Live data from Hacker News

Botspam apocalypse

memex.marginalia.nu

331–340 of 358 posts

Re: Botspam apocalypse

#331
post #325
post #285

Earlier quoted context omitted.

You could just decrease the timestamp instead of actually waiting.

I meant for general spammers who goes after tons of sites mostly blind. I agree it would not help for a targeted attack.

I'm already using this timestamp technique on my website and so far no bot operator has bothered trying to work around this. However even if some bot operator were to specifically target a website using this technique and try to decrease the timestamp, I believe you could still force a bot to wait by just changing the website to use something like a cryptographic nonce that includes a timestamp instead of just a simple timestamp that can be understood easily.

Re: Botspam apocalypse

#332

> If Marginalia Search didn't use Cloudflare, it couldn't serve traffic. Cloudflare is not the only CDN/protection. It's the most popular and the most evil one. You have a choice.

Why do you consider them to be "the most evil"? Their services seem to be completely fine in almost every regard, and their communication doesn't at all suggest that they might be evil.

They actively (including legally) protect groups which coordinate targeted abuse and swatting (basically murder attempts) https://twitter.com/stealthygeek/status/1485731083534667779

Re: Botspam apocalypse

#333
post #316

Earlier quoted context omitted.

Website operators could still take measures to stop abuse from troll farms as well while still allowing people to remain anonymous. A website operator like Twitter for instance could perhaps require users to make a small micro-transaction before allowing someone to make a post. Some equilibrium for the cost of a post could probably be found where most legitimate users would still be willing to pay that cost but most…

Are you serious? The problematic troll farms are the ones backed by states and multinational corporations. Gating speech behind money only makes the problem worse. The correct approach is to deanonymize reasonably "public" online behavior. This is the only way to hold abusers accountable, and, ironically, democratize free speech. 1 person, 1 voice. Not 1 rich person, 100 troll accounts.

Yeah, I'm serious. Even with Twitter, for example, currently allowing accounts to be created and posts to be made for essentially free, real accounts and posts still outnumber those of troll farms and bots from what I've seen. If those troll farms and bots actually had to pay, I imagine there would be far less. I also imagine that those troll farms and bots are less influential than real people. I believe that the endgame is that if a website operator takes enough measures to stop troll farms and bots, the operators of those troll farms and bots will eventually run out of resources and be forced to curtail their activity.

You're right that gating speech behind money could potentially be bad and make problems worse but I only offered that as one suggestion. Instead of or in addition to using money, you could perhaps make a system that uses some type of karma/reputation for instance. Those could still be done anonymously.

Re: Botspam apocalypse

#334

The only real solution to the abuse of anonymous protocols is to stop using anonymous protocols and use protocols where clients can be held accountable. But that's politically nonviable in the West.

Thanks god it's not. The right to anonymity is something we shouldn't lose.

Re: Botspam apocalypse

#335

I work in this space at a company you've heard of - even at our scale and with our resources the proportionally larger attack incentives mean we are constantly firefighting. > The other alternatives all suck to the extent of my knowledge, they're either prohibitively convoluted, or web3 cryptocurrency micro-transaction nonsense that while sure it would work, also monetizes every single interaction in a way that is mo…

Wasn't this the basis of bitcoin? Pre bitcoin, I remember some whitepaper suggesting that email clients should spend some minute amount of processing power solving a cryptographic problem for each email sent. The theory was that a legit client would barely notice, but a spammer would expend significant resources.

Re: Botspam apocalypse

#336

I wonder if a general solution could be to make the visit more computationally demanding to the visitor than to the host, e.g. some form of proof-of-work. I guess captchas already do that in some sense but they require the humans to do the work. Now the author above has stated they dislike the crypto route and I agree that the whole web3 idea is bs but what if in the case that spam of some form is detected by the ser…

post this above, but there is a pre-bitcoin whitepaper suggesting just this approach to solving email spam

Re: Botspam apocalypse

#337
> The other alternatives all suck to the extent of my knowledge, they're either prohibitively convoluted, or web3 cryptocurrency micro-transaction nonsense that while sure it would work, also monetizes every single interaction in a way that is more dystopian than the actual skull-crushing robot apocalypse.

