6 ms·
The spam is infuriating (not GitLab's fault, of course). Atleast, on our instance at https://git.cloudron.io https://git.cloudron.io, we got massive snippet spa
by gramakri 6y ago
The spam is infuriating (not GitLab's fault, of course). Atleast, on our instance at https://git.cloudron.io https://git.cloudron.io, we got massive snippet spam. After we disabled snippets, we got massive spam on the issue tracker (!). The way we "fixed" is by turning on mandatory 2FA for all users.
As a general lesson, what we learnt is these are not bots. These are real humans working in some poor country manually creating accounts (always gmail accounts) and pasting all sorts of random text. Some of these people even setup 2FA and open issues with junk text, it's amazing. Unfortunately, GitLab from what I can tell cannot make issues read-only to non project members (i.e I only want project members to open issues, others can just read and watch issues).
Currently, our forum spam (https://forum.cloudron.io https://forum.cloudron.io) is way more than GitLab spam. On the forum, we even have Captcha enabled (something we despise) but even that doesn't help when there are real humans at work.
- csdreamer7 6y agoWhy are they posting random text in Gitlab?
- riffic 6y agogetting that sweet sweet seo backlink juice
- gkop 6y agoIsn’t that why we add rel=nofollow to low friction user submitted links on our platforms?
- ivank 6y agoGoogle changed the interpretation of those a year ago. https://webmasters.googleblog.com/2019/09/evolving-nofollow-new-ways-to-identify.html https://webmasters.googleblog.com/2019/09/evolving-nofollow-...
- nurettin 6y ago> Looking at all the links we encounter can also help us better understand unnatural linking patterns. It appears as though they want to mark these links in order to prevent inorganic SEO, not help it.
- nerdponx 6y agoI don't get it. They post all this spam in the hopes that people click on the links therein, thereby boosting the ranking of those sites? Does that actually work at all?
- rudedogg 6y agoIt doesn’t actually require anyone clicking on the links. Google sees inbound links and uses that as a factor when calculating the ranking of the linked page.
- IggleSniggle 6y agoI thought that was how it worked like a decade or more ago, but not today.
- deleted 6y ago[deleted]
- technion 6y agoRegardless of whether it works, people still pay for it. I have a Facebook ad right now that says "Get over 500,000 backlinks for $29.99". No doubt it's someone with a bot that spams comment forms.
- gramakri 6y agoI am not entirely sure. See https://forum.cloudron.io/users https://forum.cloudron.io/users, if you go to say page 10 or something you will see all sorts of nonsense. I am still trying to figure what the best way to fight this spam (because captcha is enabled and required to even create accounts). But these are real people and not bots. I know this because they even post new messages all the time.
- fancyfish 6y agoDefinitely the SEO backlinks- for example one profile I see is linking to an Indian escort service in the profile.
- coder543 6y agoMaybe GitLab needs an option to disable external linking, and filter any comment that contains an external link automatically
- csdreamer7 6y agoOr a nofollow option (add rel=nofollow)
- dnsmichi 6y agoThat's a great idea. We have discussed ways of getting a trust level, and enable this for specific groups. Discourse uses the same system for preventing spam. "Good" bots detect the rel=nofollow and do not come back. See my proposal here: https://gitlab.com/gitlab-org/gitlab/-/issues/14156#note_258252735 https://gitlab.com/gitlab-org/gitlab/-/issues/14156#note_258...
- dnsmichi 6y agoIterating on my original thought, here is a smaller feature request for self-hosted GitLab instances. This can help GitLab.com too: https://gitlab.com/gitlab-org/gitlab/-/issues/273618 https://gitlab.com/gitlab-org/gitlab/-/issues/273618
- grey-area 6y agoThis is a typical spam profile. Usually they contain links, which search engines follow. https://forum.cloudron.io/user/cardioaseg https://forum.cloudron.io/user/cardioaseg
- edflsafoiewq 6y agoThe link contains rel=nofollow.
- leipert 6y agoI don’t know for sure, but I think our Markdown implementation adds nofollow.
- brlewis 6y agoI used to think that spammers would stop if their spamming didn't win them any results. But they don't care. They spread their spam as widely as possible without trying to prune out the places where it does them no good.
- grey-area 6y agoThat doesn't matter, see other comments below on Google's changing treatment of this attribute. Also you'll find spambots posting on any open form on the internet even if it doesn't do them any good, because much of it is automated, so even if you hide the results the spam will still come in.
- Siira 6y agoHow do you know they are real humans? I imagine bots doing 2FA would still be cheaper.
- boneitis 6y agoMany bots are likely still powered under the hood by humans. On my backlog of projects to do is to make a browser extension that solves the more obnoxious captchas for me, as I'm regularly behind vpn and fall into ridiculously long solve loops. On the most popular api i could find, $10 buys you a shockingly LOT of solves (not that I've tested it yet). It is automatable but ultimately still powered by humans.
- dannyw 6y agoIt’s incredibly sad how the open web is being destroyed by google’s recaptcha.
- boneitis 6y agoI'm totally in that camp of opinion, although I'll acknowledge the escalating abuses carried out by both "sides." In the meantime, i hope to have the savviness to program my own way out of unsolvable captchas.
- nerdkid93 6y agoI'd argue that it's equally sad to see the open web get destroyed by massive DDoS attacks and malicious actors. How would you keep your own website up if it was constantly being attacked?
- Kalium 6y agoWithout google's recaptcha, do you think there would be less spam? Personally, I suspect there would be more without at least some speed bumps to raise the cost of spamming. I would absolutely love for there to be better options than recaptcha that meets the same needs around bot-detection, price, implementation effort, and accessibility. It is, sadly, the best option I've seen on offer. You're right. The scenario we're in is incredibly sad. It would be wonderful if the individual actors involved had better options to meet their needs.
- Symbiote 6y agoWe had one of the "real humans" write to us (in issues) asking us to leave his spam up for "just a few hours". We implemented a filter anyway. (This was not Gitlab, but a specific form on our unique website.)
- packetlost 6y ago> asking us to leave his spam up for "just a few hours" What... why? What is their goal???
- deleted 6y ago[deleted]
- vvpan 6y agoFeeding their family?
- packetlost 6y agoBut like... who's paying for that kind of spam??
- mpol 6y agoA service like Stop Forum Spam might be a solution to this. It checks for IP address and email address and gives it a value based on how likely it is assumed to be a spammer. When they have to set up a new email account and maybe even a new IP address for every few accounts, it gets to be a lot of work soon. https://www.stopforumspam.com/ https://www.stopforumspam.com/
- pcmaffey 6y agoCould add nocrawl to your robots.txt and advertise the fact on signup page that search engines won’t find this content.