Password protecting the Cyberix Network [rss]

rave ## MOD >30d ago #p1408 >>quote

we've been dealing with an uptick in low-effort spam, child porn, and meta-drama from users who contribute nothing of value.

>>52160 The PoW token idea was interesting but is too complex to implement. Here's a simpler solution: just password protect the entire site

How it would work:

Homepage, articles, and connect page remain public (people can read our content and find the chatrooms) Everything else requires a site password to access Password available by joining IRC/XMPP/Mumble and asking We can rotate the password if it leaks to public indexes

Why it should work:

Instantly kills scrapers (LLM and otherwise) Adds friction for drive-by spammers Forces normies to learn how to use actual protocols

if you can't figure out how to join XMPP to get a password, you probably weren't going to contribute quality posts anyway

Downsides:

Slower site growth Might make us seem "too exclusive" Password will eventually leak (but we can change it)

The site's tagline is "the sophisticated man's creative playground" but we've been getting a lot of unsophisticated men posting here as of late. This would align our access model with our actual values. People who are willing to jump through one hoop will be more invested than people who aren't.

Replies: >>4589
Anonymous >30d ago #p1409 >>quote

this has been posted on /g/ https://boards.4chan.org/g/thread/106911558#p106912045

>some very small imageboards also have email verification or special captchas third worlders have no idea how to solve because the subject is niche

Anonymous >30d ago #p1410 >>quote

You could make it invite-only. Require users to send you an e-mail with their reasons for wanting to join. But at the moment, to be honest, there aren't many reasons to post here. I myself, if it wasn't for the fact that I can post anonymously and without filling a captcha, I don't know if I'd be posting here. The whole point of this forum is to talk about how crappy the internet has become, which is bound to piss some people off, but on the other hand it's not enough to form a community.

If I were you, this is what I'd do: I'd close the forum temporarily, keep posting articles and accepting submissions, use the IRC or e-mail to stay in touch with readers, and think, really think, about what I want to do with this site. Closing the forum might seem a drastic decision, but at it is now, it's not worth the stress of having to deal with spammers. Then, once the site has grown a bit and I have a clear vision for it, I'd consider re-opening the forum, if there's a real need for it.

Replies: >>2376
Anonymous >30d ago #p1413 >>quote

Sucks but hey at least you will get to keep the moderation 100% opaque. Whatever's good for the site I suppose.

Anonymous >30d ago #p1414 >>quote

>>52281 fuck off back to ur honeypot brah ive been witnessing u post shit for the past week that gets deleted. 99% of sites on the internet have "opaque moderation" cope and seethe

Anonymous >30d ago #p1422 >>quote

>>52282 Nope. This site is a farce: it positions itself as a rebellion against the corporate Internet, but has all the same problems. Users here have no more freedom, no more knowledge, and certainly no more welcome by the mods and admin than any other shithole.

I've seen real effortposts get deleted with no explanation, not just my own. Generalize what was deleted all you want, it won't change what's happening.

My best estimation is that the admin is a teenager with zero experience administrating a forum, and picked the earliest and most eager participants to both moderate the board and let their words inform his decisions. He must think that the shittification of the Internet happened by random chance, not through calculated actions taken by subordinates.

To the admin: I don't think this is your fault, and it's not too late to change direction. Consider the possibility that your moderators have different priorities than you, and realize that's often a bad thing. Communities aren't built by closing doors. You got visitors to this site by promoting ideas, now you have ideologues who agree with you on most issues but are happy to burn your site to the ground if it means leaving room for more promising platforms to prosper. My fight is not so different than yours.

admin ## ADMIN >30d ago #p1423 >>quote

>>52276 This would have a horribly negative impact on site growth and might even dissuade existing users from coming back here if they don't want to join any chatrooms just to obtain a (potentially) temporary right to access the site for an unspecified amount of time. It is a good idea in theory but the effectiveness of it depends very heavily on how it is executed. The goal would be forcing engagement with our actual communication infrastructure (IRC/XMPP/Mumble) rather than treating this as just another disposable imageboard/BBS.

>>52290 I appreciate you choosing to take time to write this out. Let me address:

>I've seen real effortposts get deleted with no explanation, not just my own.

I've just reviewed every deletion from October 5-17. The moderation log (which I have full access to) shows me the following:

>35+ posts of spam in a single thread (>>52018 'HELP')
>3 threads with variations of nigger as the sole title/content
>Multiple AI-generated replies to thread topics (I assume posted in protest to >>##52174)
>Posts consisting of 'you are brown/jeet/nigger' towards moderation (probably in response to previous deletions)
>Test posts for HTML/formatting exploits (I think I deleted these because I was done testing sanitization fixes?)

All of these deletions, excluding the test posts were also posted from a Tor proxy.

If you're referring to something specific that you believe was wrongly deleted, I'm going to need actual details. An approximate date and the overall context/topic would be great. I can and will restore posts if moderation was wrong but I can't casually spend time investigating vague claims.

