denise: Image: Me, facing away from camera, on top of the Castel Sant'Angelo in Rome (Default)
Denise ([staff profile] denise) wrote in [site community profile] dw_maintenance2023-09-24 04:49 pm

A heads up on spam prevention measures

Due to recent increases in spam account registration (over and above the already-high baseline levels of spam account registration!) and the amount of our administrative time that dealing with spam is costing us, it's highly likely we will need to start playing around with more aggressive measures to block spammers in the next few weeks. We already use quite a few spam account creation prevention techniques, but there's been a worldwide increase in the amount of abusive/spam traffic over the last six months or so, and we're at the point where we need to start getting much more aggressive about filtering it.

Generally speaking, we try to use the least restrictive measures of spam blocking that we can, because any form of spam blocking can impact legitimate use of the site. If you start getting 403 errors when accessing the site, or you are asked to solve a captcha from our hosting provider (the graphical captcha that shows on a separate page, not the text-based one that shows on the same page) before proceeding to the page you're trying to load, and you are not using a VPN service, please email support@dreamwidth.org with your IP address and let us know. If you don't know your IP address, you can look it up at whatismyip.com.

If you are using a VPN provider and you get these errors, I am incredibly sorry, but we probably won't be able to help. We know that many of our actual-person users use VPNs for privacy and security reasons or to circumvent government restrictions on accessing the site, and we are trying our very best to keep those services able to access Dreamwidth. Unfortunately, VPN services are also a major source of our abusive traffic, especially the free ones, and it's impossible for us to distinguish legitimate traffic from abusive traffic automatically. You are less likely to have problems with paid VPN services, but even those are the source of a lot of spam: our two main VPN sources of abusive traffic are NordVPN and Proton VPN. We're trying very, very hard to not have to block VPN services entirely, but the problem is getting much worse. If you subscribe to either, you may want to contact them and tell them that you've been having problems accessing sites you regularly use because of the amount of abusive traffic that comes from their network.

We will continue to tweak our spam prevention measures as much as we can to avoid interfering with legitimate traffic, and I apologize in advance if we wind up temporarily interfering with your use of the site as we try to stop the garbage we're drowning in.
the_broken_tower: (Default)

[personal profile] the_broken_tower 2023-09-24 09:00 pm (UTC)(link)
Completely understandable and unfortunate the abusive traffic is becoming such a problem. Thanks for the heads up!

- Ellie (she/her)
(reply from suspended user)
havocthecat: the lady of shalott (Default)

[personal profile] havocthecat 2023-09-24 09:04 pm (UTC)(link)
Can you give us a heads up if you plan on blocking any of the VPN services? I use a paid VPN for my own reasons and I totally support your spam-blocking measures! But I would like to know if I need to alter my Dreamwidth access processes if I have to. Which I will do in order to keep supporting you.

And I'll try letting them know, but uh, you know. Idk how much it'll work.

(no subject)

[personal profile] havocthecat - 2023-09-25 19:51 (UTC) - Expand
ninetydegrees: Art & Text: heart with aroace colors, "you are loved" (Default)

[personal profile] ninetydegrees 2023-09-24 10:09 pm (UTC)(link)

Thanks for the heads-up! That explains the captcha I get :)

vesper_evensong: (Expressions - Thank You 2)

[personal profile] vesper_evensong 2023-09-24 10:46 pm (UTC)(link)
Thank you for your efforts in these areas. It has made DW a very decent place to be. I migrated from LJ because it's hard to use for Americans now, and as I've used DW I have appreciated the regular updates on things, and how hard you all work to keep things up and running smoothly.
(reply from suspended user)
nerakrose: drawing of balfour from havemercy (Default)

[personal profile] nerakrose 2023-09-24 11:06 pm (UTC)(link)
Ah that confirms why I was getting 403 error messages when I had my VPN on the other day (I use NordVPN). I did figure it was a VPN thing as I’ve run into similar on other sites so didn’t log an error message. It’s not a big deal for me, though I understand it might be more of an issue for others.

I was wondering, and this may not be viable at all, is it possible to flag and exempt logged in accounts that use VPNs so this doesn’t happen for them? As in, my user account at fanlore has that kind of account flag (I reached out to them about it) so that I can access and edit entries even when my VPN is on, that was something they were able to do. The infrastructure here may be completely different though so this may not be a helpful suggestion at all!
devilc: Go Like Hell (Default)

[personal profile] devilc 2023-09-25 02:46 am (UTC)(link)
I would just like to echo this suggestion.

