25 ms·
Hi! I'm the PM at GitLab who works on Snippets, so thanks for providing this feedback. We do have Recaptcha support which can be configured - are you seeing the
by phikai 6y ago
Hi! I'm the PM at GitLab who works on Snippets, so thanks for providing this feedback. We do have Recaptcha support which can be configured - are you seeing these kinds of issues with that enabled/configured?
One item that is on the roadmap that is coming and may be of interest is `Optional Admin Approval for local user sign up` - https://gitlab.com/groups/gitlab-org/-/epics/4491 https://gitlab.com/groups/gitlab-org/-/epics/4491.
I'm not in the group working on that, but it does appear to be coming soon and would limit the ability of newly created accounts from doing anything until they're approved.
- protoduction 6y agoHi phikai, I built a privacy friendly alternative to ReCaptcha called FriendlyCaptcha [1], is there a possibility to see this integrated as a more user friendly alternative? Happy to chat (e-mail in profile) [1] https://friendlycaptcha.com/ https://friendlycaptcha.com/
- sytse 6y agoThat looks cool! Can someone create an issue to add support for this to GitLab? And maybe we can consider switching GitLab.com to this as well.
- robotmay 6y agoI'm personally interested in this too so I've created one :D https://gitlab.com/gitlab-org/gitlab/-/issues/273480 https://gitlab.com/gitlab-org/gitlab/-/issues/273480
- sytse 6y agoThanks for creating this! I think adding support for this in GitLab is a no-brainer. After that we can consider enabling it for GitLab.com
- barnabask 6y agoMan this needs more attention, cool project. I see you tried to submit to HN a couple of times and didn't get traction, that's too bad. Don't give up!
- birdsbirdsbirds 6y agoHopefully you are successful, but how can you scale? If it takes 5 seconds on a desktop, then a server can solve 500.000 captchas per month. At $5 per month, a spammer can still send 1.000 messages for a cent.
- protoduction 6y agoIt's not enabled yet in production - but the main mechanism is by increasing the difficulty as more requests are made from an IP in a certain timeframe (it's basically rate limiting at that point). Think: every 3rd request in a minute doubles the difficulty with some cooldown period. With that the cost (and complexity) of an attack can hopefully be in the same ballpark (or higher) than ReCaptcha - without your end user having to label cars or send data to Google. But in the end a determined spammer will get through any captcha cheaply (for reference: ReCaptcha solves are sold by the thousands for $1) - we just hope we can do better than ReCAPTCHA, especially UX-wise.
- coder543 6y agoThe obvious follow-up question is how IPv6 impacts this, because I think it's supposed to be easy for someone to get their hands on a decent chunk of IPv6 addresses. Maybe the difficulty could scale as a property of how similar the IP address is to previously seen addresses... so the addresses in the same /64 block would be very closely related, for example. (I think that's how IPv6 works... but definitely something I haven't researched lately, so I could just sound very confused)
- protoduction 6y agoI don't have all the answers yet, but indeed rate limiting a larger block (at least /64), or even at multiple prefix sizes with different weighting makes sense.
- zahllos 6y agoSo the way this is supposed to work is that providers hand out /48s and each site should be allocated a /64. In practice if you for example rent a VPS, you'll be handed a /64 for it by your service provider from their /48. I would personally treat any /64 as the same. Depending on your local network setup the second half of the address could be anything and could change frequently. You might also get multiple addresses. Whereas getting a new /64, or /48, requires slightly more effort. Of course there's a risk you'll block a /64 and that takes out some whole company or whatever, but I've seen that happen to corporate proxies that got flagged as a source of spam as well so this is not an easy problem even without the 2^128 address space.
- Max70 6y agoWow! Thumbs up! I have just checked it out and FriendlyCaptcha seems to be a true game changer. I hope that it will replace every f*cking Google reCAPTCHA out there. Such a great idea!
- webphineas 6y agoReally nice! Finally someone is using the blockchain technology in a meaningful way!