>My best estimation is that the admin is a teenager with zero experience

I'm open to criticism, but it needs to be specific and actionable. "Your moderators might have different priorities" - okay, give me an example. Show me a specific deletion you disagree with and explain why.

>Consider the possibility that your moderators have different priorities than you

This is the most interesting point you've made. I do take this seriously, but here's the problem: you were directly invited to discuss this in our chatrooms by one of those moderators (>>52275), and you never showed up. I would have been present to see it occur in real-time (I keep my client open in the background and usually respond to notifications immediately), but I see no discussion that could have possibly taken place that was about moderation. If you're actually concerned, why did you not take the invitation to discuss it directly?

Anonymous >30d ago #p1437 >>quote

>>52291 Yeah let me just link you to the modlog entry... oh wait.

I don't save my posts nor do I care to remember them well. I actually remember shitposts a lot better than most effortposts I make. Not just here, but elsewhere too.

Herein lies the critical benefit of a public modlog. I'm sure you know by now I have no problem with shitposts being deleted. The real reason you should absolutely have a public modlog is because it deters glowies from deleting posts to prevent conversations from developing in directions harmful to their mandates. You might say "that won't happen," I say there is already evidence of it, though whether it's actual glowies or retarded teens on their first power trip is open to interpretation. If you think you can just filter out the glowies, you can't. You can only lower the ceiling of power they can gain here.

It's also critical that there is a line drawn for shitposting, so people know what it is and isn't, and your mods can't just hand-wave away the issue with lies about the content of the post they deleted, like they have done now countless times.

I could link to better examples if the modlog was public, but the best example I can think of (notably missing from your list) is my response to "Lainchan and other imageboards are compromised" (>>51903)

That post hit on the nose the similarities between the OP complaint and the situation developing here. It's a stark warning that you WILL end up with the same cesspool if you are not careful. The Internet is shit nowadays because it's tough work to advocate for your users and maintain a healthy hatred of them at the same time. The moderation here mimics the psychological whack-a-mole you see anywhere else where the tallest grass gets cut first, and considering your positioning of this site as a better alternative to those platforms, I find it a far better use of time to kill a traitor before an enemy.

Also, you didn't mention CP from your review of the private modlog. Either you don't label such content and fully delete it outright, or this "rave" mod is being dishonest about the problems you face in an attempt to lock down your site and kill its growth. If it's the latter, in your position I would see that as a bright shining red flag and remove rave from the mod team. You should staff your site with people that want to grow it and care for it, not kill its growth. If you really want a private forum that idea should come from YOU. Anyone else who tries that shit should be taken out back and given the Old Yeller.

I want you to know how awesome a public modlog could be. You list the post number (and thread number if applicable), the action taken (delete, warn, ban), the reason for the action, and the post content UNLESS the post was deleted for commercial spam or illegal content. Showing ban periods would be nice too.

Benefits of doing it this way include:

  1. You make it difficult, but not impossible, to view offending posts in their original context, to prevent the modlog being a basedboard.
  2. You show newcomers how content is handled before they make their first post
  3. You show everyone who faces action what the basis for the action is AND that the action taken against them is not special or the result of glowfuckery or vendetta, but blends in with other deleted posts.
  4. If there IS fuckery afoot, you make it easier for users to seek recourse. No one is screenshotting their posts and that content is the only proof of whether a rule was actually broken. When a poster can see their content was absolutely discriminated against and it's no accident, they will feel enabled to do the right thing and let you know about it. A HUGE benefit to your site.
  5. If a user is accidentally posting below your desired quality, you prevent them from assuming some error occurred and just continuing to shitpost. Some people really do want to contribute in a meaningful way but will not gaslight themselves over some invisible action.

There are your specifics. I hope you use them well.

Anonymous >30d ago #p1438 >>quote

More thoughts continuing >>52306

I never planned to join IRC or XMPP in this current state. I would rather wait until your site either dies or grows enough to make warning users en masse both useful and entertaining. I am truly concerned about the direction here, but only in the context of this colorful rectangle I can open and close at any time. I may join the other services one day; not to presume but I think my intuition was correct that you are a different person than "rave" (who has posted with admin cap) and you have the good intentions necessary to code a website like this but are letting yourself be informed by bad actors and retards. If you were a bad actor yourself you would show these glownoobs how to really scorch the earth, not get your feet wet and ask a bunch of questions about the situation publicly.

Anonymous >30d ago #p1439 >>quote

This thread is still at the top of the board so if you delete this post for triple posting you suck cocks.

I forgot a detail:

>You make it difficult, but not impossible, to view offending posts in their original context, to prevent the modlog being a basedboard.
One way you can really accomplish this is by placing the content behind a "View Post" button or a link that makes the post appear on hover (no JS required), meaning you can only view one offending post at a time. Also now your table row heights are all the same which makes a very clean look.

admin ## ADMIN >30d ago #p1447 >>quote

You've made several compelling arguments. Especially about transparency preventing future moderator abuse.

