9 ms·
Spam accounts in 2022
- hayksaakian 5y agoKey point: if your platform allows people to post links that Google can see Spammers will inevitably try to take advantage of your website
- hypertele-Xii 5y agohttps://developers.google.com/search/docs/advanced/guidelines/qualify-outbound-links https://developers.google.com/search/docs/advanced/guideline...
- infogulch 5y agoIn particular: > rel="ugc" > We recommend marking user-generated content (UGC) links, such as comments and forum posts, with the ugc value.
- dclusin 5y agoUgc content “may” be used by google as a ranking signal. It’s definitely not a panacea.
- mpol 5y ago"rel=nofollow" is the only somewhat standard one. I have never heard of "rel=ugc" and I wonder if google made it up, does that work on bing and yandex? I mostly use "rel=nofollow noopener noreferrer" which should cover most "use-cases" of spammers.
- dspillett 5y agoThat won't stop the spam appearing, and the spam accounts to generate it, it'll just remove (most of) the benefit to the spammer. It takes less faf for them to just post anyway than to check if you use nofollow/other, and they may still get a small side benefit if a blog-spam scraper or such takes your content and reposts it without the extra directives.
- tinus_hn 5y agoSolution: for free accounts, only show links with the appropriate tags so they don’t improve ranking. This was clear a decade ago, did we go backwards?
- Lascaille 5y agoSpammers don't fill comment sections with spam to improve the ranking of that website, they fill comment sections with spam to target the users of that site.
- mnw21cam 5y agoThey fill the comment sections with spam to improve the ranking of a different site that they are linking to in the spam.
- vintermann 5y agoYeah, but they don't bother checking for nofollow attributes. Not spamming people who enforce nofollow attributes would just encourage more people to adopt it, which the spammer doesn't want. Either way, the spammer rarely spams his own thing. They spam what someone else pays them to spam, and don't care if it actually works as long as their customer believes it works (much like legal advertising).
- tinus_hn 5y agoIn other news, even if you block spam spammers still keep sending it, because it’s cheaper to not care. Does that mean we should not block spam?
- danuker 5y ago> This was clear a decade ago, did we go backwards? Maybe to you. But you are not the only person in the world. And as the other comment said, spam still gets exposure to other comment readers.
- leke 5y agoIs there something simple, like a tag, we can use to wrap comments in to ask google not to use in search results?
- clusterfish 5y agorel=nofollow etc. Although not sure how much it's respected
- dazc 5y agonofollow will prevent links being counted but it doesn't stop you being spammed. Spammers don't bother checking existing links at their target site since indescriminate spamming at scale obviously works and doesn't need such finese.
- encryptluks2 5y agoI am now under the impression that we have two solutions for spam and robocalls. Make people link some real ID to accounts, or treat spammers and robocallers like terrorist. I personally prefer the 2nd option. Once spammers fear for their lives, they will stop.
- reayn 5y agoI personally am not opposed to the Idea that there be more verification involved in important things like Phones and E-Mails (as it's usually a 1-to-1 thing per person anyways) but the privacy and logistics concerns are very valid and will probably stay that way knowing this space. Such things require either consensus or tyranny, the former of which is nigh-impossible to reach and the latter being not exactly ideal. > Once spammers fear for their lives, they will stop. They could just as likely just improve their methods...
- foepys 5y agoThe German ID card ("neuer Personalausweis") can already prove to a service that you are a real human without revealing your identity in a fully automated way. It can also verify you are 18+ years old, reveal partial data, and much more. Sadly certification for services is not easy and very bureaucratic but then at least you as a user can be sure that nothing unnecessary gets revealed to the service. This is >10 year old technology, by the way.
- encryptluks2 5y agoI don't know how well something like this would work for an international website or service. There are a lot of challenges, like for example the centralized authority responsible for managing and creating new IDs could abuse the service. It isn't fool proof.
- foepys 5y agoIt's obviously something services have to implement for each type of ID. When you have to interact with the real world that things get a bit messy. Companies can abstract this away and be certified by each government, e.g. like Stripe. It's nothing special.
- vmception 5y agoI love how benign it all is, fun rabbit hole. Just AI affiliate marketing
- arbuge 5y agoI am not sure I would describe any of this as benign. Spamming multiple SaaS services, generating websites containing solely AI generated junk and ads, in an attempt to profit off the sales of extremely dubious products does not meet the definition of benign in my mind.
- xchaotic 5y agoIn a somewhat off topić is there a narro alternative but using real Voice actors?
- a1371 5y agoYou mean like people who do voiceovers on Fiverr?
- kingcharles 5y agoI was going to say Fiverr. I can highly recommend my First Wife as an excellent source of cheap voiceovers (6000 five-star ratings?): https://www.fiverr.com/actressellen/record-a-professional-voiceover-up-to-150-words-using-high-quality-equipment https://www.fiverr.com/actressellen/record-a-professional-vo...
- stephen123 5y agoWhat process do you have to stop this spammer sighing up again. It sounds like you already have some automation, but in this case it got flagged for manual review.