(no subject)

[personal profile] twoeleven - 2023-09-25 04:21 (UTC) - Expand

(no subject)

[personal profile] innitmarvelous_og - 2023-09-25 04:48 (UTC) - Expand

(no subject)

[personal profile] thesaltinstitute - 2023-09-25 07:40 (UTC) - Expand

(no subject)

[personal profile] amalthia - 2023-09-25 18:23 (UTC) - Expand

(no subject)

[personal profile] pinterface - 2023-09-26 00:44 (UTC) - Expand

(no subject)

[personal profile] pinterface - 2023-09-26 14:48 (UTC) - Expand
morrow: (💋)

[personal profile] morrow 2023-09-24 11:09 pm (UTC)(link)
Fair enough!
watersword: Keira Knightley, in Pride and Prejudice (2007), turning her head away from the viewer, the word "elizabeth" written near (Default)

[personal profile] watersword 2023-09-24 11:15 pm (UTC)(link)
Thanks, I hate it! (I don't hate you, D. I hate that spam is still a problem.)

(no subject)

[personal profile] corbiecore - 2023-09-26 13:12 (UTC) - Expand
house_wren: glass birdie (Default)

[personal profile] house_wren 2023-09-24 11:58 pm (UTC)(link)
Thank you for all your work!
scissorsevered: (Default)

[personal profile] scissorsevered 2023-09-25 12:22 am (UTC)(link)
Maybe some sort of invitation system would work for curbing spam accounts, similar to how AO3 runs their signups? I know it would place a damper on the number of people signing up at a time but it would seriously reduce the number of accounts being made just to spam.

This isn't me trying to say what you're doing isn't good, because we all really do appreciate the hard work you put into running this site! I'm sure trying to block spam and ensure user privacy at the same time is a pain in the ass lol. But we have faith in you :D
medusahealing: (Default)

[personal profile] medusahealing 2023-09-25 02:08 am (UTC)(link)
Funny enough, DW actually started with an invitation system. You had to have an invite to set up your account.

(no subject)

[personal profile] jeweledeyes - 2023-09-25 05:35 (UTC) - Expand

(no subject)

[personal profile] the_broken_tower - 2023-09-25 17:24 (UTC) - Expand

(no subject)

[personal profile] jeweledeyes - 2023-09-25 17:42 (UTC) - Expand
elderwitty: (art judith and her maidservant)

Dam spam!

[personal profile] elderwitty 2023-09-25 02:22 am (UTC)(link)
Thank you for fighting the scourge that is spam!

Is this why I've needed to login two days in a row? It's usually only a couple of times a month or so.

(I'm not upset, just curious.)

Re: Dam spam!

[personal profile] elderwitty - 2023-09-26 02:28 (UTC) - Expand
kore: (Default)

[personal profile] kore 2023-09-25 05:29 am (UTC)(link)
BOO SPAM. I was followed by at least twenty empty pornbots on Tumblr last week. I've given up playing whack-a-mole with them. I am so glad DW fights spam with a fury!
innitmarvelous_og: (Default)

[personal profile] innitmarvelous_og 2023-09-25 05:42 am (UTC)(link)
Aren't the p*rnbots on Tumblr awful? I am soooooooooo sick of them too, especially the ones that are not an empty account!

(no subject)

[personal profile] kore - 2023-09-25 05:44 (UTC) - Expand

(no subject)

[personal profile] innitmarvelous_og - 2023-09-25 06:09 (UTC) - Expand

(no subject)

[personal profile] scissorsevered - 2023-09-25 13:15 (UTC) - Expand

(no subject)

[personal profile] innitmarvelous_og - 2023-09-25 16:41 (UTC) - Expand

(no subject)

[personal profile] profiterole_reads - 2023-09-25 11:50 (UTC) - Expand

(no subject)

[personal profile] profiterole_reads - 2023-09-26 12:32 (UTC) - Expand

(no subject)

[personal profile] ganimede - 2023-09-26 18:25 (UTC) - Expand

(no subject)

[personal profile] ganimede - 2023-09-27 17:55 (UTC) - Expand
vriddy: Dreamwidth sheep with a red wing (dreamsheep)

[personal profile] vriddy 2023-09-25 05:36 am (UTC)(link)
Sorry to hear spam is becoming an even worse problem. Thank you for all the good work!
ex_flameandsong751: An androgynous-looking guy: short grey hair under rainbow cat ears hat, wearing silver Magen David and black t-shirt, making a peace sign, background rainbow bokeh. (reactions: down with this sort of thing)

[personal profile] ex_flameandsong751 2023-09-25 07:09 am (UTC)(link)
Thank you for staying on top of the spam, which sounds super annoying to deal with.



Since other people brought up that DW used to have invite codes [and Ao3 still does], might it be possible to re-implement this? Would it have at least some impact on the amount of spam account registrations?
tessitura: iconriot @ dw (Default)

[personal profile] tessitura 2023-09-25 01:58 pm (UTC)(link)
While I am not trying to speak for them, my best guess as to why they don't use invite codes now is the large amount of roleplayers on the site.

