Need help (forum spambot countermeasures)

Questions and comments
Post Reply
jacob
Site Admin
Posts: 8969
Joined: Fri Jun 28, 2013 8:38 pm
Location: USA, Zone 5b, Koppen Dfa, Elev. 620ft, Walkscore 73
Contact:

Need help (forum spambot countermeasures)

Post by jacob » Wed Sep 14, 2016 10:13 am

In the past couple of days the forum registration has been overrun by spam accounts. I suspect some perp figured out the secret answer to the Q&A based captcha, so I need some new ones.

The question needs to fulfil the following criteria:
1) Should be answerable by all real humans who want to register on the forum. This includes new humans too, so ERE history is not that useful.
2) Should not be googleable/answerable by some AI algo. (E.g. not: What does ERE stand for?)
3) Should have a unambiguous answer (single word). (E.g. not: What is a popular investment strategy?)
4) If possible, the question should also not be every human on the planet. (E.g. not: What is two plus two?)

These questions are actually surprisingly hard to come up with.

One example of what I've been using is "Which city does jacob currently live in?"

If anyone comes up with a good one, please PM me. That would be PM! Posting them below defeats the purpose.

ether
Posts: 164
Joined: Sat Nov 17, 2012 1:50 am
Contact:

Re: Need help (forum spambot countermeasures)

Post by ether » Wed Sep 14, 2016 11:13 am

Why not use google's captcha?
If this spammer is actually a member of the forum he can just update the answer.

jacob
Site Admin
Posts: 8969
Joined: Fri Jun 28, 2013 8:38 pm
Location: USA, Zone 5b, Koppen Dfa, Elev. 620ft, Walkscore 73
Contact:

Re: Need help (forum spambot countermeasures)

Post by jacob » Wed Sep 14, 2016 11:29 am

I don't have a choice of specific captcha. The 3 different kinds I do have access to are rather useless and usually result in much more spam accounts. I think what happens is that spammers set up a third site that gets a lot of traffic (e.g. porn, quiz tests, page rank checkers, ) ... and then have some random unrelated human solve the captcha that the ERE forum presents. It's pretty clever.

sky
Posts: 725
Joined: Tue Jan 04, 2011 2:20 am
Contact:

Re: Need help (forum spambot countermeasures)

Post by sky » Wed Sep 14, 2016 11:44 am

What is the airspeed velocity of an African swallow?

User avatar
BRUTE
Posts: 2265
Joined: Sat Dec 26, 2015 5:20 pm

Re: Need help (forum spambot countermeasures)

Post by BRUTE » Wed Sep 14, 2016 12:00 pm

isn't there a plugin that outsources the captcha for phpbb to some service?

User avatar
BRUTE
Posts: 2265
Joined: Sat Dec 26, 2015 5:20 pm

Re: Need help (forum spambot countermeasures)

Post by BRUTE » Wed Sep 14, 2016 12:01 pm

sky wrote:What is the airspeed velocity of an African swallow?
laden or unladen?


jacob
Site Admin
Posts: 8969
Joined: Fri Jun 28, 2013 8:38 pm
Location: USA, Zone 5b, Koppen Dfa, Elev. 620ft, Walkscore 73
Contact:

Re: Need help (forum spambot countermeasures)

Post by jacob » Wed Sep 14, 2016 12:03 pm

Maybe ... but in the name of easy maintenance, the decision is to keep the forum software as close to the basic installation as possible.

Q&A really is the best solution since a good question also eliminates any "mechanical turk"-human who's paid 50 cents an hour to register fake accounts.

