15 ms·
Things I learned after getting users
- dhosek 4y agoMan, on the abuse front—it’s amazing the lengths that people will go through to put spam on the web. There are apparently canned solutions for pushing stuff to any Mediawiki site, although I found that a really stupid captcha¹ was enough to bring that down almost to zero, but early on with rejectionwiki, I had the same sort of chronic abuser things happening that are described in the article. ⸻ 1. Basically a set of really obvious questions, like “Who wrote Hamlet?” and what’s “Shakespeare’s first name?” that any writer (for whom the site is targeted) should be able to answer.
- warkdarrior 4y ago> Basically a set of really obvious questions, like “Who wrote Hamlet?” and what’s “Shakespeare’s first name?” that any writer (for whom the site is targeted) should be able to answer. Given that ChatGPT exists now, I assume these questions will need to be replaced with something harder to automate.
- juped 4y agoChatGPT would be an extremely expensive way to answer these questions.
- addisonl 4y agoAt MOST that is a 100 token prompt/response, so that is like $0.0002 to answer with gpt-turbo. Hardly going to break the bank...
- corobo 4y agoReally? I thought these types of questions would be limited. They seem hand-crafted. If you cache the answers you're probably looking at 10 queries or so until the site admin gives up on that idea and tries something different
- dhosek 4y agoGiven that the spammers seem to use some sort of canned software, it might have been enough to figure out how to change one or two internal URLs in MediaWiki, actually.
- josephg 4y agoYep. I think writing code is quite difficult for most spammers. They often depend on hacked together scripts and things other people have written. Making those obvious scripts fail can make a massive difference. I suppose people who can write good code can usually make a lot more money by getting a real programming job. Years ago I heard of a simple anti-spam technique where you add extra form fields to a web form. Then use CSS to make those fields invisible. Put a check in your backend where if you see any content in those form fields, you respond with 200 OK but ignore the request. The programmer in me can immediately think of 10 ways to get around that - the most obvious being to fill in spam using a real web browser, automated via webdriver or something. But apparently that one trick removed ~95% of spam on their site.
- codetrotter 4y ago> Who wrote Hamlet? Sir Francis Bacon :smirk:
- naniwaduni 4y ago> that any writer (for whom the site is targeted) should be able to answer hey now, not all writers who discuss things in English are necessarily familiar with the anglo literary tradition (it's probably a higher overlap than average, and shouldn't be too hard for them to search, but be careful throwing the assumption around)
- chrismorgan 4y ago(Ooh, three-em dash. Fancy! I use two-em dash very occasionally in prose, and —⁂— as a section and footnote divider, but haven’t found anywhere I really wanted to use three-em dash, though I did still add a Compose key binding for it.)
- cousin_it 4y ago> some users have suggested pretty smart features that i've since implemented, like this back-to-top button to quickly get back to the top of the page To me all position:fixed elements (headers, footers, this back-to-top button, etc) feel like a kind of annoying dirt on the screen. Their absence is a big part of why I love the web 1.0 aesthetic.
- nicbou 4y agoMe too, but I still added a table of contents button on my long, structured articles. It's very helpful in my opinion.
- layer8 4y agoWikipedia does this now, and I find it annoying, in particular the changing “current section” highlighting, and the fact that it hides when the browser window is a bit narrower. I’d rather press Home to get to the TOC again when it scrolled off.
- retox 4y agoAgreed, seeing something changing out of the corner of my eye is very off-putting.
- nicbou 4y agoHm, I can see where the criticism comes from. Is there a way to keep this feature that would make it more acceptable?
- layer8 4y agoPersonally I don’t think it’s worth the benefits over just having a TOC at the top of the page, as is otherwise customary. It’s different if this is a web site or web app where you have an account, and where users can permanently enable/disable it as an option when they prefer it. But on a public web page for a general audience, it always introduces friction by being visually distracting (because it doesn‘t scroll with the rest of the page), or by hiding due to responsive layout (requiring the browser width to be adjusted, or having to toggle it by mouse instead of scrolling to the top by keyboard), and so on.
