The Frustration Loop
herman.bearblog.dev
herman.bearblog.dev
Newsvine had comments and upvotes and link submissions and posts - it was very reddit-esque except it was focused around the news. The team had to have a way to deal with spammers and trolls. They found the most effective way was to flag a user as a troll on the Newsvine backend. If the troll flag was set to true, Newsvine would add a random 10-60 second delay to every page load for the troll's account. IIRC it solved the problem pretty effectively.
> U.S. District Judge Naomi Reice Buchwald in Manhattan ruled on May 23 that comments on the president's account, and those of other government officials, were public forums and that blocking Twitter Inc TWTR.N users for their views violated their right to free speech under the First Amendment of the U.S. Constitution.
https://www.reuters.com/article/usa-trump-twitter-idINKBN1KV...
In the above case, the block was executed by the account holder who was a government official. Having the service provider flag a user as a troll and degrading their experience might be acceptable for comments on non-government accounts, but if a federal judge "flags" government accounts as public forums in a US court of law, then the service provider is now creating additional friction for a user participating in a public forum.
We have had political candidates and politicians like Alexandria Ocasio-Cortez doing AMAs on Reddit, so what I am describing is not a far-fetched hypothetical: https://old.reddit.com/r/SandersForPresident/comments/6ftvhu... .
(Rather like how lots of non-US banks block US nationals from having an account even if they're resident in the bank's country, because of the paperwork overhead)
It's not the same thing as a bank in another country refusing to open an account to an average Joe because of too many hurdles involved with reporting your balance the the IRS.
The practice is fundamentally malicious because innocent people get caught in it all the time. The two main problems both stem from the fact that they don't admit to doing it.
The first is that you're posting interesting things but nobody ever sees it because you're shadow banned, and then what you should really do is create a new account and start over, but you don't know why nobody ever sees it. "Maybe you just don't have much of a following yet." But you never will with that account. An innocent person is subjected to the penalty meant for a spammer -- and suffers longer for it because they have no reason to expect they're being punished when they haven't done anything wrong.
The second is that even if you figure it out, they still don't admit to doing it, the consequence of which is that there is no appeals process. So if you have an account with a significant following and then get shadow banned illegitimately, you're much more likely to notice this because your engagement falls off a cliff, but there is no process for undoing it other than to abandon your account and start over from scratch.
there's the confusion (unaware or intentional) between 'getting actually shadowbanned, as in, your posts actually do not appear to anyone else but you' and 'not getting free promo, free algo boost, free views from the platform, if it either doesn't choose to promote you, or chooses to not promote you' (these two are subtle but different as well). 'not getting the extra boost from a platform' - or just really 'having a piece of content fare for what it is, just by itself'. these kinds of mixups lead to kinda inane takes like 'i'm not getting as many views -> the platform has shadowbanned me', which are particularly weird to actually see, as a post, that is very much up and visible (and not "shadowbanned").
there's almost a vague sense of entitlement to getting views, getting an audience from a platform, in bulk and for free, and for whatever it may be. when a platform really just may choose to not extraneously promote something. or have a more sophisticated way by which some piece of content 'bubbles up', as it gets engagement and moves up in ranks of reach and virality. or it may downrank something, which still isn't a "shadowban". but lo and behold, "shadowbanning" now has its meaning so diluted, you'll just get talking heads throwing it around, and very visibly so - almost as if they're unencumbered by it and just saying a buzzy word.
"Well, the algorithm just isn't promoting you, that's not the same thing."
The algorithm is sorting a feed containing millions of posts. There is no mathematical difference between a penalty and the removal of a bonus that similarly situated accounts get. They both cause your posts to be not seen by people who would otherwise have seen it. You can easily be blocked from 95% of your audience and still be able to find people in the last 5% who occasionally see your posts.
The thing that makes it a shadowban is that it's a hidden penalty applied to your account, regardless of what you subsequently post or how the people who do see it respond to it.
no, a platform not promoting posts, and a platform hiding posts and making them not visible to anyone else at all, are not the same thing.
see, it's going as far with complaints about "shadowbanning" as to say "well maaaybe 5% might see it - But it's still a shadowban!" - that's the part that makes the complaints sound like bullshit that they are
How is it not shadowbanning? They're not showing your posts to people they would otherwise show your posts to because of an opaque penalty tag on your account. This can obviously be done to varying degrees ranging from not putting your posts in anyone else's feed, to not showing your replies even when viewing the post it's a direct reply to, to not notifying the person you replied to that they have a new reply because it was you who posted it.