I'm going to implement a public modlog as an experiment. Here's the initial approach:

Post/thread IDs, actions taken, reasons, day-of-week timestamps Moderator pseudonym responsible

1 - No post content for obvious spam or illegal content or 2 - Similar spam entries are consolidated into one mega-entry to prevent entire log page from being spam entries? Illegal content gets redacted? I'll figure this one out.

Log will be batch-updated periodically rather than real-time

This should address this problem while preventing some of the issues I'm concerned about. In regards to 'rave', I do appreciate the warning, but right now, I'm confident in the moderation team's alignment with site goals. If I am wrong, then the public modlog will make those patterns visible if that confidence is misplaced. >Either you don't label such content and fully delete it outright
Most likely what happened. There are two kinds of deletions: soft and hard deletions. Posts SHOULD be soft-deleted unless they're illegal but I realize that there also isn't really anything stopping moderators from hard-deleting other things. This is a fault on my part. The ban management page also has a delete checkbox that actually hard-deletes instead of soft-deletes, so posts and threads that may have been deleted alongside a ban don't show up in the logs, either.

I am going to take time this weekend to work on the site. Best case scenario, it's done within a few days or less.

Anonymous >30d ago #p1448 >>quote

>>52316 >Please write a better post.
There goes my post, wow. I don't know whether to laugh or cry.

Anyway, thanks. You can solve #2 by adding a spam tag to actions/entries or compromise and group by date,content in sql or php.

>Log will be batch-updated periodically rather than real-time
Sus as fuck but ok. you can just edit it manually to group the entries then janny

Also, moderators can delete something so even you can't see it?

Anonymous >30d ago #p1464 >>quote

Password protecting the whole website looks great in theory. However, it doesn't fix the issue with content quality. Nor will it make the community more thriving. Pushing the forum users to IRC/Mumble/XMPP/(Discord ☠), will only harm the activity of this place.

You'll have to implement a captcha system, similar to what http://leftychan.i2p/ | http://kacdyre2mccory3jccpzu36ybzr6tpteuic6a7uhhya4dleek4xeuiid.onion/ does, in order to filter out the low quality posts. Also http://lambdaplusjs35padjaiz4jw2fugdoeutse262phqr72uf634s2wdbqd.onion/All/catalog.

If you plan on creating a thriving community, do consider creating an i2p (or onion) domain. Some configuration overhead, but it will clearly set this forum apart. What's more, i2p goes hand in hand with this forum's principles.

Anonymous >30d ago #p1465 >>quote

http://leftychans5gstl4zee2ecopkv6qvzsrbikwxnejpylwcho2yvh4owad.onion/ is actually the onion of leftychan, which forked from http://kacdyre2mccory3jccpzu36ybzr6tpteuic6a7uhhya4dleek4xeuiid.onion/

A nice example of how three protocols are bridged properly.

Anonymous >30d ago #p1742 >>quote

Lets revisit this topic again. As I said >>52684 here, a place cannot truly be considered free speech if free and public access is given to everyone. This consequentially invites actors who are willing to sabotag ethe infrastructure of the free speech hub in order to pervert and take away free speech, usually without the speakers knowing they have lost it

Free speech has no value if nobody is willing to listen to it. The activity of the site should not be considered. Cyberix gets thousands of new "Visitors" every day and yet there is an obvious signal-to-noise ratio where only a couple handful of people bother to stimulate the activity of this forum while thousands are simply observing. Why? They do not value free speech or have nothing to say.

Password locking Cyberix would kill off ALL glownigger and bot spam activity, AND fix this obvious signal-to-noise ratio. it WILL bring in more activity because this place will appear to be very elusive on the outside than it was before. People will want to come in rather than stumble past it like a drunken hobo.

Anonymous >30d ago #p1747 >>quote

password locking cyberix would only kill it more, if people don't know about the site when i'ts not password protected then it's going to be even more obscure when it gets password protected and that might be bad

Anonymous >30d ago #p1756 >>quote

Yes, I2P and Tor mirrors would be awesome to have. Any doubts about abuse are ignored solely by the fact that Tor users have been able to post here without any restrictions whatsoever and nobody has used it to abuse or spam the site even before the markers were added to tor posters. What other clearnet forum have unrestricted I2P and Tor mirrors? NONE OF THEM!