User avatar
Chris
Posts: 495
Joined: Thu Jul 22, 2010 2:44 pm

Re: Need help (forum spambot countermeasures)

Post by Chris » Wed Sep 14, 2016 3:05 pm

jacob wrote:Maybe ... but in the name of easy maintenance, the decision is to keep the forum software as close to the basic installation as possible.
Understood. But there's breaking point somewhere... if you need to update the question weekly, it might be less work to do the upkeep required to use a plugin.

jacob
Site Admin
Posts: 8969
Joined: Fri Jun 28, 2013 8:38 pm
Location: USA, Zone 5b, Koppen Dfa, Elev. 620ft, Walkscore 73
Contact:

Re: Need help (forum spambot countermeasures)

Post by jacob » Wed Sep 14, 2016 4:33 pm

Until I manage to get some trustworthy software nerd on retainer for $100/month(*) for work that mostly requires doing nothing except that one time a year where there's a fire alert that requires some immediate response with 1-3 hours, any breakpoint is strongly skewed towards Q&A.

(*) That's the 1099 level. If you want to avoid the tax complications and just do line 21 on form 1040, I can't pay more than $50/month or rather $600/year.

User avatar
BRUTE
Posts: 2265
Joined: Sat Dec 26, 2015 5:20 pm

Re: Need help (forum spambot countermeasures)

Post by BRUTE » Wed Sep 14, 2016 4:43 pm

so being on call with 1-3h response time for one year, paying $600. pretty sure that's what being on call pays in a day.

jacob
Site Admin
Posts: 8969
Joined: Fri Jun 28, 2013 8:38 pm
Location: USA, Zone 5b, Koppen Dfa, Elev. 620ft, Walkscore 73
Contact:

Re: Need help (forum spambot countermeasures)

Post by jacob » Wed Sep 14, 2016 4:59 pm

Could be, seeing that I've failed to attract any bidders so far. If I have to pay $200k/year to get someone to spend a few hours fixing a problem once a year, it's never going to happen. I want to pay some trustworthy forumite some $600-1200/year for website support (it's 95% forum crap) for issues that historically has happened about once every 6-18 months and which has required some 1-6 hours to fix. This is on the condition that the person is competent enough to fix them and will/can fix them inside of 12-24 hours.

sky
Posts: 725
Joined: Tue Jan 04, 2011 2:20 am
Contact:

Re: Need help (forum spambot countermeasures)

Post by sky » Wed Sep 14, 2016 5:01 pm

The problem is that the Mechanical Turks are about as smart as some of the people that would like to participate on the forum. I used to run a phpbb forum and there were plug ins for captchas. I went to the phpbb forums every year or two to check out the current best practices to combat spam sign ups.

Did
Posts: 598
Joined: Mon Apr 01, 2013 7:50 am

Re: Need help (forum spambot countermeasures)

Post by Did » Thu Sep 15, 2016 6:16 am

I don't know what city Jacob lives in.

Guess I will never progress up the ERE table

User avatar
cmonkey
Posts: 1457
Joined: Mon Apr 21, 2014 11:56 am

Re: Need help (forum spambot countermeasures)

Post by cmonkey » Thu Sep 15, 2016 7:22 am

I am on call for 1 week every 5 weeks and it doesn't pay anywhere near 200K annually. The job would probably be similar to what I already do and since I find my day job pretty boring/easy....well... If you could match the 'income' row in my spreadsheet....let's talk. :D ;)

User avatar
Chris
Posts: 495
Joined: Thu Jul 22, 2010 2:44 pm

Re: Need help (forum spambot countermeasures)

Post by Chris » Thu Sep 15, 2016 10:13 am

jacob wrote:Until I manage to get some trustworthy software nerd on retainer for $100/month(*) for work that mostly requires doing nothing except that one time a year where there's a fire alert that requires some immediate response with 1-3 hours...
I think it's the expected response time that is off-putting (speaking for myself). Perhaps if you enlisted two people, pay them each of them a small monthly retainer, and then whichever one responds to the annual emergency would get a bonus.

User avatar
BRUTE
Posts: 2265
Joined: Sat Dec 26, 2015 5:20 pm

Re: Need help (forum spambot countermeasures)

Post by BRUTE » Thu Sep 15, 2016 11:54 am

Did wrote:I don't know what city Jacob lives in.