- laughinghan 6y agoThis doesn't use a blockchain, it uses a Hashcash-style proof-of-work function (an idea that predates the Bitcoin by decades): https://en.wikipedia.org/wiki/Hashcash https://en.wikipedia.org/wiki/Hashcash
- aeyes 6y agoIs the demo somehow tweaked to be less hard? On my machine it doesn't take any time to solve it and I see no signs of CPU usage. Even trying a couple of times in incognito mode and watching CPU immediately after loading the page for the first time. On many sites creating a profile takes a few seconds. Loading one of my CPU cores for another 5 seconds doesn't really bother me if I wanted to create massive amounts of profiles/posts. I'll still do over 100 per minute on a standard desktop PC.
- protoduction 6y agoThe default difficulty is set to a difficulty that makes sense on websites that have a varied audience (which includes some ancient browsers on old devices). The solver runs in WebAssembly and is really really fast (~4M hashes per second) - but not every browser supports WASM yet (around 0.3% empirically). The JS fallback is around 10 times slower (more in 5+ year old browsers) - for those users you want at least a decent solve time too. For Gitlab's audience the difficulty can probably be increased a lot - it all depends on the website and usecase. I'm sure the JS fallback's performance can be improved (it involves a lot of operations on 64bit ints that need to be represented as two numbers in JS), happy to accept PRs [1] :) [1]: https://github.com/FriendlyCaptcha/friendly-pow/blob/master/src/blake2b/blake2b.ts#L80-L82 https://github.com/FriendlyCaptcha/friendly-pow/blob/master/...
- thinkloop 6y agoWhat are your thoughts on performing a quick intial test on each client to measure their performance then tailoring the puzzle to be difficult enough for each?
- unilynx 6y agoOnce the spammer figures out what you're doing, he'll just throttle the CPU for the duration of the quick test. Depending on how smart the test is, just having Date.now() return values with a -12000, -11000, -10000 offsets the first few calls might even do it
- redbergy 6y agoAwesome work, I will be giving this a try in my next project
- laughinghan 6y agoThere doesn't appear to be any discussion on your website or on GitHub about why, to be blunt, this is even a good idea in the first place. A classic 2004 paper, "Proof-of-Work" Proves Not to Work [0], explained that the fundamental problem with proof-of-work bot filters is that attackers will always be able to solve the cryptographic puzzle faster than legitimate users. A touch of security-through-obscurity can help at the margins, but you chose Blake2b, which is used by cryptocurrencies like Zcash, Siacoin, and Nano [1], and as a result there are optimized GPU algorithms (first Google result [2]) and FPGA designs (one of the top Google results [3]). Have you run the numbers on any of those? The closest to any discussion of these numbers that I saw was a mention on your website that it may take up to 20s on mobile; for comparison, the much-hated image CAPTCHA takes about 6-12s on average for native English speakers, and 7-14s for non-native speakers [4]. In another comment you bring up the idea of starting with a lower difficulty, and increasing it with repeated requests from the same IP address (IPv4, I assume). Unfortunately, access to unique IPv4 addresses is highly correlated with access to more compute power: laptops and desktops in developed countries are most likely to be in a household with a unique IPv4 address, whereas mobile devices on 4G internet and households in developing countries are more likely to be behind Carrier-Grade NAT [5], where thousands or millions [6] of hosts share a pool of a handful or dozens of IPv4 addresses. (The exact same concern applies to IPv6 /64 prefixes.) This means that mobile devices will face a "double-jeopardy": your service will present them with higher proof-of-work difficulties because the same IPv4 address is shared by more people, and at the same time, the mobile device solves the proof-of-work slower for the same difficulty than a desktop. Do you have documented anywhere on your website or GitHub how you address these concerns? [0]: https://www.cl.cam.ac.uk/~rnc1/proofwork.pdf https://www.cl.cam.ac.uk/~rnc1/proofwork.pdf [1]: https://en.bitcoinwiki.org/wiki/Blake2b https://en.bitcoinwiki.org/wiki/Blake2b [2]: https://github.com/zhq1/sgminer-blake2b https://github.com/zhq1/sgminer-blake2b [3]: https://xilinx.github.io/Vitis_Libraries/security/2020.1/guide_L1/internals/blake2b.html https://xilinx.github.io/Vitis_Libraries/security/2020.1/gui... [4]: http://theory.stanford.edu/people/jcm/papers/captcha-study-oakland10.pdf http://theory.stanford.edu/people/jcm/papers/captcha-study-o... [5]: https://en.wikipedia.org/wiki/Carrier-grade_NAT https://en.wikipedia.org/wiki/Carrier-grade_NAT [6]: Yes, millions. RFC 6598 reserved a /10 for them, which is 4 million unique IPv4 addresses: https://tools.ietf.org/html/rfc6598 https://tools.ietf.org/html/rfc6598
- typenil 6y agoLove to see this. ReCaptcha is nothing short of a menace. I'll take a shot at this for my next project
- remram 6y ago> up to 20 seconds on old smartphones That sounds like a very battery-unfriendly idea.