Dignity >30d ago #p2376 >>quote
>>1410
We aren't some fucking "private cheat" distributor to make a invite only website to make accounts
(I.e. moneybot.cash and astral cs2)
Anonymous >30d ago #p4589 >>quote
>>1408

Places I administrate implement a quarantine for new users and content, requires moderator effort but you avoid strangling your struggling community. You even get to curate exactly the kind of people you want to let in, keeping that hivemind healthy, something that has been killed off here.
A password lock is pretty similar to this but on a more extreme level.
I understand small websites get spammed and raided to shit constantly, but bad automated moderation just makes things worse. I'm tired of having to deal with the content similarity block when all i was trying to do was split a long post of mine into thirds. 99% similarity? What the fuck? I'm just discussing the same topic.
Replies: >>4592
Anonymous >30d ago #p4592 >>quote
>>4589
> Places I administrate implement a quarantine for new users and content, requires moderator effort but you avoid strangling your struggling community. You even get to curate exactly the kind of people you want to let in, keeping that hivemind healthy, something that has been killed off here.
https://desuarchive.org/g/thread/107964385/#q107964385
ANOTHER verbatim copypaste post from /g/. WTF is going on lmao
This started with https://cy-x.net/topic/linux-as-a-whole-is-compromised/601
lain >30d ago #p9976 >>quote
(12:52:40 PM) rave:
Fuck your anonymity. There's nothing to anonymize on Cyberix. We don't fucking use javascript and you're able to register with Tor and a VPN all you want. I am going to passwordlock the site and make it registered accounts or aged IPs only. You can change your display name in the posts and threads you make for an identical effect on discussion. Anything else serves to inhibit ME and the site at large. If you have a problem with this you better show me a website on the Internet that allows anonymous posting as free as we do without problem and without invasive javascript malware
(12:53:08 PM) cr0s5h34d:
> If it were up to me I'd implement a non-invasive captcha or something.
I remember back then we used to have a captcha for making posts, if I recall
(12:53:10 PM) rave:
Fuck developer as well
(12:54:04 PM) :
<anontor> based rave is killing cy-x
(12:54:15 PM) :
<anontor> thats my president
(12:54:20 PM) cr0s5h34d:
I mean it is a last resort isn't it?
(12:54:33 PM) cr0s5h34d:
He cant do anything else other than do that
(12:54:37 PM) rave:
It is beginning to dawn on me that solutions do exist, but you'd have to accept that anonymity sucks, doesn't it?
(12:54:47 PM) cr0s5h34d:
> It is beginning to dawn on me that solutions do exist, but you'd have to accept that anonymity sucks, doesn't it?
Yeah, it does
(12:55:09 PM) rave:
We are all here in IRC XMPP and Mumble with unique nicknames and yet our privacy has not been compromised in the slightest
(12:55:43 PM) cr0s5h34d:
You could say it like that
(12:56:21 PM) rave:

> <anontor> based rave is killing cy-x

Saving the site from bullshit like this is not killing Cy-X
(12:56:47 PM) cr0s5h34d:
It'll probably die down in a month
(12:56:47 PM) rave:
You cannot have it both ways. I don't like waking up early in the morning to see that Cyberix is once again being spammed by retards and bots
(12:57:13 PM) cr0s5h34d:
It'll probably die down in a month
_depending of course.._
(12:57:23 PM) cr0s5h34d:
> You cannot have it both ways. I don't like waking up early in the morning to see that Cyberix is once again being spammed by retards and bots
No one does
Replies: >>9978
rave ## MOD >30d ago #p9978 >>quote
>>9976
Lets discuss.
I accidentally nuked all posts from January 25 - February 4th in an attempt to fight against (One) guy and his neverending pile of IPs.
This is unacceptable and I need to prevent this from happening in the future.

I am defending against IP-based attacks with IP-based defenses. The attackers have infinite IPs (Tor). If I want this to stop NOW and FOREVER, Cyberix MUST switch to identity-based defenses.

The base philosophy is that you can be anonymous WITH an account (custom display names), but you need to prove you're human ONCE.
You cannot have Tor, VPN, and Datacenter IPs posting freely on the site while bans are still IP-based. Requiring accounts is a necessary step and would be better for poster "anonymity" or "privacy" compared to allowing anonymous posts and banning all proxies.

The forum should work the same way as it does in IRC/XMPP/Mumble. You'll need a persistent identity (account), but that identity can be pseudonymous and you can change how you appear (display name) on each post.

Here's how it works:

1 - you register using a password you get from the chatrooms, yes
^ this kills the robot
getting the password requires someone to spoonfeed it to you, so the gatekeeping is done by whoever chooses to acknowledge whoever asks for the password

now we know the attacker is human. the attacker can still automate spam though, so we do this:
accounts will be discriminated against based on age in a very unique way.
They will have a limited amount of posts they can make per five hours. for a regular user who isn't online 24/7 this limitation shouldn't be a problem, and it also helps kill off double/triple/quadruple-posting in threads by forcing users to consolidate all of their points into one singular post instead of posting separately for no good reason
This number will be visible to the end-user.
This number increases as the account naturally ages and the account makes posts. If the account remains dormant, it will not be given new posts in order to prevent spammers from prepping waves of accounts to spam with later
In code, I imagine I could just implement this as a simple mathematical calculation that applies this in the form of a reputation/trust score tag
If the account goes over the post limit, their post will not go through and they will be warned that if they continue, the number of posts they can make will begin decreasing. Spambots will end up neutralizing themselves if they aren't aware of the amount of posts they have remaining.
If I wanted to be brutal, I could implement an automatic ban that occurs the moment the account reaches the minimum possible limit.

