CAPTCHAs and sign‑up quizzes annoy real people and barely slow down determined bots. As the fediverse grows, we need smarter, more humane defences, ones that don’t push away genuine newcomers. What creative, non‑intrusive ideas do you have? Trust‑based vouching, proof‑of‑humanity protocols, behavioural signals… what feels both effective and aligned with the open social web? I’m building a social media platform and I’d love to hear your thoughts on this topic.

  • mesa@piefed.social
    link
    fedilink
    English
    arrow-up
    4
    ·
    23 minutes ago

    I created a honeypot that creates a link only bots would think is a link. Then it gives them random words with another link. If they click the link 3 times they get ip banned by fail2ban. Works wonders! I can see my logs and the difference it made.

    I also have bots.txt that only the big players care about like google.

  • melsaskca@lemmy.ca
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 hours ago

    They should publish their “23 nd Me” results or at least prove which parent they loved more. /s

  • eicker@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 hours ago

    There probably is no magic solution: I would focus on making abuse expensive instead of making honest users miserable. Gradual trust, optional vouching, sensible rate limits, reputation, and behavioral signals together will outperform almost any CAPTCHA while keeping the door open for real newcomers.

  • m_‮f@discuss.online
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 hours ago

    It’d be nice to see public libraries take over this sort of thing. They can do community-based physical verification, without cost. They can assert that someone is legit, without revealing any private info. They’d have to be low-drama, boring infrastructure, in that they merely assert “This person is real”, without getting into “This person is good”.

    It’s not sexy like a new protocol or blockchain or whatever, but IMO it’s one of the few ways to really handle the problem, and also is a good way to help build local community.

    • Grimy@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      1 hour ago

      That’s a step away from showing ID. It’s not okay because your local (government owned) library does it. Even wirhout much info, it still becomes easier to dox if you have the person’s location.

      It would also be insanely complicated. How many libraries would need to be contacted and taught how to use some kind of software for this. It would be a mess.

  • Th4tGuyII@fedia.io
    link
    fedilink
    arrow-up
    9
    ·
    3 hours ago

    You could try Anubis? From what I’ve heard it works well against bots - but if not implemented properly can also block “good scrapers” like search engines and the internet archive that increase discoverability

  • Hubi@feddit.org
    link
    fedilink
    English
    arrow-up
    11
    ·
    4 hours ago

    It’s pretty much impossible IMO. You cannot possibly fortify every single instance against bots, there will always be ways around it. It’s just something that the open internet will have to deal with unfortunately.

  • rowinxavier@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    ·
    5 hours ago

    I hate to use the example, but one of the worst places on the internet actually found a solution for this a long time ago. $10. By having a small, but meaningful, fee for the account people couldn’t have unlimited accounts and there was a cost to getting banned. If you are posting bot slop you will be banned quickly and lose your $10. If you are not being bot like and also not breaking tonnes of other rules many times then you will not be banned and can keep your account.

    This works well enough most of the time. Getting a new account after your previous one has been banned can be done fairly quickly but that $10 adds up quickly and can fund the cost of reviewing and potentially banning bad actors. It doesn’t solve the problem in full, but another thing you can add is region gating. In your profile you set where you are going to be dialling in from, including which VPN providers and so on. This means you have a fairly specific pattern of behaviour that is white listed in advance. Now if your account is compromised and starts logging in from other places it can be blocked quickly, and also potentially the login attempts can be blocked and a password reset process initiated.

    Another option would be to require a invite only process and have those you invite reflect on you. For example, if someone invites a friend and that friend invites not accounts then both people are impacted. If someone invites 9 good people and 1 abused account their ratio is 0.9, if they drop below some value then they lose invite privileges. If you consistently invite crappy people or abusive bots you get banned, but if it happens only occasionally then you lose your invite rights for a while. Those parameters are all tunable but should help to get things operating more smoothly.

    Also, having invite periods but closing invites most of the time can also kill off many bots. People using bots are lazy, they don’t want to wait for months posting stuff and pretending to be a person to then use the accounts to post 3 junk things and then have the whole set banned. They want a large network of accounts they can throw away as needed. Make it slow, expensive, and consequential. Make botting 50 accounts cost $500 and also be a waste of time and the bots will stop coming.

    • jtrek@startrek.website
      link
      fedilink
      English
      arrow-up
      1
      ·
      24 minutes ago

      I would recommend the invite tracking. Keep track of who invites bad actors, even higher order. If your friend’s friends suck, that should reflect a little on you. If no one has vouched for you, then you’re less trusted.

    • lath@piefed.social
      link
      fedilink
      English
      arrow-up
      7
      ·
      3 hours ago

      I assure you, paying for an account is a terrible idea simply because some of the moderators/admins in charge are awful at it and will cause an incredible amount of backlash with their unlimited ban hammers.

      “I didn’t pay to get banned by a dumbass! Moderators must be elected and administrators must be held accountable for their poor decisions! As a shareholder, I cannot condone the misuse of my investments! … Etc”

    • CameronDev@programming.dev
      link
      fedilink
      English
      arrow-up
      15
      ·
      5 hours ago

      Using money as a gate has some issues. If you don’t scale the amount to the region, you effectively exclude that region. But if you do scale to the region, it encourages the spammers to simply setup their operations (either physically or virtually) in the cheapest region (physically also has the benefit of cheap labour).

      Requiring unique credit cards could mitigate that, but then there is PCI issues there, and its basically no different to requiring ID.

    • Zen_Shinobi@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      4 hours ago

      Requiring a fee wont stop anything. Look at old school Rubescape, botters pay monthly for their bot farms on the member’s worlds.

      • rowinxavier@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        Yeah, sadly I have to agree, a fee won’t do anything on its own. This would require a mix of features working together. Each makes botting a bit more painful and a bit less effective, but putting them all together makes it not worthwhile.

        Also, we don’t need to make a space perfect, just better than other places. You don’t need to be faster than the bear to escape, just faster than the slowest member of your group.

    • Da Oeuf@slrpnk.net
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      4 hours ago

      I think payment is a really good idea for deterring bots, and making people behave better too. It does leave a paper trail to your real identity though (unless instances are willing to accept cash or crypto), which many people would rather avoid.

      A fixed fee is also relative to who pays it. To a company who only care about jacking up their share price it could be nothing, but for a person working in a very exploitative economy it could be several days wages. I would say that it’s the poorest people whose voices are most suppressed, so I wouldn’t want to be part of that problem.

      Now, having said that, if there was a mechanism for distributing back the surplus from signups after running costs to good users of the instance I would be in favour of it. Per-user instance costs are very low on medium and large instances, so most users would get most of their money back, and perhaps even make money. Making it a cooperative would mean low costs for genuine users and incentivise participation in making it a good instance. If OP wants to do something like that let me know - I’d love to get involved!

      • rowinxavier@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 hours ago

        Ooh, I really like that idea! You are putting money in as a sort of deposit, but after a period of time it has served its purpose and the money can be returned. If I have to be active for say 3 months and also a certain amount of activity to get my deposit returned then burning the account after would be a pain in the arse and I would not bother. Having an account in good standing could also be a soft filter. Users could only show content from validated users and thus filter out all the bot junk, but if they wanted their comments and posts to show up they would go through the process.

    • CoderSupreme@programming.devOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      Thanks, the third option is what I had in mind but I had completely missed the automated banning feature, reviewing manually each time probably wouldn’t scale well.