- protoduction 6y agoIt's not perfect, but maxing a single core for 20 seconds on an older smartphone is a necessary evil for this kind of captcha. The alternative: loading a third party script and multiple images (~2MB) to label for ReCAPTCHA and spending time performing the task also takes some battery (and mental) power.
- NorwegianDude 6y agoCool project, but I do find it quite ironic that it's named friendly captcha when it's not a captcha.
- Eldt 6y agoHow would you define "CAPTCHA"?
- jimmydorry 6y agoCAPTCHA: a computer program or system intended to distinguish human from machine input, typically as a way of thwarting spam and automated extraction of data from websites I would say this Oxford Languages dictionary definition is close enough.
- perryizgr8 6y agoThe original expansion was "Completely Automated Public Turing test to tell Computers and Humans Apart".
- ognarb 6y agoYour website mention that friendlycaptcha is open source but looking at the license in the repository, it is a custom license that can't be defined as open source. Can you change it to source available?
- rightbyte 6y agoRelying on Google's Spying-as-a-Service tooling is not very FOSS at all. There need to be other ways to reach out to users who block Google.
- encom 6y agoI immediately back out whenever encounter Recaptcha. The other day I was forced to endure it, because I wanted to delete my ancient Minecraft account, since Microsoft pulled a Facebook and are going to require a Microsoft account to play going forwards. Without exaggeration, it took me 15 minutes of training Google surveillance AI (had to solve it three times), for Recaptcha to let me in. I guess Google really hates me.
- wolco2 6y agoAre you sure you are human?
- encom 6y agoYes, definitely. https://v.redd.it/uaefcc2mztj31/DASH_720 https://v.redd.it/uaefcc2mztj31/DASH_720
- myself248 6y agoI'm human enough, and I've been a licensed driver long enough, to recognize that rumble strips at the side of a road are not crosswalks. But apparently enough bots thought they were that the system is now trained on that 'fact', and I as a human am forced to misidentify rumble strips as crosswalks to pass as human. It's bizarre.
- ignoranceprior 6y agoReCaptcha also thinks that mailboxes are parking meters, for some reason.
- db48x 6y agoI do the same thing.
- jancsika 6y ago> We do have Recaptcha support which can be configured - are you seeing these kinds of issues with that enabled/configured? Thanks, I have used Recaptcha for a long time now. It made no difference. > One item that is on the roadmap that is coming and may be of interest is `Optional Admin Approval for local user sign up` - https://gitlab.com/groups/gitlab-org/-/epics/4491 https://gitlab.com/groups/gitlab-org/-/epics/4491. Yes, that would be a very sensible solution and welcome feature for my use case here. Unfortunately, from the bottom of that issue tracker: "Yikes. I'm glad we did the further breakdown and pre-work. It's a bit cringeworthy looking back and seeing I estimated a 5"
- mushakov 6y agoHi! I'm a PM at GitLab. Please see my reply above for more details but TL;DR we shipped the first iteration of the `Optional Admin Approval for local user sign up` feature in 13.5. I'd love your feedback! Please comment on the epic if there are other changes for this feature that would help your use case https://gitlab.com/groups/gitlab-org/-/epics/4491 https://gitlab.com/groups/gitlab-org/-/epics/4491
- jancsika 6y agoThanks for the update. I can certainly manage user sign-up from the admin tab for the time being. Once it's hooked into email, I believe that will make things maintainable again for me. From a UX standpoint it's still sub-par. Someone who wants to report an issue doesn't want to wait an arbitrary amount of time to be allowed to report an issue. They are ready to report it at that moment. And as an admin, I don't want to have to approve new users on a schedule to ensure the delay is low enough that they are still willing to submit the issue after I approve them. I'd much prefer they go ahead and submit the content, especially so that I can use it in my review of whether to approve the sign up or not. I seem to remember some pattern in Gitlab where my login period timed out before I finished making a comment. When I logged back in, Gitlab had somehow saved my comment content so that I could then post it so that others could see it. Is there any way to use that pattern for users who haven't been approved yet? So that they can post content, but with a warning shown to them that other users won't see it until the sign-up is approved.