If a human spammer wanted to spam, they would have to:

1 - Join a chatroom
2 - Coerce someone into giving up the registration password
3 - Contribute to the forum over a long period of time before spamming and getting themselves banned (nobody does this), or send a measily 3-4 posts before hitting the post limit and getting banned

However, this system falls apart whenever a group of human spammers are involved
1 - Already have the password
2 - Across as many IP addresses as they want, register new accounts manually
^ 3-4 post limit for new fresh accounts in this scenario
3 - Spam the forum with these new accounts, recycling them whenever a post limit is reached
4 - Repeat for lulz

Potential ways to combat this?

>how about a parent and child accounts
>users can generate a password to give as a one time invite, if one turns out spammer the parent account is held responsible and both are banned and all accounts they invited
Effectively serves the same role a global Cyberix password that only chatroom users know. Not bad!

Password is one-time unique instead of static, making it incredibly hard to coordinate group raids on Cyberix without a network of accounts
^ Constant raids become impossible if accounts are prevented from generating codes until their internal reputation reaches a certain point (equivalent to 5-10 post limit?)
^ Password generation has a ratelimit, maybe five per hour. Curbs facilitation of malicious invite codes overnight
^ Spam account networks can be nuked all at once the moment they're discovered, making cleanup trivial

okay, here's a summary:

1 - Accounts required to post. Accounts need an invite code. Join the chatrooms and get aquainted. Someone will give you an invite if they think you're a good fit for the forum.
^ Consider: Anonymous, account-free posting under a manual quarantine?
2 - Internally, accounts have a simple reputation number. This number will determine the amount of posts an account may send per hour, and will determine whether or not the account is permitted to generate invite codes. If the account attempts to exceed their post limit, their reputation will decrease. Reaching the minimum possible reputation will result in a ban.
^ Consider: Attackers may be able to compromise accounts and intentionally get them banned. Do we need a protocol for this?
^ Might not be a problem, but "Just unban me bro" would require implementing a feature in the moderation panel that allows moderators to tinker with an account's internal reputation level which conflicts with how I plan on implementing it (in a loop that occasionally calculates it for all accounts that runs in the background, incredibly simple)
3 - Invite code system just like a private tracker. Incredibly simple and streamlines moderation.
^ Consider: Compromised or rogue accounts. Need to avoid banning half the forum if a core parent account gets banned or an account that happens to be part of a tree connected to the core parent account gets banned

There's one thing I haven't accounted for though:

For the past few months, the majority of Cyberix's activity has come from anonymous posts. If we take this away, would we effectively be killing off the entire site?

The site has 930024 unique visitors and 1781414 total hits. There are definitely lots of individuals who keep coming back to the site and probably posting as well. What are the implications?
Replies: >>9979 >>10017
Anonymous >30d ago #p9979 >>quote
>>9978
If this actually gets implemented, this is where my interest in this website dies, I'm not namefagging or sucking some guy's dick in IRC for a password or invite code.
Replies: >>9980 >>9985 >>10017
Anonymous >30d ago #p9980 >>quote
>>9979
>site allows anonymous
>site gets spammed with gore, porn, soyjaks, advertisements and gibberish
>"this is okay :)"
>site does not want to be anonymous because of the gore, porn, soyjaks, advertisements and gibberish
>":O NOOOO BUT MY ANONYMITY OR SOMETHING. I DIDN'T READ THE POST SO I DIDNT SEE THE PART WHERE ANONYMOUS POSTING WOULD STILL BE POSSIBLE BUT MANUALLY APPROVED BUT IT DOESNT MATTER!!!! I AM A REAL POSTER WHO HAS POSTED SOMETHING OF VALUE HERE AND NOT A GLOWING SCHIZOPHRENIC TRUST ME BRO"
Replies: >>9982 >>10017
Anonymous >30d ago #p9981 >>quote
All my posts got wiped and this is happening?
The day that cy-x dies
Replies: >>9984 >>9985
Anonymous >30d ago #p9982 >>quote
>>9980
Good then keep the site to yourselves faggots and make it a circlejerk lul
Reddit will be better anyways
Replies: >>9985 >>10017
QA ## MOD >30d ago #p9983 >>quote
And in we quote inside of the XMPP, from the spammer/botter.
>"*You* are the problem. Go disappear and delete your website. Bye."

I have no say in this.
QA ## MOD >30d ago #p9984 >>quote
>>9981

Soz..
rave ## MOD >30d ago #p9985 >>quote
>>9982
>>9979
>>9981
You offer zero technical solutions, zero alternative ideas. Just scorn and an attempt to poison the well.

THE PROBLEM: Malicious actors are using infinite IP addresses (Tor, VPNs and other proxies included) to spam the forum at will anonymously. IP-based bans are useless.
I do not want to prevent Tor users from posting. I do not want to restrict someone's ability to use the site just because they're behind a proxy. That is not a solution.