(no subject)

[personal profile] ex_flameandsong751 - 2023-09-25 18:14 (UTC) - Expand

(no subject)

[personal profile] morrow - 2023-09-25 20:36 (UTC) - Expand

(no subject)

[personal profile] pauamma - 2023-09-25 21:00 (UTC) - Expand

(no subject)

[personal profile] ex_flameandsong751 - 2023-09-25 20:56 (UTC) - Expand
murphys_lawyer: The avatar for Mozilla Firefox (Default)

[personal profile] murphys_lawyer 2023-09-25 12:02 pm (UTC)(link)
Another vote for some sort of other check if you have a VPN. I use one of the ones you've mentioned, and while I'm resigned to always being "randomly selected" to take a Captcha every time I visit here, I absolutely loathe them, especially when I'm one pixel out on selecting something.

(no subject)

[personal profile] murphys_lawyer - 2023-09-25 21:22 (UTC) - Expand
groovesinorbit: (Default)

[personal profile] groovesinorbit 2023-09-25 01:26 pm (UTC)(link)
Thank you for all your hard work!
filialucis: (Default)

[personal profile] filialucis 2023-09-25 03:45 pm (UTC)(link)
Hmm, thanks for this detailed explanation of the issues. I use a different VPN and have been considering switching to either NordVPN or ProtonVPN when my subscription expires later this year. I'm less likely to do so now that I know that they're known sources of spam!

(no subject)

[personal profile] chestnut_pod - 2023-09-27 02:00 (UTC) - Expand

(no subject)

[personal profile] chestnut_pod - 2023-09-27 03:19 (UTC) - Expand
mdlbear: blue fractal bear with text "since 2002" (Default)

[personal profile] mdlbear 2023-09-25 05:59 pm (UTC)(link)

Thanks for the heads-up, and for your good work. I'm not having any problems so far, but it probably explains the persistent CAPTCHAs I've been seeing on other sites.

chicklet_chatter: (Castle)

[personal profile] chicklet_chatter 2023-09-26 01:24 am (UTC)(link)
Thank you for the update. I was seriously considering going to VPN soon. This is a major point against that option. Thank you very much for informing us!

Chicklet - They/Them
arkessian: (Default)

[personal profile] arkessian 2023-09-26 01:54 pm (UTC)(link)
Can I steal some of these words for a site I moderate where VPN users are getting annoyed (nay, abusive) because they're being blocked by our spam filtering service.

(no subject)

[personal profile] arkessian - 2023-09-27 07:12 (UTC) - Expand
lovingboth: (Default)

[personal profile] lovingboth 2023-09-26 03:20 pm (UTC)(link)
Yep, sympathy. I do consultancy for a message board and what used to be a problem with Tor exit nodes is now a problem with VPNs... as well.

albedinous: A cross-stitched owl on blue fabric, partially complete. (Default)

[personal profile] albedinous 2023-09-28 12:14 am (UTC)(link)
Thank you, Denise! I'm not affected by VPN issues, but appreciate the heads up; four hours is SO much spam-detection, my goodness.

I'm going to go renew my paid account, because you guys seriously deserve a coffee after all this.
pritkiy_kaban: (Default)

[personal profile] pritkiy_kaban 2023-09-28 12:12 pm (UTC)(link)
Yup, browser plugins and Proton tend to trigger (almost) blanket 403 when using free plans.

Knowing how deeply spam and ad industries metastased into current Web economy, I hate them filters much like I hate lying in dentist's chair for costly treatment of acute pulpitis.
Edited 2023-09-28 12:16 (UTC)
omnicat: (Default)

[personal profile] omnicat 2023-09-28 08:53 pm (UTC)(link)
I remember you mentioned an unusually steep, internet-wide uptick in spam this year in an earlier Maintenance post too. Do you peeps in the business have any indication of the reason this is happening?
cellio: (Default)

[personal profile] cellio 2023-09-29 12:55 am (UTC)(link)

Thank you, as always, for your thoughtful and transparent communication, and for the great service. I was wondering why I was getting those captchas (I just started using AdBlock VPN). I can disconnect when using DW, and don't mind that minor hassle to help the spam monster from expanding even more. Grr, spammers ruining things for all the rest of us...

(no subject)

[personal profile] cellio - 2023-09-29 01:48 (UTC) - Expand
redwolf: (Default)

[personal profile] redwolf 2023-09-29 08:11 am (UTC)(link)
Huh. I wonder if this is the same bullshit I'm being inundated with on a corporate mailing list.

Page 1 of 2