These are all forms of shadowbanning. Meanwhile a given post might still be visible via some other means even when they're being applied.
> no, a platform not promoting posts, and a platform hiding posts and making them not visible to anyone else at all, are not the same thing.
This is a kind of pedantic reasoning where if you hide a post from very nearly everyone you want to call it something else because "very nearly everyone" and "everyone" theoretically isn't the same thing even if it's practically the same thing. It's like saying well, you know, technically we didn't remove you from the search results, we just put you on page 50384.
I've no dog in this fight, but this seems deliberately obtuse. You could call "traditional" shadowbanning "100% shadowbanning" and what you've just described "95% shadowbanning". They're extremely close.
The rich/ceremonial/leisure classes have through out history been constantly spamming everyone with whatever shit occurs to their 3 inch brains, because they can afford to buy the largest amount of attention.
To bad there is not enough attention for anything anymore cause production of content is happening at volumes that dwarf Consumption of content.
If 99% of comments and links on HN are not read by anyone, do you think the great geniuses who run HN will tell you that? Whats the use of such systems no one asks. They want to just keep it alive like some dumb engineers in the control room of Jurassic Park after the children are lost and the T Rex is loose.
The platforms, without knowing what the fuck they are building, have made it Free for everyone to Broadcast. So its now not just the rich who are spamming and trolling. Its everyone. For free. All you get is noise. Read the UN Report on the Attention Economy.
One dimensional software engineers now have capability to build and scale systems quickly. Thats the only reason we have these dumb fucking mindless systems wasting everyones time and energy.
I see what you did there.
Please never implement that idea though, it would be like the opposite of https://xkcd.com/810.
But of course it would be trivial to modify the llm output, to include random misstakes, if this ever would become a standard way of dealing with bots.
... or written by non-native speakers.
What's screwed up right now is we are currently forced to rely on 3rd-parties to filter for us, and they do so often poorly by just dropping content that's not "popular" which results in biased sampling, or worse, they select based on some kind of profit motive. Why can't we own our own "social media algorithm" or something? Why do I have to spend so much time consuming? Give me the IV drip, and filter out the unhealthy portion, please. Ideally, I should be able to trust the filter, too.
Akismet is very good at detecting comment spam. If it were any good at detecting signup spam then wordpress.com would not have so many spam blogs.
I also would track down spam blogs there. Sometimes manually through search engines and a curated list of known terms and sometimes with tools that one of the devs created for me.
I suspended thousands of genuine spam blogs. Sometims mistakes were made but they were rare.
Then, although some automated tools were created to try and stem the tide, that hunting and suspending was deemed not to be a priority. It was important at the start that wordpress.com was seen to be clean so it could grow but once deemed big enough, it was stopped. While I know I was using a supersoaker to put out a burning car it didn't take long and I found it satisfying
This time of year I'd be hunting hunting Halloween spam blogs and would start to see Christmas spam blogs too.
I have my own domain name for email. My email box accepts anything that goes the domain. I.e. a catchall email account.
However, I give a different email address to every site and service. I.e. sitea@mydomain.com, site2@mydomain.com
This lets my email reliably get auto sorted by who its from.
But I also use a consistent form to the names I hand out, so that random email that comes to my domain gets deleted instantly and I never see it.
I almost never get spam. But sometimes some service leaks my email somehow and I start getting some. So I change my email with that service (or cancel it) and add that email to a manual list of incoming addresses to block.
It's so dead simple, I feel like all email programs should have the option of working with a whole domain this way.
IMNSHO: sysadmins who do not know that the local part of an email address is not of their concern (as long as it complies to RFC 822++), are not worth their money. And web designers? Don't get me started on that topic ;-0
Edit: ok, they even allow "." and "-" in local parts.
- Fastmail masked emails (https://app.fastmail.com) - Firefox relay (https://relay.firefox.com/) - SimpleLogin (https://simplelogin.io/)
There's many more.
That, and the UI for disabling masks is much easier than having to create a new filter.
