Spam accounts in 2022
joshbeckman.org
joshbeckman.org
They seem to have actual people that contact accounts/leads and their contexts from somewhere in India, and those people share spam accounts. Initially they try to sell you some tickets to an analytics and cyber security conference at first, but then they try to contact C-staff as soon as you start reacting.
The C-staff members then get trapped into the selling and audit game, so they offer free pentests / IT audits and "cyber security software" that can fix the problems (duh).
I created a honeypot with a fake domain and a fake company that doesn't exist, with emails that cannot be guessed blindly and with an email server that doesn't list its account names (and account names are not bruteforceable and neither guessable). Zero links on the internet, domain isn't even google-able.
Once I trapped them with private linkedin profiles and the people of whitehall media contacted the fake accounts, the spam arrived in masses. I'm not talking about 10 or 20 a day but in the thousands per day. And their network of hosts that they operate is _huge_.
My current guess is that they abuse administrative access to their customer's servers (the analytics/cybersecurity/IT-security forefront) to install their malware and send spam on their customers' behalf without them even knowing about it. We contacted our customers afterwards and asked all others whether or not they had contact to them; and if so that they start to double-check on their server infrastructure because it was very likely that they got infiltrated.
> rel="ugc"
> We recommend marking user-generated content (UGC) links, such as comments and forum posts, with the ugc value.
I mostly use "rel=nofollow noopener noreferrer" which should cover most "use-cases" of spammers.
It takes less faf for them to just post anyway than to check if you use nofollow/other, and they may still get a small side benefit if a blog-spam scraper or such takes your content and reposts it without the extra directives.
Either way, the spammer rarely spams his own thing. They spam what someone else pays them to spam, and don't care if it actually works as long as their customer believes it works (much like legal advertising).
Maybe to you. But you are not the only person in the world. And as the other comment said, spam still gets exposure to other comment readers.
Although not sure how much it's respected
Spammers don't bother checking existing links at their target site since indescriminate spamming at scale obviously works and doesn't need such finese.
It seems this is part of the automation, it got flagged based on this.
By the way, I am quite happy with JavaScript based spamfilters, they work quite well for small websites. The service Stop Forum Spam is something that seems fit for this, also at bigger scale. I assume Akismet might be good too, but it is somewhat leaky in privacy, depending on what you send to it.
Are there any other filters you recommend?
It doesn't seem scalable but I guess if you're targeting website owners and able to automate this at huge scale it prob has some success?
Surprised, actually.
I used to create and sell similar "linkwheels" as we called them back in the day.
...Sorry!
For other people there are just too many things to pay for. So it's either free or they do without.
If I take my case, C# dev in a small town in the east of France, I have about 100€ of monthly disposable income. I choose my battles huh expenses very carefully and compared to people around me I'm not an outlier.
https://www.fiverr.com/actressellen/record-a-professional-vo...
Just AI affiliate marketing
Such things require either consensus or tyranny, the former of which is nigh-impossible to reach and the latter being not exactly ideal.
> Once spammers fear for their lives, they will stop.
They could just as likely just improve their methods...
Sadly certification for services is not easy and very bureaucratic but then at least you as a user can be sure that nothing unnecessary gets revealed to the service.
This is >10 year old technology, by the way.
Companies can abstract this away and be certified by each government, e.g. like Stripe. It's nothing special.
Not really, unless you think of PayPal and Stripe as the "centralized authorities" of credit card processing. It's still a system with multiple authorities/centers of power; you'd just be paying a third party for the convenience of integrating those multiple authorities into a single layer of abstraction. If you're worried about the aggregator somehow subverting or altering your requests, you can always cut them out of the transaction.
It is enough that I need to tell the German "Verfassungsschutz" all my social media networks, all my domains, all times that I was in a foreign country for an extended stay just because I work for an agency that does projects for governmental institutions. Not that it matters, as I had to do a similar strip tease when I started my university job as a student helping the professor.
Not that I have anything to hide, but I just don't see the government having a track record of safe systems. Or keeping adversarial actordout of such systems. Additionally these systems might only be an election gone south away from falling into untrustworthy hands with me not being able to delete the collected data.
I might currently be living in a relativ (pseudo-)democracy. But if history tought us anything, that is nothing to be forever certain about.
And it might be tech that is >10 old. But I believe you will be hard pressed to find a significant amount of people in Germany (especially in tech) that would want to use it. Maybe the fact that nearly nobody is using it tells a lot about if this is an idea worth pursuing.
If you don't want to use this system, you will also never be able to complain about the government not offering digital services and requiring you to physically stand in line. The nPA is the base for those services and can be used today (provided the government provides the service digitally).
I've seen many Indonesian scams which utilizing many Blogger/Blogspot websites (which are definitely ugly) and phone numbers. Even though the government enforced all cellular phone numbers to be registered under a valid ID, this still not actually stop them to scam more people.
One of these scam sites is https://berkahmy-pertamina.blogspot.com which was published this year (see RSS/Atom feed for details) to impersonate Pertamina (national gas/petrol company) to run classic lucky draw scams.
Let see how many SIM cards you can count in this video: https://www.youtube.com/watch?v=vi4BlFXAnvI (at 3:30 and 8:40). This is from an actual Indonesian TV show about police investigation and was taken before the regulation was passed by the government.