I accidentally made my link shortener into a malware honeypot
app.y.gy
app.y.gy
The second most effective thing is making the malicious actor use some sort of resource. Such as a payment (the author uses), or a time commitment (eg new accounts can only create 1 link a day), or some other source of friction. The idea is that for legitimate users the friction is acceptably low, but for consistent spammers the cost becomes too high.
The 3rd thing I've found effective is that lots of spam comes from robots - or perhaps robots farming tasks to humans. If you can determine how the traffic is coming in and then filter that traffic effectively without indicating failure, robots can happily spam away and you can happily filter away.
Still an interesting idea though.
If there’s anything I have learned about IP based blocking, it’s very unreliable. Especially in a NAT’d world.
Great you “shadowbanned” an IP, but you also impacted many other people and devices behind that public IP including the bad actor.
IPv6 is supposed to make NAT irrelevant but adoption is still very low despite IPv4 deprecated more than 2 decades ago.
And IMHO, NAT won the fight against IPv6 because it’s backward compatible.
The entire /64 will nearly always be a single ISP customer, not thousands of customers behind one address as it can be for IPv4. And you can start by banning the /64 and then widen the mask, say, 4 bits at a time if abusive traffic continues from an adjacent range. It's not that hard to automate this. Then the /48 gets blocked only if you see abusive traffic from multiple ranges within it, implying that the whole range is controlled by the attacker, or that ISP does nothing about abusive customers, which is nearly the same thing.
In this scenario it doesn't matter. Some user might be able to access the malware still, but that's better than not blocking it at all.
> Shadowbanning is extremely hostile to users that have been mis-identified as spammers (which will happen)
It should always be a manual action and moderators should continue to see messages of shadowbanned users. You can always lift it in case of a mistake.
If you're going to have a free tier on your service and your service has any sort of interaction going on between users that could be degraded by spammers and the mentally insane, you're going to need shadowbanning. It's either shadowbanning or upping the hurdle to creating an account considerably.
The risk of misidentifying legit users and shadowbanning them outweighs the potential gain.
What's the risk?
Because if done correctly the user never knows they are shadow-banned. It sounds trivial when you know _how_ the shadowban is done. But for instance, instead of an IP check, perhaps it's a time check - after 3 days it comes into play. Or a combination of different checks. So imagine that you are accessing a service that appears to be working correctly .... you would basically need to a) determine that that service even does shadowbanning, and b) think of infinite ways that you might be shadowbanned and try to determine if that's the case.
A big problem that came up at the domain level was what I'd call
a _trustworthy domain with untrustworthy subdomains_, specifically
where those subdomains represent user-generated content.
The Public Suffix List (PSL) [1] to the rescue! It can help with this kind of disambiguation.Paraphrasing, it's a list of domains where subdomains should be treated as separate sites (e.g. for cookie purposes). So `blogger.com` on the list means `*.blogger.com` are separate "sites".
It looks like the repo where the list is maintained [1] is pretty active. YMMV, I'm not a maintainer or anything..
It made sense back before Twitter had one of their own. And I know that some people use it to get link analytics. I've also occasionally seen it used for printed materials, to get pretty URLs that are easy to hand-type.
People also use it for malicious purposes, such as hiding malware, or disguising referral links, or otherwise trying to obfuscate where a link is going. (Note: I'm not calling referral links malicious, I'm calling disguised referral links malicious.)
Other than printed materials (which need pretty URLs and thus often need a dedicated first-party URL shortener) and analytics, what are people using third-party URL shorteners for today?
But most public ones don’t let you change the redirect.
“q.ly/abc” or “website.com/20240229/my-blog-title-here/1”
But as some have mentioned, QR codes have easily replaced URL shorteners for this purpose anyways.
Also I guess for the very small number of people without a device that can’t read QR codes, a shortened url would help them engage
I also use it to hedge my risks from using SaaS. For my org, we host some things that we offer to the public on different services. Sometimes a vendor doesn't work out. We use our shortened URLs in public communications, and I can redirect them to our new service if we need to switch. It was a way to address my discomfort with URLs that break too easily when you host on 3rd party services.
Also places where the cost to change the url is expensive, bus shelter adverts etc.
A link shortener doesn't solve any of those problems
I think a conservative estimate of link shorteners usage is that 99% of cases are used by bad actors, and if they would all die out my life would be a lot easier. But, every week it seems some new one pops up and theres a new wave of spam to deal with.
At least thanks to this post I can add a new one to the filters before a wave of spam, so yay?
In a sense, Google Search is even more evil because they change the destination link on-click. So hovering on a search result link doesn't show you the true destination.
