6 ms·
We are a small SaaS vendor and fighting spam is, like, 20% of the technical work that we do. Bad actors register trial accounts and then reverse engineer your f
by jitbit 6y ago
We are a small SaaS vendor and fighting spam is, like, 20% of the technical work that we do. Bad actors register trial accounts and then reverse engineer your front-end and forge millions of requests. Just 2 days ago we had a very similar issue [1]
We have all sorts of protection: rate limiting, crippling non-paid accounts, detecting if a trial signup comes from a VPN/Tor (+5 to "suspicious" score!) etc... But they still manage to find ways. It's a never-ending battle. And the saddest part is - all this hard work is completely invisible to our existing paying customers :(
If your app has an email-sending module of some sort it WILL be abused. Even a trivial "reset password" form is a target.
My support goes to the GitLab team. Good luck and no hard feelings.
[1] https://www.jitbit.com/news/5354-spammer-attack-post-mortem/ https://www.jitbit.com/news/5354-spammer-attack-post-mortem/
- gogopuppygogo 6y agoSounds like something a lot of companies need. Could be a good lifestyle startup company.
- nathancahill 6y agoRequire a credit card on signup.
- wu_187 6y agoThat won't work as the same bad actors typically dabble in CC fraud as well. They will typically already have thousands of CC numbers at their disposal.
- dec0dedab0de 6y agoCredit card and a delay.
- applecrazy 6y agoThat would basically destroy user acquisition metrics. As a user, I don’t want to wait days to get access to something.
- mro_name 6y ago> acquisition metrics here's the trade-off. Make you decision.
- dec0dedab0de 6y agoit doesn't have to be days, most credit card fraud is found within hours. You can also allow partial use of the application during the vetting period, just exclude the parts that are being abused. Though you should probably aim to build a product that people want to sign up for, and are willing to wait for.
- f430 6y agoMy solution was to block IP addresses from the following regions who were never our target customers anyways: India, Midde East, Turkey, Russia, China, South East Asia (except Singapore), All of Eastern Europe, Africa and island nations. It immediately reduced the amount of fraud and spam. Sure you might miss out on the <1% of your revenues but its a tradeoff I'm okay with.
- sergiotapia 6y agoYep, totally agree. We blocked China (a country we do zero business in) and saw a drastic double digit percentage decrease.
- f430 6y agoweird. not sure why you and my comment is being downvoted.
- bigint 6y agoRude!
- f430 6y agoPlease explain why you think its rude to block countries thats responsible for most of the spam and fraud. or is this another one of your alt nick you periodically sign in from?
- TheCapeGreek 6y agoIs the African and island nation traffic that significant and fraudulent? Having worked in the South African tech scene and for a UK company, every spam/dos detection I've seen has been from everywhere you mention except Africa and island nations.
- f430 6y agonot sure what you are trying to say here. Simply blocking all sources of traffic which we don't do business with has been beneficial in stopping spam and frauds.
- jarym 6y agoSo these 'bad actors' are they just out to find a way to DoS your service or do they have some other motive for forging millions of requests. (I get that email sending is a target - that has been the case since forever - but I'm asking about 'what else'?)
- deleted 6y ago[deleted]
- jdsalaro 6y agoIt varies: generating inconvenience(for fun or hate towards a particular service), spreading scam URLs(leveraging existing trust relationships), SEO and improving discoverability of their projects (porn, streaming of pirated content, etc) and many more.
- jitbit 6y agoYes, they sure do have a motive - to send spam via a 3rd party service. Like in this case (GitLab) - create a fake "issue" with spammy links in it and then "notify" thousands of users. In our case - we are a helpdesk ticketing app, so bad actors sign up for a trial, then add "users" to their account and then, say, create "tickets" on users' behalf (customizing the email template by inserting spammy links).
- tutfbhuf 6y agoUse hCaptcha for sign up and other sensitive parts of your application.
- meibo 6y agoI'd rather not use the service if it has hCaptcha OR ReCaptcha. hCaptcha has bad UX, their dataset is way harder to decipher and commonly takes me three or four tries to get around on Cloudflare, if it doesn't keep failing with a server error which I've had happen on multiple, distinct occasions. At least for Google, I was done in one turn when lucky, if I had no other choice (e.g. banking).
- contravariant 6y agoIt seems to have gotten better but I still haven't forgiven ReCaptcha for regularly making me spend ages retrying the unending and excruciatingly slow loading tests. At least hCaptcha has a decent chance of letting me through if I answer correctly.
- nonbirithm 6y agoI wonder if effective DDoS protection today is inextricably tied to having to route your traffic through centralized third parties like Cloudflare.
- rectang 6y agoImagine a world where spammers could be identified, prosecuted, and convicted reliably. The amount of economic energy unleashed would be staggering. We are still in the early days of the internet. It is a frontier territory where crime is rampant.