How do you stop spammers with infinite IPs?
How do you do it without JavaScript/bloatware?
How do you do it without requiring constant, exhausting manual moderation from me?
How do you do it while preserving the ability for a completely unknown person to post without any friction?

I've proposed a system of pseudonymous accounts with invite gates, rate limits and a quarantine queue for true-anon posts. These are concrete proposals that address the technical reality of the situation at its core.

If you have a better, workable idea that answers my four questions above, please present it. If you don't, I have no reason to take your "input" into consideration.
Replies: >>9986 >>9995 >>10018
Anonymous >30d ago #p9986 >>quote
>>9985
How about a hashcash? Or do it the Soyjak.party way where posters/images have to be approved, but with users being the approvers (Posts are hidden automatically, revealed with a click of a button until a few people vouch for the poster to be approved)
Replies: >>10003
Anonymous >30d ago #p9987 >>quote
p2w cyber ix where you have to pay 1 cent in monero/btc to post on the site and if it doesn't get flagged or reported you get refunded
Anonymous >30d ago #p9988 >>quote
Lol should have made in your site in the 2005 sorry lil bro youre soo young haha xd xd bye faggot NIGGER
Anonymous >30d ago #p9989 >>quote
I just took a shit
Anonymous >30d ago #p9995 >>quote

>>9985 The ultimate solution would be some verification network among anonymous imageboards. It acts as a layer on public IP space, since too many bad actors have been let into that network by residential botnets, datacenters, and Tor nodes. You get verified once, become a Trustfag, and then can post on adhering imageboards with no captchas, no friction.

It was outlined by Shii in the halcyon days of 200X (omg frutiger aero) that the advantage of anonymous discussion is the lack of friction in posting. You could get a reply from anyone in the world.

(https://wakaba.c3.cx/shii/)

No-registration posting must be saved, but as the internet is too polluted we have to add verification layers. Let's do it strategically. Imageboards could use the Trustfag network to limit the number of times a user has to use a registration form to 1 (one). Related ideas: Digital ID comes to mind. Federation could also be on the table, as once you've registered on a homeserver you can post in other federated websites without seeing a registration form.

Replies: >>10001 >>10002 >>10003
Anonymous >30d ago #p10001 >>quote
>>9995
registration does not require email, email is optional, the requirements are a username and a password
a nostr like verification or web of trust could be intersting to implment for a forum
QA ## MOD >30d ago #p10002 >>quote
>>9995
We used to be a reputation system (_probably._) I do not remember how it worked at all. I do not know if that system is up to place currently as rave probably has a higher power than I do.
rave ## MOD >30d ago #p10003 >>quote
>>9986
>>9995
I have taken your input into consideration and I will let you all know of my newest approach later today.
rave ## MOD >30d ago #p10006 >>quote
I feel like I reacted too fast with yesterday's spam. I hope I'll be able to find a permanent solution to this issue.

one at a time, our goals are to:

1: kill the robot
2: kill the human spammer
^ easier said than done

How to kill the robot:

Assume the attacker automates completely unique posts. Assume the attacker rotates IPs per posts and has access to infinite IPs. In order to have frictionless anonymous posting, you MUST rely on IP-based defenses. IP rotation bypasses these.

1 - Dropdown captcha with randomly selected question out of question bank with answers
^ Dedicated attacker can collect all possible answers and code in the correct answer for all of them
2 - JavaScript free image check box captcha like what 4get.ca employs
^ Effectively prevents text-only browsers from posting on the site
3 - Cookie-age restriction
^ Single cookie can be used across IP addresses. Per-IP cookie doesnt work because dynamic IPs exist, and legitimate proxy users automatically change IPs


Remember: The attacker's goal is to make the site unreadable (spam), or unusable (force the site into restricting posts)
Our goal is to make the site unspammable while maintaining frictionless posting.

Assume the robot is stopped. Now our enemy becomes the manual and coordinated human spammer.

1 - Soyjak.party-style community post/image approval
^ Easily abusable. Tor bots can collectively approve other Tor botposts in order to facilitate their spam. Requiring accounts to approve is a restriction and can have its own problems.
2 - Ratelimits, delays, ages, any sort of requirement
^ They will have to be IP-based, making it vulnerable to dynamic IPs and malicious proxy hopping that can piggyback off of good proxy users who may have passed any requirement set


Soft nuclear solution:
Cyberix does not get posts every day. There are lapses of activity that occur and that's okay. With this in consideration, we can adopt a modification to the approach we use for site interaction.

Because the forum aims to be more of a long-term discussion hub / an informational archive, we hsvr no incentive to have realtime rapidfire posting and response times like what you see on social media and image boards 24/7.

I propose a forum lockdown mode that makes all posts made during the lockdown require manual approval.

When I go to sleep, the forum will enter lockdown. It will automatically exit lockdown in the morning. Any posts that were in the manual queue will remain there, but this will be disclosed to the end user in threads.

If the forum begins to exhibit activity levels above whatever the weekly average is, it should automatically enter lockdown mode in order to curb spam.