- econnors 4y ago> when the site first got a surge of users from hacker news, there was one poster in particular who came to the site, registered a bunch of offensive, racist usernames and proceeded to post and create threads that were just full of dumb slurs. this was definitely a learning experience because i had to act quickly, so i tried a bunch of different methods to get rid of him. it's sad that people like this exist in the world. what could possibly motivate someone to spend their time doing this?
- flangola7 4y agoAttention seeking + lack of moral compass.
- yamazakiwi 4y agoA lot of them are edgy underage children and don't know any better. They think that they have a dark sense of humor but really they've lived a life disconnected from those words, so they like the idea of pushing others buttons at no cost to their selfish existence.
- wolfi1 4y agonot only attention seeking, sometimes the motivation is "to spread the truth", at least as they perceive it, and sometimes it's people who get triggered and are not able to stop their rants
- expertentipp 4y ago"Is my girlfriend pregante?"
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- nicbou 4y agoI dealt with a similar basket case once. It seems like parasocial relationships can swing both ways. You know how some fans develop a creepy, obsessive sort of love for creators? Well, the same goes for hatred. They feel slighted by that person that doesn't know them, and they retaliate from behind their keyboard.
- monroewalker 4y agoAre you paying for Sentry? What type of monitoring does it provide? I'm working on a project I'd like to add some monitoring so I'm on the lookout for a good solution. Looking for something free though until there's a need to have better insight than I can get without paying for it
- benaduggan 4y agoMy team got really far using something called GlitchTip. It's compatible with the Sentry SDKs, but really cheap, so it felt like there were minimal consequences to switch if we ever had the need to. We only switched to Sentry cause our company was acquired and they already had a Sentry subscription going.
- monroewalker 4y agoHadn't heard of GlitchTip, but will look into it. Thanks!
- kevincox 4y agoI'm using the Sentry free tier and it is great. The main value is how to managed repeated errors. You can group different exceptions for the "same" error, resolve errors that have been fixed or ignore known errors until they occur to more users, more often or what have you. If you are good about squashing errors you can make it very far on the free plan. Plus they have some burst detection built in. Just make sure that "expected" errors aren't just ignored in the UI, stop emitting them in the app itself so they don't count towards your quota (and it keeps your logs tidy). I haven't been using their tracing or anything because their Rust SDK doesn't seem to support it despite claiming that it does (or I have set it up wrong).
- monroewalker 4y agoThank you for elaborating, this is useful :)
- partly_cloudy 4y agoi am not! right now, i'm mostly just using it for performance monioring - how many MS are my queries taking and how long are my first-contentful paints on the front-end also for errors from the BE and FE
- hermitcrab 4y ago>listen to your users. they might have better ideas than you! So true. My products have improved greatly from listening to (some!) user feedback.
- yamazakiwi 4y agoUsers that give great feedback also generally give great feedback in the future.
- OJFord 4y agoAnd if you're going to do it, make it easy. Many sites have missed out on my thoughtful (not to say I'm 'right', but that even if they don't want to do it it's considered and reasoned) feedback simply because the process although offered requires a login (i.e. sign-up) or because the last time I tried I got some dumb email back thanking me for my question it's not really possible but I can work around it by (x y z that I already said would be easier if w) and do get in touch if I have any more (sic) questions. If you're going to solicit feedback, just dump it in an ideas bucket, no need to reply, certainly don't funnel it through the support channel for bugs/questions.
- hermitcrab 4y agoI always reply to feedback. Seems only polite.
- OJFord 4y agoCertainly, I've had some great even more thoughtful/in-depth replies too, it's just the ~zero effort template support-channel 'thanks for your question'/'unfortunately that's not possible today' type response - I know, that's why I gave the feedback; all it does is tell me it didn't get anywhere near the right person, which is a souring experience (and waste of my time & effort) and makes me wish there just hadn't been a feedback button to begin.