Payment per request is the long term solution, but I completely disagree that it’s in any way dystopian. The trick is to set the fee so low that humans, who make few requests, aren’t really affected while bots, who make a large number of requests, become unprofitable.

It’s exactly the same solution as email spam: at a hundredth of a USD cent per email, spam emails would no longer be profitable while regular consumers would spend 10 cents per year (assuming they send 3 emails per day).

Re: Botspam apocalypse

#338

Earlier quoted context omitted.

> However for a small scale thing I'd gladly go visit at a face to face meetup to fulfill this type of validation. Even if it were 3 flights totalling 18 hours away? :) Or even just from one coast of the US to another...

Someone that far away shouldn't want my direct contact information to join a group. However there is a medium / large organization case, where each area has local 'chapters' or some other term for a small fragment of the larger group. In that case the local leaders each operate as a small group for their areas.

> Someone that far away shouldn't want my direct contact information to join a group.

An international group based on common interests isn't entitled to protect themselves in the same way?

Re: Botspam apocalypse

#339
post #289

Earlier quoted context omitted.

> The solution is real simple Uhhmmm, I beg to differ and so do a lot of very smart people with many more servers and users than you or I are likely to see. As with most 'Oh, its' Simple - Just Do XYZ' solutions there are often very good reasons for not doing the 'Easy/Simple/One-Liner' and here are a few with yours - Firstly - The '10 bux' could exclude a vast swathe of the poorest. Skipping a couple of Starbuck cof…

> Firstly - The '10 bux' could exclude a vast swathe of the poorest. Skipping a couple of Starbuck coffees vs. the local currency equivalent of whatever you are charging equating to a month's worth of food or being able to send at least one of your children to the local village school. I mean - your forum / site so you can gate it anyway you wish, I'm just pointing out that it could and would be exclusionary (perhaps…

Providing paid service doesn’t make one exclusionary of the poorest. You are free to give discounts or free service to vulnerable groups in exceptional circumstances, requesting a verification of your choice in place of a financial roadblock. While giving them status otherwise equivalent to that of regular paid accounts, you can still apply more sensitive monitoring procedures to them if you have grounds to expect false positives and abuse—good thing now you don’t have to do it with every account.

What being a paid service does make you is a player in a game with certain agreed-upon rules, by which your incentives are aligned with those of your customers. Giving your paying users the right of the ultimate vote (with their wallets), you in a way paint yourself into a corner where you can either act in their best interests or go broke. It matters less if you are a huge corporation (many revenue streams), and it doesn’t guarantee you won’t cheat and violate the rules (take my money and sell my data, why not!), but still as a user I find it a useful signal.

Re: Botspam apocalypse

#340
post #60
post #2

> They're a major part in killing off web forums, and a significant wet blanket on any sort of fun internet creativity or experimentation. > The only ones that can survive the robot apocalypse is large web services. Your reddits, and facebooks, and twitters, and SaaS-comment fields, and discords. They have the economies of scale to develop viable countermeasures, to hire teams of people to work on the problem full ti…

few edits I wanted to make but couldn't while HN was down: this comes to a question of intentions, right? Like are you trying to build a high-value community , or are you trying to make a billion-dollar company? Photrio or Pentaxforums is never going to sell for a billion dollars like Reddit, and that's not the kind of community that Reddit is trying to build. The highly-chaotic multithreaded model of Reddit/HN/etc i…

> The highly-chaotic multithreaded model of Reddit/HN/etc is directly designed to be impenetrable and chaotic, where everyone is just responding to everyone rather than having a "flow of conversation" in which everyone is involved.

What are examples of websites that maintain a flow of conversation while involving everyone without letting everyone reply to each other? Being able to reply directly to others while discussing a topic has been the norm at forums, and before those, mailing lists and BBSs. The clients/interfaces just got better over time at sorting/collapsing replies.

Whose got the forum where "everyone responding to everyone" doesn't happen?

Post reply on HN