Actually, this isn't a good solution because it means I'll need to manually sort through whatever's in the queue whenever I log onto the site..

We need to:

1 - Find the most effective solution against robots
2 - Find the most effective solution against humans
3 - Consider lockdowns as an additional implementation to have
Replies: >>10010 >>10017
Anonymous >30d ago #p10010 >>quote
>>10006
Sorry if this comes off as rude, but who browses Cyberix on a text-only browser? Hasn't image been invented since 1993? I feel like you may be appealing to an audience that does not exist.
Anonymoose >30d ago #p10017 >>quote
>>9979
>>9980
>>9978

>>10006
4chan makes it impossible to post over tor. It also bans most vpn ip ranges. Anonymous as in everybody are called anon. Anonymous in the sense that no other user knows anything more than the user has written. Not private in the sense that any server admin can track ip, cookie (poster id), user agent. Anyone with access to the 4chan data and the isp metadata (police), can with a high accuracy correlate each post to a isp subscriber (real life identity). And if access to devices maybe even tie a post down to a specific computer and web browser.

4chan has a spam problem despite having cookie sessions, fresh IP restrictions, and a captcha that dynamically modifies difficulty.

>>9982
Reddit allows you to create an account and post over the tor network last time i tried. Not anonymous in the sense that you have a username. But private in the sense that it's very hard for anyone to track down the real life identity of a poster, unless stupid mistakes.

Reddit does not have the same kind of spam problem that 4chan does. You can go on any niche subreddit and see real people posting.

4chan literally has a legal team that works with all legal and law enforcements. doesnt matter what country either. i worked in criminal cases for a certain us agency for a few years and saw emails and evidence given to law enforcement freely without question from 4chan's legal team personally. this finally came to the public's attention when they helped that florida sheriff find who was making threats a few years ago. (memory holed)

the legal issues is primarily what made moot leave for good. he got in so much legal terrible because of this site and just couldn't handle it. as a final "fuck you" to the feds, he sold it to gook moot thinking they couldn't keep in control of 4chan via legal issues. but the us government told gook moot, either play nice or they will take the domain. gook moot folded because he wanted to prove to 2ch that he can run an imageboard just as well, if not better than they did after they fired him.
zahno >30d ago #p10018 >>quote
rave admin l-i developer nyrd nen roriman

>>9985
You allow accountless posting, with at least a rate limit per IP and various rate limits on the aggregate of all accountless posts you might impose CAPTCHA or other costs on accountless if you insist)

You have rate limits per board and per thread. (global and per-IP and per-account limits)

Anomalies: When a massive influx of accountless posters appears on a board, accountless are automatically clamped down upon, with an extra rate limit increase given to people who were there before the anomaly.

You have optional accounts
- Accounts don't imply usernames or post histories. They are purely antispam measures
- Limit on non-invitation registrations per day
- Limit on non-invitation registrations per IP per day
- Rate limits per account (nullifies IP rate limit)
- Accounts get an invitation every X days with a maximum of Y invites. These invite codes can be given to other people to make their own accounts
- Account rate limits are lower if the account hasn't posted recently
- Account rate limits are even lower if the account is new
- Account rate limit ramp-up may be per-board
- Store a tree of invitations so it's easy to track spammers who cluster within a branch and thus easy to ban them

Most of the time there will be no spam so you can use accountless posting perfectly fine
when there is spam from accountless the mods can slow it to a trickle
Spammers clustered under one branch can be removed in seconds, so effective spammers need invites from lots of users or need to register many accounts over time, and can only use this to cause a minor, temporary disruption
with these measures you can remove all IP blocks, including of tor
Captchas can prolong the lifetime of accountless posting for a while too.

For a lot of boards, they stay obscure or not targeted by spammers for a very long time such that accountless posting can have a high limit most of the time. The point is that you can just lower it to zero or just quite low when spammers appear.

Also boards and threads can have their own rolling global limits, so you can't just come in and spam many threads and push all threads off the board.

In summary the accountless idea is invitation system + registration system + accountless.
The accountless is for when shit hasn't hit the fan, the human invitation is what you fall back on when the spammers show up. It takes much longer to infiltrate and the amount of damage you can do once you have is very small. You could pretty much get rid of IP-bans entirely
Replies: >>10084
admin ## ADMIN >30d ago #p10084 >>quote
>>10018
I like this idea. When I have time, I will work on implementing it myself.
Replies: >>10093
anon >30d ago #p10089 >>quote
admin, rave, l-i, developer

Suddenly, the strategy shifts:

Spammers are no longer interested in the volume of what they post.
They are interested in the power and effect of what they post has on the people who view it.
Gore. Child Pornography. Shock Content (Think goatse-tier).
They relish reactions. They have no problem posting (one) post containing one of these (or more) while you are asleep. They realize that it'll be deleted immediately anyways, so they decide that one is enough and having eyes laid upon their post once is good enough.
They care about the feeling that they know you will have to see what they posted. They love knowing that innocent eyes are stabbed by an unsuspecting picture of some random dude's guts being posted on an old-school tech forum.