- mpol 5y ago"They immediately generated enough audio readings to max out the free tier" It seems this is part of the automation, it got flagged based on this. By the way, I am quite happy with JavaScript based spamfilters, they work quite well for small websites. The service Stop Forum Spam is something that seems fit for this, also at bigger scale. I assume Akismet might be good too, but it is somewhat leaky in privacy, depending on what you send to it.
- lrem 5y agoStop Forum Spam looks nice. It's great they're giving the data like this. In fact, I'm somewhat surprised there's no software download to self-host. Seems rather easy to make, given the data files. Are there any other filters you recommend?
- mpol 5y agoThis was already my list of "approved" spamfilters :) I don't know any others that I like and are low in false positives.
- lrem 5y agoI'm wondering how much a Hashcash implementation would help. The approach doesn't seem to be widely attempted. Maybe because we assume spammers are using botnets anyway and don't care about computational cost?
- onara 5y agoOOPSpam is a privacy-friendly alternative to Akismet.
- vintermann 5y agoIt seems to me like spammers like the one behind this, put enough effort into it that they could probably make more from legitimate activity. It's like there's a "scam premium", where some people pay extra (or work extra for free) just to feel they're outsmarting people.
- cookiengineer 5y agoI did a similar investigation into a couple of fake profiles that are also on LinkedIn and some customers of us got spammed by them. Turns out there's a company with a facade called "whitehallmedia dot co dot uk" and they are hugely involved in the spam game. They seem to have actual people that contact accounts/leads and their contexts from somewhere in India, and those people share spam accounts. Initially they try to sell you some tickets to an analytics and cyber security conference at first, but then they try to contact C-staff as soon as you start reacting. The C-staff members then get trapped into the selling and audit game, so they offer free pentests / IT audits and "cyber security software" that can fix the problems (duh). I created a honeypot with a fake domain and a fake company that doesn't exist, with emails that cannot be guessed blindly and with an email server that doesn't list its account names (and account names are not bruteforceable and neither guessable). Zero links on the internet, domain isn't even google-able. Once I trapped them with private linkedin profiles and the people of whitehall media contacted the fake accounts, the spam arrived in masses. I'm not talking about 10 or 20 a day but in the thousands per day. And their network of hosts that they operate is _huge_. My current guess is that they abuse administrative access to their customer's servers (the analytics/cybersecurity/IT-security forefront) to install their malware and send spam on their customers' behalf without them even knowing about it. We contacted our customers afterwards and asked all others whether or not they had contact to them; and if so that they start to double-check on their server infrastructure because it was very likely that they got infiltrated.
- ericbarrett 5y agoThis sounds really interesting but I didn't quite follow the first paragraphs. How do they "trap" C-staff?
- dzink 5y agoRunning a consumer site that has plenty of user generated outgoing links but doesn’t give any exposure to new accounts I’ve seen a lot of different spam tactics as well. The one thing that has worked reliably is building a repository of bad IPs or potentially domains that are doing the spamming and blocking those. I wonder if a central repository of bad actors with this type of activity can be made for multiple UGC platforms to share. Wouldn’t be surprised if Akismet and other spam blockers already surface those. Bonus points if each entry provides details on the kind of attack vector used by each spammer and the sites who add to the list are also vetted/penalized for bad entries. Plus entries have a way of appealing if needed. Multiple layers of accountability built in. Unique ids won work - too dangerous and likely to be abused by advertisers or centralized entities trying to track individuals.
- dzink 5y agoA ton of automated attacks happen in the logs as well - constant barrage of bots looking for crypto wallets and doing POST requests to index, registration urls, wordpress registration and admin paths, any vulnerable middle layer standard urls as well.
- mjmasn 5y agoOh great, now my good name has been sullied by crypto spammers.
- locusofself 5y agoHah. Reminded of Office Space, "Why should I change, he's the one who sucks" (Michael Bolton)
- Ozzie_osman 5y agoMy favorite technique (in terms of "how the heck did they think of that") is Google analytics referral spam. Spammers use bots to generate visits to your website, coming from a site they own that sells something. You (a website owner) see a referrer you don't recognize sending you traffic so you go see what it is. I fell for it a few years back (granted it was obvious when I visited the "referring" site that it was spam). It doesn't seem scalable but I guess if you're targeting website owners and able to automate this at huge scale it prob has some success?
- jsnell 5y agoI don't think the point was to get visitors directly from those links, but to hope that the referer URLs were ending up in some kind of publicly visible page (e.g. the logs directory of the HTTP website being exposed), have those pages indexed by search engines, and get a URL reputation boost from those inbound links.
- ravenstine 5y agoSpam can be mitigated by charging money for usage. Sadly, we've got this precedent where everything on the internet either needs to be free or freemium.
- jmnicolas 5y agoEternal debate, but the partisans of paying everything usually have Silicon Valley level salaries. For other people there are just too many things to pay for. So it's either free or they do without. If I take my case, C# dev in a small town in the east of France, I have about 100€ of monthly disposable income. I choose my battles huh expenses very carefully and compared to people around me I'm not an outlier.
- johnnyApplePRNG 5y agoHonestly it seems like spam account creation/SEO blackhatting has not changed in 20 years. Surprised, actually. I used to create and sell similar "linkwheels" as we called them back in the day. ...Sorry!