5 ms·
I don't think Javascript tricks work very well against motivated spammers. It is trivial to use headless WebKit client to execute Javascript and ajax requests.
by obsession 14y ago
I don't think Javascript tricks work very well against motivated spammers. It is trivial to use headless WebKit client to execute Javascript and ajax requests.
- Goopplesoft 14y agoThats for bots customized to run on your site. There are generic spider-like bots that look for forms they can submit into, without knowing anything about the sites architecture.
- its_so_general 14y agolike the other poster says, this is just a cat-and-mouse game. If the mouse gets big enough, garfield gets off his lazy ass and eats it.
- duiker101 14y agoI think that at least 90% of the bots are not made to work on specific sites. Unless your sites has millions of visitor I so not think someone will spend time to make a bot just for you.
- threedaymonk 14y agoI'm reading this thread whilst running a full-stack test suite against my app - using a headless WebKit client. I expect spammers will do the same if and when the JavaScript-unaware methods stop yielding an acceptable return, but given their low costs that threshold may be a long way off. I use something similar in my own site: a field in which the commenter is asked to fill a specific value. If they're running JavaScript, I fill it in for them and hide the element. So far, it works perfectly. As other commenters have pointed out, however, this kind of defence only works against generic attacks, and defending against a targeted spam attack will always be difficult. But for the generic case, there will continue to be simple things you can do to thwart naive attacks. One that springs to mind is to introduce a scripted timing element. A spam bot won't wait a minute before submitting, but a user should at least have read the post they're commenting on.
- gambler 14y agoProgressive enhancement for bot detection... I like your idea. This is much, much better than simply stopping anyone without JS enabled from using the form.
- vidarh 14y agoIf by motivated you mean "want to spam your site specifically at any cost", you're right. But running javascript multiplies their processing costs substantially and it also means that at that point their costs can be driven up far higher simply by making the computation required to post higher - it doesn't take much - say a few hundred milliseconds of hash calculation on posting - to suddenly tie up a lot of resources for someone trying to spam as many people as they can for as few resources as possible. For any spammer that has softer targets it makes little to no sense to bother.
- eli 14y agoNothing works against motivated spammers. For high value sites, they pay real humans to operate real browsers to post spam comments on your site.
- krapp 14y agoClearly the answer then is to kill all the humans.