What I noticed is that the only spam I get goes to my mail address that's published on my blog and my github address. So it seems that nobody sold my address to spammers, they only scraped Publicly available addresses.
I've been doing it for many years and have already went through quite a few leaked addresses (at least a dozen or two, out of many hundreds). Even a small hotel, not part of any hotel chain, in Portugal in the middle of nowhere has leaked my address.
That said, I believe almost all of those leaks were due to websites or databases having been hacked, not due to them actually selling my email addresses.
When they sell my data (which has also happened before) I tend to get spam from actual businesses, often related ones. When the email gets leaked, I tend to get huge amounts of generic spam/scams (e.g. "your device was hacked!!"). You also tend to find the latter addresses on haveibeenpwned.com.
Besides that my postfix server is configured to reject connections, where the sending site does not have a reverse DNS mapping. Worked twenty years ago, is still useful today when I check my logs.
For example, if I get an email at anything_s@mydomain.com, that will go directly to spam. I use this for everything from Google to every small website I sign up on. They usually only spam anyways. And I check my spam every now and then for if there's anything important - there has never been.
I consider whatever most normal businesses send me spam as well, as I don't care for most of it. Uber Eats, for example, sends a number of emails per each order. That is just spam in my eyes. If I'll use a service I care about, I'll give it an email with a different alias suffix that will never go to spam. But I almost never do.
This has keep out the phishing spam when websites leak my email address just as well as the regular "important information about a minor interaction you did with us" spam that comes from most websites.
The problem is that I still need a general address for my website, resume, HN profile, Git author info... So I still accept mail to a handful of publicly available addresses. However it does let me play with the spam rules a bit more. Signed: auto-accept, known address: moderate spam filter, unknown address: heavy spam filter.
It's better than Gmail in filtering Spam.
The field of spam-prevention is fascinating because it's essentially an arms race between companies deploying tactics to detect spam and sophisticated spammers using increasingly complex methods to avoid detection.
So there's an advantage gained by companies if spammers believe they don't need to evolve their methods.
And my Instagram account got permabanned because they said I was impersonating myself. This was worse because I lost the entire account. They even had me send a selfie of myself and the instant I submitted the image was when they did the permaban lol.
Yay, incentives on social media sites are totally not perverted.
Some people have a knack for making content that goes viral, but for most folks, it's a muscle that needs to be learned through lots of practice, with a lot of early going seemingly bearing little fruit until the inflection point is reached.
I have an old account with almost 4000 followers.
TikTok just woke up one day and hated me. Hopefully it has a timeout on it.
So they could compare it with what, the content posted?
Read my suggestions here:
You're the sacrifice that they're willing to make to build their social media, and if you don't think it's fair... no one cares.
Even if this somehow offends people, those people will never notice that it actually happened.
Probably, this means that sane people should want the government to regulate at least those services considered essential to life to require appeals systems. Not TikTok, but I've heard of people losing access to Amazon forever. There are people for whom Amazon is essential, there are no local alternatives. And if the people wrongly permabanned from it ever overlap with those who can hardly live without it, then we have a big problem.
I got banned by disquss too! for posting many useful links in comments on blogs by people I know. They resolved the issue in 2 days and were wonderfully polite about it.
Akismet should at least clear wordpress users banned countless years ago and wp should replace it with something less well... insane.
I don't mind not being able to reply on my own wp blog. It is fairly amusing actually. Ill just use some other blog engine. Its easy for me.
but it seems bad for wp to refer to their users as uhh lets kill some spam??? Im not impressed.
> Enter Akismet... Blocking spam on signup worked somewhat, but was easily circumventable
> some spammers found ways to parade as legitimate blogs... which I would have to manually sniff out and flag.
> This lead me to an idea: The Frustration Loop... When spam is detected... Waste their time and make them give up.
> "Now hold up there Herman! Won't this be triggered by valid users?"... it's been running in production for the past 3 months and I've only had one user report this as an issue.
imo that would be the most interesting part of the article. It's cool that the action that's being taken is to frustrate the spammer but I wished there was more info on separating spammers from real users, figuring out false positives and false negatives and the like. I understand that giving details on detection is probably not a good idea and that the article is about The Frustration Loop, though.
afaik its main feature is an API to detect whether a given comment is spam: https://akismet.com/developers/comment-check/
So spammers noticed being blocked on account 1, created account 2 with legitimate content, and then started spamming.