(Also note the difference between the length of the "Advantages" and "Disadvantages" sections)
Right now any phone should be able to parse a url if it can read the type, and so what is the point of QR besides the ubiquity?
Also the longer a url is out in physical space the more danger of it being replaced online, longevity may not be desirable.
Be careful relying on Stripe to prevent these users. Next they will start using stolen credit cards to create accounts then you will face disputes. If you get too many, Stripe will prevent you from processing payments.
About a year ago, I launched a service called Link Shield. It's an API that returns risk scores (0-100) on URLs. It uses AI and other services to score if a URL is malicious. Check it out and let me know if you would be interested in trying it linkshieldapi.com/
I don't want to provide my data to multiple services just to be able to compare their prices and find out which one I'm actually gonna use. At first this will lead to countless automated mails from all those "founders" asking why I haven't started paying yet, and if I'm unlucky my credentials end up on haveibeenpwned.com…
Integrating a new system requires some effort. And there are some systems, like the one in question here, where there's a real cap on how much value they could possibly provide for me, even if they're perfect.
If I can't see whether the pricing falls in that range before I need to sign up, I'm just not going to seriously consider it for most services.
I would not use something like this to send my customer data to the thing to check a link, but if it was something that could be self hosted on my vps and a script to attach wordpress chat system to check with it - maybe..
But with no pricing showing, I am assuming I can't afford it anyhow.
Established players like bitly and tinyurl didn't have all the resources to deal with the problem when they started out either, and they arguably still don't, yet they get favored by the antivirus vendors and "safe"search blacklists, since they're well-known services. It doesn't seem fair.
Is this really the way it should be? I wonder if they could've explained the situation to the antivirus vendors: The site itself doesn't host malware and doesn't allow the discovery of said malware through its service. It requires a user to receive an exact URL, just like they could've received any other link, and the blocklists should operate on what's hidden behind it instead of the redirect in front. Maybe y.gy could've been hooked into the safesearch API to automatically nuke any URLs blacklisted already by them, or another antivirus vendor.
I prompts me to wonder whether abuse was one reason that Heroku removed their beloved (among students) free tier.
If you're going to provide people with free compute online, there are just a lot of ways to exploit that.
Between gift cards, money mules, shell corporations, and "that country doesn't cooperate with investigations"...I'd guess that this is no more than a minor problem for serious criminals.
For the malicious links, did you have a chance to track whether the malware actors verify that their links do not work, e.g. by setting a cookie when they make a link and checking it later ?
I wonder if making these malicious links silently work only for the people that submitted them (and to say “no such link” for everyone else) ought to create a degree of confusion and slow them down to some extent at least…
Kinda sad that this is what the online world has become.
And we just put up with it.
Imagine if walking down the road each day was like this – people lining up ready to swindle you or manhandle you in order to steal your things. There would be outrage. But online we have just sort of reached a weird state of acceptance I guess.
The time it took you to write all this evidences the problem with hosting the service publicly.
Yesterday I ran into problem with sharing a link to a simplex.chat group which was so long my website builder translated it incorrectly. I looked at link shorteners publicly available and now understand from your writeup why they are somewhat limited now. I found it easier to just spin up my own link shortener on my webserver using Shuri. It took less than a minute for me install. I won't publicize its availability now that I have read this.
My thoughts after reading the article: I was so right.
So for a service at $4 a month which is likely to get a lot of fraudulent payments I wonder if it's really viable.
One thing he should do is immediately cancel accounts and refund subscriptions when there's an early fraud warning. They are usually accurate and help avoiding those fees.
Many many years ago I ran a small forum for a small webcomic, and one day it was just full of low effort scams and spam. For an audience of, I dunno, a dozen people? I just shut the whole thing down because it wasn't worth our time to do anything about it.
We just can't have nice things, and if you run across something that is actually nice, make sure to thank whoever runs it for all their behind the scenes effort to deal with the scumbags that clog everything, and I mean everything, up with s(p|c)am.
Thankfully after a couple years, I convinced them (it took several tries) to use a 3rd party hosted provider.
Bullet dodged.
As it turns out, my ISP was simply doing a rubbish job at blocking the site. After a few 10s of tries it eventually managed to redirect me to their warning page and prompted me to turn off settings in my account config. Thanks Virgin Media.
The price of success is you then need to deal with moderation in some form. (and on that note: "it is easier to automate bad behavior than it is to police it")
Right now, "enshittification" is (rightly) on many people's minds, but before that the reason any company makes a process difficult is because some assholes ruined it for the rest of us.
Parasitism is the reason things are as they are. But we got Sex out of it [1], so that's nice? Maybe?