- dgb23 4y agoIf you can recognize good feedback and manage expectations well. From a user’s perspective there is typically a tipping point for a thing that becomes popular enough where user feedback becomes useless, superficial, lowest common denominator crap, which doesn’t understand the value prop, the quality standards and the implications of change vs stability. I believe this type of feedback often bubbles up for similar reasons bikeshedding can become a problem, which is then perpetuating through social media. At this point one needs a filter.
- Joel_Mckay 4y agoYes, there are numerous automated and human-powered nuisance traffic streams. 1. CMS sites are constant maintenance, as most are an endless supply of issues. However, some have content caching to reduce the SQL workload. 2. Delayed registration with CAPTCHA and a brief explanation of why you are there. Quiet banning IP filter applied to list to boot pending users who enter emails that bonce or fail to authenticate. 3. Firewall blacklist areas of the world where you don't do business (better yet, whitelist the ISPs in the regions you do business), blacklist proxy/tor/spam IP ranges, add port tripwires, and setup rate limited traffic per IP (see slow loris mitigation methods if you are not using nginx). 4. add peer site content blocker for forum spammers/bots i.e. share exploit probes preemptively with the rest of the net. 5. add email filter for mention of bitcoin/BTC, and black-hole the entire IP block if in an irrelevant region. 6. lookup same-origin enforcement for your web-server, add Subresource Integrity Hash to your core, and re-scale/watermark/scrub all media to protect users from themselves. 7. fail2ban rules for common site security scanners, known exploit attempts, and common email scams. You owe nonpaying users nothing, so the collateral cost of blanket bans is $0 in hostile regions. Remote traffic monitoring is also recommended if you have a game engine running. On day 2 we can look at how BTC tumblers/launderers fund most of these issues, and whether it is OK to also preemptively blanket-ban most cloud/hosting providers (costs under 7% of your users in most cases). Remember, adversaries will often pretend to be from wherever they wish to inflict harm, and time does not have an associated cost in the 3rd world. Have a gloriously wonderful day =)
- hderms 4y agoHey there! Thanks for your comment. What do you specifically mean by rescale/watermark/scrub content to protect users from themselves?
- Joel_Mckay 4y agoThis is done mainly to strip off meta/EXIF/GPS Data, and mitigate other format violations often used to cause "trouble". Resampling/transcoding also tends to corrupt steganography utilities, thrash user hardware thumbprints, and standardize the web experience by excluding unsafe formats in favor of well-tested efficient traditional codecs. Specifics preclude the multifaceted nature of the policy. https://www.youtube.com/watch?v=cJMwBwFj5nQ https://www.youtube.com/watch?v=cJMwBwFj5nQ Happy computing =)
- dahwolf 4y ago"this is mostly because i relied on a SQL ORM which in short is a tool that makes writing SQL easier to pick up and faster to develop. the biggest downside is that it might execute 50 queries to your database to get a list of information, when it probably only needs 1, which will cause slowdown." I appreciate this honesty. Listen to this old man's advise: learn SQL properly. It's not that hard. Focus on it for a few weeks intensely and you've mastered it for life. Then just write SQL directly. I've had weekends ruined troubleshooting my "highly productive ORM layer" that nuked a production database. Whilst functionally speaking my ORM code was in no way incorrect. I'm talking differences of a thousand fold in query load depending on how one expresses the ORM calls. You can then become proficient in trying to reason and predict about what your ORM calls do in the actual database, but when you're several joins deep, this becomes near impossible. At which point you become the ORM, and might as well just write SQL.
- andrewstuart 4y agoThese days I build applications that actually use SQL. Typically a single statement to get the job done for any query.
- akprasad 4y agoIf writing SQL directly, what process do you use to update your queries during schema changes? Do you rely on a test suite to catch errors then update queries by hand? Are you using compile-time checks through libraries like sqlx [1]? [1]: https://github.com/launchbadge/sqlx https://github.com/launchbadge/sqlx
- willio58 4y agoThis is exactly why I find no solution fits all here. For me, I use an ORM as a catch-all and then for certain applications I manually write the queries. It's best of both worlds, and I know what components in my app have custom queries so I can test against them.