New process is detecting spammers on first post but instead of immediately sending them away (or throwing their content into the void), go to some length to pretend the website irreparably broken in subtle ways.
The point is to waste their time before they realise they've been flagged, and have them give up.
> Enter Akismet. This is a spam detection tool by the Wordpress people and is pretty accurate and easy to use.
> Blocking spam on signup worked somewhat, but was easily circumventable by spammers who are well versed in dealing with these kinds of barriers.
But now that I look at Akismet's description, it sounds like Akismet does a lot more than block on signup. Perhaps they use it after signups but apply the frustration loop instead of blocks because it's less accurate there.
My thoughts on the loop overall are:
- maybe users are false flagged but not complaining because the "bugs" are rare enough
- spammers with automation may brute force through the "bugs"
- handles manual spammers well because they will encounter the "bugs" more often and just leave; or they'll report it as an issue that you may have to look into.
To draw a comparison with my own experiences, I have to jump through hoops when I visit sites with bot detection or other related security measures. I am the normal user being flagged as a spammer being frustration looped in this case.
That's the thing. It feels like no one wants to solve the problem; it will only hurt metrics and profits, I've already figured at this point /shrug
They all had default values.
If the submitting handler detected any values in these fields that were different from the default, the submission was rejected.
I don’t think I ever got a single bogus email from that form.
I got the idea from a book. Can't remember which, but it may have been in the early oughties, or even last century (and the book called it "Honeypot Fields").
The nice thing was, the user didn't have any friction at all. They had a subject and message. No CAPTCHAS, no math problems. Nothing.
The form was on a site with a fair bit of exposure and traffic. Another similar site used Contact Form 7 (or whatever the predecessor to it was), and we would get fairly regular spams. This was a plugin that I hand-crafted.
There are hidden input fields on the login page..
You're not the only one to do this, many pages do it whenever you do a vpn, they fail in silent and annoying ways not displaying any errors or otherwise. Turn off the vpn and everything magically starts working. Etsy for a long time would return blank pages if you were on VPNs. Extremely irritating.
It started with "suspicious activity detected on your account", followed by "your account has been disabled", and while it won't state the actual reason for this, the only realistic reason listed in their official rules would be that I posted something that offended someone.
There is one problem with this explanation though: I never posted _anything_. I follow a few people, that's all I do on instagram. So I filled in codes, sent them photos of myself, and eventually received access to the account again - but now it makes me log in again for absolutely everything I do. I can't believe they would do this by accident, or that it would be a bug. Clearly they identified me as a miscreant, and while they couldn't get enough evidence for an execution, they can sure as hell punish me for whatever misdeeds they imagine I committed.
I suspect what caused the problem was that occasionally you come across links to pictures on instagram. Apparently following those is suspicious enough that it warrants triggering a frustration-experience. Of course, being part of Meta also means that if they decide to shut down my instagram for good, I'll also lose access to my Facebook account, which I use to communicate with a few faraway friends.
Of course the world moved on from Facebook, and everybody is now on Instagram. I suppose I would be as well - if only it let me...
It's a race between your blog/website and other blogs/websites. If you're better protected than your neighbor, the spammers will go and haunt your neighbor instead. Especially when it comes to protecting against click farms, not against bots. As the joke goes, you don't have to outrun the bear in a forest, you have to not be the slowest in your group.
But that just means it doesn't flag you. What is a "dodgy action"? Other people might do things that you think are dodgy, without any malicious intent at all. A common one: if I sign up using Tor, is that dodgy?
It is very frustrating to get caught in these frustration loops.
Another approach might be to make it look to them like they managed to create their blog, but just quarantine the content so no one else can ever see it.
You either die an MVP or live long enough to build content moderation: https://news.ycombinator.com/item?id=28684250
Congrats on the milestone!
To make this clear to users, when posting content, the following is displayed: "Note: This content will not be indexed by search engines unless it has passed our manual review process."
Instead have them apply and pay for a review, thus monetizing the service?
But they read Hacker News....
It's a loop? I thought frustration is a constant state? It is for me at least.
This doesn’t completely solve it since people pay for any kind of link but it might reduce it.
Another one is to require a paid subscription to comment. It’s a filter for low effort spam.
Substack is an email newsletter platform and even that has a comment system.