more performant!) version from more than a decade ago, shouldn't that be a strong signal that you've made some mistakes? Why not try making the new version more appealing by investigating and fixing the issues that cause people to use the old one. I guess cred…

I mod a reasonably popular subreddit for work, and, looking at the stats as a die hard old reddit user, I was floored at how few of us there really are.

Re: So Reddit has decided that plain HTML is unsafe

#567
post #536

I always wondered how Reddit justified the old.reddit effect. If your new design is so awful that a large percentage of users refuse to use it, and prefer the (more performant!) version from more than a decade ago, shouldn't that be a strong signal that you've made some mistakes? Why not try making the new version more appealing by investigating and fixing the issues that cause people to use the old one. I guess cred…

Reddit redesign strikes me as a convenient excuse to enforce infinite scrolling by a company looking to IPO.

Reddit has already IPO'd

Re: So Reddit has decided that plain HTML is unsafe

#568
post #536

I always wondered how Reddit justified the old.reddit effect. If your new design is so awful that a large percentage of users refuse to use it, and prefer the (more performant!) version from more than a decade ago, shouldn't that be a strong signal that you've made some mistakes? Why not try making the new version more appealing by investigating and fixing the issues that cause people to use the old one. I guess cred…

I think there is a possibility that this is simply someone's ego trip that has evolved into a monster. One "nepo hire" in the correct position of power is all it would take for something like this to happen. I believe that's what occurred with the GitHub refactor too. That happened way too early to be attributed to the AI/Copilot stuff.

If business was truly driving the ship a lot of these bad ideas would have been killed and buried on day one. The React tribalism was unbelievably hot for a while there. Not going along with it was a great way to not get hired at a lot of places. This is still the case.

The reason the business tolerates this bullshit is because they are so afraid of losing certain people. I'm watching it happen in real time for two smaller startups right now. The business would be much better off if they simply fired the "revolutionaries" right now (i.e. today without warning or preparation), but they've become convinced by the propaganda of these very same people that their removal would be catastrophic to the business. So, these people get to torture all of the employees and end customers with their ridiculous schemes (ego trips) and the business covers up for them. As long as everyone survives to the weekend, no one seems to care enough to change anything. The customers in this case are other businesses who are also sucked into the scheme (they don't want to look stupid for signing a contract), so the issue propagates ever deeper.

Re: So Reddit has decided that plain HTML is unsafe

#569
post #536

I always wondered how Reddit justified the old.reddit effect. If your new design is so awful that a large percentage of users refuse to use it, and prefer the (more performant!) version from more than a decade ago, shouldn't that be a strong signal that you've made some mistakes? Why not try making the new version more appealing by investigating and fixing the issues that cause people to use the old one. I guess cred…

I mod a reasonably popular subreddit for work, and, looking at the stats as a die hard old reddit user, I was floored at how few of us there really are.

Numbers please

Re: So Reddit has decided that plain HTML is unsafe

#570
post #536

I always wondered how Reddit justified the old.reddit effect. If your new design is so awful that a large percentage of users refuse to use it, and prefer the (more performant!) version from more than a decade ago, shouldn't that be a strong signal that you've made some mistakes? Why not try making the new version more appealing by investigating and fixing the issues that cause people to use the old one. I guess cred…

Enshittification is the answer. Old Reddit doesn’t make any money. Users block what few ads there are and it’s free so there’s no subscription revenue otherwise. New Reddit is full of ads plus social media engagement-bait garbage. New Reddit makes money. Reddit the company wants people to use New Reddit. So why does Old Reddit still exist? Because that’s where the content creators live! Old Reddit is a cost centre bu…

I wonder how new Reddit users manage to post nowadays, given that many default subreddits have karma restrictions. You need esoteric knowledge, like knowing that /r/askreddit allows you to build initial karma via comments, to be able to do that.
Post reply on HN