Guess I will never progress up the ERE table
for only $999.99 or 99 monthly installments of $99.99 each, brute will certify Did in the Level 1 ERE(tm) program

OTCW
Posts: 236
Joined: Thu Mar 31, 2011 12:55 am

Re: Need help (forum spambot countermeasures)

Post by OTCW » Thu Sep 15, 2016 3:14 pm

Can you make someone's first post(s) only be able to be made in a specific forum? If it is spammy, no one sees it, and you delete it and them at your leisure.

User avatar
BRUTE
Posts: 2265
Joined: Sat Dec 26, 2015 5:20 pm

Re: Need help (forum spambot countermeasures)

Post by BRUTE » Thu Sep 15, 2016 3:40 pm

good idea. brute thinks there's a class of users in phpbb that's "registered new" or something. then the admin can move them to a "real registered" group manually. it might be more effort to manually accept every legit user, but it might be less effort than deleting/banning hundreds of fake ones.

Augustus
Posts: 121
Joined: Sat Apr 02, 2016 10:15 am

Re: Need help (forum spambot countermeasures)

Post by Augustus » Mon Sep 26, 2016 4:02 pm

Somewhat interested in your offer, depending on how many hours you actually end up needing. I am looking to increase passive income for retirement. If it's averaging over an hour a month, then your price would be below market. Regardless, have 15+ years professional web dev experience, and php was my first web language.

Also agree with brute, I have less faith in phpbb contributors than google developers, I think it is much more likely that the phpbb project will die before google drops support.

User avatar
bigato
Posts: 1526
Joined: Sat Mar 05, 2011 12:43 pm

Re: Need help (forum spambot countermeasures)

Post by bigato » Sat Nov 05, 2016 2:35 pm

The definitive solution the the spambot problem in my opinion is to require the user to write a paragraph or two explaining the reasons why he want to register and also convincing you that he is not a bot. You only approve it if he convinces you. No automatic approval. You review the requests once a week and quickly delete the ones that does not convince you.

enigmaT120
Posts: 886
Joined: Thu Feb 12, 2015 2:14 pm
Location: Falls City, OR

Re: Need help (forum spambot countermeasures)

Post by enigmaT120 » Sun Nov 06, 2016 12:31 am

No way. It discriminates against people who can't pass a Turing test.

User avatar
Smashter
Posts: 80
Joined: Sat Nov 12, 2016 8:05 am
Location: NYC

Re: Need help (forum spambot countermeasures)

Post by Smashter » Thu Dec 01, 2016 3:14 pm

Time for a confession: I think this mysterious "spammer" was me!

I created an account and lurked for a long time. As a proper busy person who never reads disclaimers and merely scrolls down as quick as possible to hit "accept," I never read the code of conduct for the forum. Thus, my first post ever contained a link, got marked as spam, and I was banned forever. (I was just trying to help some people find a good water filter, it's something I'm passionate about!)

Then, I tried in vain to get back on the forums by creating new accounts. It was right around the time this thread was started. I figured if I tried enough one would get approved, but Jacob was NOT having it haha. I had to use my fiance's computer before I finally got approved again. I don't know why it didn't occur sooner that my IP address must have been flagged. I guess I was desperate for my ERE fix and wasn't thinking straight :)

Anyway, maybe that will quell some of the fears that a horde of nasty scammers is trying to burst down the gates. Or, maybe my plight happened simultaneously to all this and it's just a coincidence.

TLDR: don't throw a hyperlink in your first post.

130
Posts: 3
Joined: Thu Oct 13, 2016 7:37 pm

Re: Need help (forum spambot countermeasures)

Post by 130 » Wed Jan 25, 2017 4:01 am

Possible questions.

How about some maths questions in text? i.e. If you had to multiply two identical numbers to get sixty four, what is the square root of that multiplying number?

Post Reply