- tetha 4y agoSorry to butt heads there, but what ORM does automatically handle schema changes? I have so many teams with highly abstracted ORMs telling me that no-downtime schema changes are impossible, no matter how trivial the changes are, or would be in e.g. Hibernate. And the only team capable of zero-downtime schema changes uses a minimal DSL to SQL lib.
- mcstempel 4y ago> this worked for a little bit longer, but he proceeded to get on a VPN, and then another when i blocked that IP, then another when i blocked that IP, etc, etc. Beyond VPNs, I've even seen attackers leverage residential IP networks which makes VPN detection ineffective as well [1]. If you ever need a more permanent identifier to ban users on, consider using a device/browser fingerprinting tool [2]. It helps avoid the whack-a-mole issue of more sophisticated attackers churning IPs/emails/user agents/etc. [1] https://brightdata.com/proxy-types/residential-proxies https://brightdata.com/proxy-types/residential-proxies [2] https://stytch.com/products/device-fingerprinting https://stytch.com/products/device-fingerprinting (I'm admittedly biased towards our solution as I work at Stytch)
- alam2000 4y ago[dead]
- eks391 4y agoAlthough difficult and not well known about, fingerprinting can be randomized[1]. I have been successful creating a random fingerprint on only Brave so far, but I did need to tweak some browser settings. 1 check your fingerprint details here: https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/
- TulliusCicero 4y agoI'm surprised that they're surprised about trolls. As someone who's been doing PC gaming a long time, I always assume there'll be people who just want to ruin things for everyone else. What they're attracted to is popularity, so the better you do, the more you'll have to deal with them (they tend to grow slightly superlinearly relative to overall user growth). This is basically every game or internet forum that acquires even a little popularity: there will be some (few) people who just wanna ruin everything, and I'm always surprised by how many people are surprised by this even when they're the technically literate sort. For example, some Japanese fighting game devs still try to count disconnects during a match as different from losses for someone's record. One guess as to what this encourages as far as player behavior goes.
- scoofy 4y agoI have a site that will likely need a denylist for usernames. Do you have any resources on implementing that? I mean, it sounds obvious how to do it, but if it's already been done, I'd rather just have a list to work from.
- partly_cloudy 4y agothe denylist on the site is actually pretty quite simple. for now, it's just a list of chunks of words and the form validation will just compare the username against that list, where each chunk in the list if used as a regexp
- monroewalker 4y agoYou could also consider shadow banning these users. If you're immediately preventing them from creating accounts with certain usernames, they'll probably just get more creative with the profanity or save it for their posts.
- mydriasis 4y agoHey hey! Been loving your forum so far. It's been great chatting with folks. Hoping for many years to come.
- partly_cloudy 4y agohey i'm the author of this site! going through comments now, but looks like i still need some work to do because all this traffic caused some slowdown :(. Looks like adding a caching layer is next.
- diceduckmonk 4y ago> someone is going to abuse your site Would gating access with Google Sign-in, or Facebook sign-in, etc, be sufficient for rate limiting bad actors?
- godshatter 4y agoGoogle and Facebook both have too much data about me already, why would I voluntarily give them more? This isn't probably that common of an attitude, though.
- beardog 4y agoA good way to combat abuse is to not feed the trolls, don't engage beyond a warning or two, simply delete and definitely don't argue publicly.
- hoseja 4y agoBlacklist please. Blocklist if you absolutely have to. "denylist" is an abomination. Oh I see, a goon.
- Sujeto 4y agoCurrently I'm using a code method, where registration requires a "code". I share this code lightly, and can change it at any time. Plus there's a re-captcha in both register and login pages to annoy abusers a bit more.
- flippinburgers 4y agoAKA blacklists are useful.
- gloosx 4y agoThe best way to deal with point one – ghosting. Feeling sorry to see 3 greatly ineffective, and 1 desperate method to get rid of the abusive spammer. I had experience with the community-driven portal, and trust me - the best way to exhaust the spammer - hide his posts from others - don't give him a single clue you acted on him, just let him continue posting in a special vacuum prison crafted exactly for him.