- ZWoz 6y agoThats about initiatives. Many daily drivers break some laws, like speeding or not using turn signals. Does that make traffic frontier territory? :) Try something serious, like operating black drug market or treatening high level politician (in internet): you going to be surprised, how well different countries co-operate. For example operation involving 30 countries: https://www.europol.europa.eu/newsroom/news/%E2%80%98avalanche%E2%80%99-network-dismantled-in-international-cyber-operation https://www.europol.europa.eu/newsroom/news/%E2%80%98avalanc...
- sneak 6y agoDo I have a minority opinion for believing that spam, even coordinated, ddos-level, business-destroying professional-grade stuff is not a severe enough problem to send men with guns to a place to lock a human being into a cage? I don't want the government prosecuting people for speech, even mass, automated speech. There are much better solutions than resorting to violence.
- rectang 6y agoYes, "spammers should not be punished by the government for destroying businesses" is bound to be a minority opinion, even if some among us are sympathetic. Protocols and system designs which make abuse impractical and thus prevent spam before it starts are surely desirable, although they often come with their own tradeoffs (user friction, privacy, false positives, maintenance costs, etc.). If spammers can be deterred by improving along other axes all the better. But the general problem of spam is that computing resources allow for massive amplification of malicious actions, and that's never going away — it will be an arms race between spammers and their victims forever.
- 6y ago
- malinens 6y agoI work for an e-mail provider. This is very painful part of our work. Part of our services are free and ad supported. We are disabling, queueing thousands of mailboxes per day. Captchas and user scoring does not help that much. There are very cheap services were people manually will solve recaptchas/hcaptchas. Even required phone numbers (normal users are pissed when we ask for a phone number to use account fully but we don't have much choice...). There are phone number farms which are used for account verification also
- jdsalaro 6y ago> This is very painful part of our work GitLabSec team-member here, ^ this 100%. Our Trust and Safety team works really hard to keep up with spam. For those interested in how they do so, you can read more here[1]. We are also working on making our spam detection engine more effective at mitigating high-volume spam incidents such as this. For current, working product improvements to detect and mitigate spam you and others can check out MRs labeled "spam fighting"[2]. We've had quite a few internal conversations about strategies and best-practices. For more information on how to contact our Trust & Safety Team, including tips on how to deal with abuse in your own instance or steps to suggest spam/abuse related features, see our handbook[3] [1] https://about.gitlab.com/blog/2020/10/29/how-we-work-to-detect-and-mitigate-spam/ https://about.gitlab.com/blog/2020/10/29/how-we-work-to-dete... [2] https://gitlab.com/gitlab-org/gitlab/-/merge_requests?scope=all&utf8=%E2%9C%93&state=merged&label_name[]=spam%20fighting https://gitlab.com/gitlab-org/gitlab/-/merge_requests?scope=... [3] https://about.gitlab.com/handbook/engineering/security/security-operations/trustandsafety/#contact-us https://about.gitlab.com/handbook/engineering/security/secur....
- zoomablemind 6y agoMaybe introduce a Moderator role to the multi-user projects? That would require the project's moderator to clear the newly posted issues (whatever is possibly a spamming route there) before they propagate. As this is an additional friction point, some bad actors may be intercepted there (say, trying to clear a million issues at once or other equally ridiculous actions). Of course, by itself it won't stop someone from clearing a single issue to a million of "users". But may still help in id'ing such actors.
- freyfogle 6y agoCan't upvote this comment enough. Have wasted years of my life on these invisible, but sadly necessary, features.
- LunaSea 6y agoHave you tried differentiating ISP vs hosting provider traffic? Also, you could try to detect headless browsers like Headless Chrome.
- pcarmichael 6y agoLots of VPNs route through hosting providers. Some hosting providers are more prevalent with spammers than others. But in the end you can only really use it as a scoring measure. It's not nearly binary enough to straight filter using it.
- LunaSea 6y agoAgreed but I'd rather lose the small percentage of users on VPNs than have my site flooded with junk traffic and spam
- walrus01 6y agogoogle "residential proxies for sale" - there is a whole huge grey market in selling proxies from peoples' actual residential internet connections, usually to be driven by bots or people in click-farms somewhere in a low labor cost location. If you want to appear to be a legitimate comcast, charter, centurylink, frontier end user on a last mile broadband connection in a house somewhere in the US48 states, that's a standard service that fraudulent organizations make use of now. Usually using software that people have been tricked into installing on their computers.
- darkwater 6y agoExactly, and this is why "in theory" Google reCaptcha, the that is just a checkbox, is a needed solution. If they only used it to just stop spam and not also to track legitimate users...
- technion 6y agoI don't need to Google them. "Residential proxies for sale" is one of the most common Facebook ads I see. There was one on my screen just five minutes ago. It's staggering that the industry is so blatant.
- waihtis 6y agoWhat do the bad actors technically do? Map your api endpoints and spam them with traffic? Something else also?
- ruffrey 6y agoSmall SaaS vendor checking in. This comment rings true and it’s a constant battle.
- stanislavb 6y agoI feel you. Fighting SPAM is eating a serious amount of my energy, too.