- 67868018 6y agoNone of your captcha settings work, not even the invisible captcha setting that requires enabling a feature flag.
- mushakov 6y agoThanks for bringing up this epic in the conversation phkai. I'm a PM at GitLab for our Auth group and am working on the `Optional Admin Approval for local user sign up` feature. I'm happy to tell y'all that we shipped the first iteration of this in our 13.5 release. You can find more information in our release blog https://about.gitlab.com/releases/2020/10/22/gitlab-13-5-released/#required-approval-for-new-user-registration https://about.gitlab.com/releases/2020/10/22/gitlab-13-5-rel... . I've also updated the epic with more information about its current status https://gitlab.com/groups/gitlab-org/-/epics/4491#status-update https://gitlab.com/groups/gitlab-org/-/epics/4491#status-upd....
- MrStonedOne 6y agoYou have to remove incentives. Block the viewing of these snippets by logged out users by default and require opt-in and a way to whitelist snippets by snippet or user. Same for user profiles
- noizejoy 6y agoI don't think this is targeting human views - but it's targeting Google for SERP (Search Engine Results Pages) boost.
- MrStonedOne 6y agoThat's the point. Having a way to disable search engines would also work, but wouldn't be obvious to spammers so they would still try to spam. Disabling all users by default works to remove the incentive to try
- xiphias2 6y agoHave you thought of the option of disabling links? That would make SEO spam impossible
- pitay 6y agoIs just adding the attribute rel="nofollow ugc" to any links in submitted content may be good enough. This tells search engines to not index, or tag them as suspicious, allowing them them to identify SEO spam more easily. [1] Having both options would be great. [1] https://support.google.com/webmasters/answer/96569 https://support.google.com/webmasters/answer/96569
- kemayo 6y agoFor this specific case, the Wikimedia Foundation has explicitly stated that "It is the Free Software release of GitLab that runs optional non-free software such as Google Recaptcha to block abuse, which we do not plan to use." So, not incredible helpful at the moment. Also, is manual approval for new signups a good idea for a large FOSS project? It seems like a pretty big barrier to legitimate discussion.
- anarcat 6y agoWe (at torproject.org) also adopted GitLab CE recently and we had to close down registrations because of abuse. Tens (hundreds?) of seemingly fake accounts were created in the two weeks we had registrations opened and we had to go through each one of those to make sure they were legitimate. In our case, snippets were not directly the problem: user profiles were used as spam directly. We can't use ReCAPTCHA or Akismet for obvious privacy reasons. The new "admin approval" process in 13.5 is interesting, but doesn't work so well for us, because it's hard to judge if an account should be allowed or not. As a workaround, we implemented a "lobby": a simple Django app that sits in front of gitlab to moderate admissions. https://gitlab.torproject.org/tpo/tpa/gitlab-lobby/ https://gitlab.torproject.org/tpo/tpa/gitlab-lobby/ The idea is people have to provide a reason (free form text field) to justify their account. We'd also like people to be able to file bugs from there directly, in one shot. We're also thinking of enabling the service desk to have that lower bar for entry, but we're worried about abuse there as well. Having alternatives to ReCAPTCHA would be quite useful for us as well.
- gaba 6y agoIs this something that we will have in the CE version (the open licensed one) or it will only go to the enterprise one?