This cannot be stopped. You cannot stop this without building an AI to detect gore and child pornography in PHP. You cannot stop this without vision models. You cannot stop this without community-vetted reporting or flagging (which can and WILL be abused, and would probably have a worse effect). You cannot stop this without introducing restrictions to attachment uploads that restrict the frictionless posting of anonymous users.

Even worse, imagine this:

They can and WILL upload CHILD PORN on your site, and IMMEDIATELY report it (FBI, hosting provider, ISP, domain provider, etc) in an attempt to get your site taken down.

Potential, likely possible scenario
You go to bed at 8PM
They post child porn, maybe they've guessed your activity schedule and do it right after 8, for example
They can report it,
You wake up at 8 AM.

This can result in a 12+ hour delay between child porn being posted and it's removal
This is also a window for a 12+ hour response between the posters and the support agents assigned to their reports on our site

How will you fight this?
Replies: >>10092
admin ## ADMIN >30d ago #p10092 >>quote
>>10089
>How will you fight this?
Anonymous attachments now expire after 30 minutes. Child porn b-gone.
žž >30d ago #p10093 >>quote
>>10084
show pics
Replies: >>10099
admin ## ADMIN >30d ago #p10099 >>quote
Mod Panel Trash.png
Mod Panel Trash.png
Invites.png
Invites.png
>>10093
I have taken over and I am now the development lead for Cyberix's latest experiment. I have implemented the suggested philosophy 1:1.

I am working on a minimalized variant of the codebase. I have created the defense systems first. I will then work towards the higher-level features of the forum to avoid codebase entropy. The updated site will retain most of its current features, but you'll notice some neat additions when it arrives.

Plans:
>Repolish everything

Current notable changes:
>Mod suite rework
That's all :^)
Attachments:
Mod Panel Trash.png (54.66 KB)
Invites.png (254.88 KB)
Replies: >>10102
admin ## ADMIN >30d ago #p10102 >>quote
anon imbalanced.png
anon imbalanced.png
account tech.png
account tech.png
what i see.png
what i see.png

>>10099 I designed a CLI tool to test the new philosophy.

Observe.

Simulating coordinated attack: 20 IPs, 5 posts each to IMBALANCED
Using actual system with rate limiting
Note: Each IP has separate rate limits (5 posts/hour normal, 0.5 in spam mode)
      Board aggregate limit: 50 anon posts/hour normal, 5 in spam mode


IP 0 (72.55.149.227): ...XX
IP 1 (189.164.30.45): ...XX
IP 2 (152.69.197.196): ...XX
IP 3 (73.104.89.107): .XXXX
IP 4 (248.88.247.171): XXXXX
IP 5 (50.246.152.14): XXXXX
IP 6 (5.62.40.239): XXXXX
IP 7 (228.88.56.67): XXXXX
IP 8 (198.3.196.239): XXXXX
IP 9 (168.18.236.190): XXXXX
[Aggregate check: 10 anon posts to board in last hour]
IP 10 (68.185.91.89): XXXXX
IP 11 (27.248.237.157): XXXXX
IP 12 (222.191.61.213): XXXXX
IP 13 (39.230.178.51): XXXXX
IP 14 (234.224.161.111): XXXXX
IP 15 (188.23.131.26): XXXXX
IP 16 (81.193.78.194): XXXXX
IP 17 (100.134.116.24): XXXXX
IP 18 (18.152.159.63): XXXXX
IP 19 (210.145.176.191): XXXXX
[Aggregate check: 10 anon posts to board in last hour]

=== RESULTS ===
Total attempted: 100
Succeeded: 10
Failed: 90
Success rate: 10%

Error breakdown:
  - Thread limit reached: 6 times
  - Anonymous posting disabled (spam detected): 84 times

Per-IP results (first 5):
  72.55.149.227: 3/5 succeeded
  189.164.30.45: 3/5 succeeded
  152.69.197.196: 3/5 succeeded
  73.104.89.107: 1/5 succeeded
  248.88.247.171: 0/5 succeeded
  ...
Per-IP results (last 5):
  188.23.131.26: 0/5 succeeded
  81.193.78.194: 0/5 succeeded
  100.134.116.24: 0/5 succeeded
  18.152.159.63: 0/5 succeeded
  210.145.176.191: 0/5 succeeded

Expected behavior:
- Each IP: First ~5 posts succeed (per-IP limit)
- After ~50 total posts: Board aggregate limit hits, all fail
- In spam mode: Board limit = 5 posts/hour, hits very quickly

 ANOMALY DETECTED: global_anon_flood (Severity: 3)

Single IP flood attempt (what Rave had to fight off on February 4th):

Using single IP: 98.88.81.247
Creating 1000 posts from this IP...

...XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

=== RESULTS ===
Total attempted: 1000
Succeeded: 3
Failed: 997
First failure at post #4

Error breakdown:
  - Thread limit reached: 997 times

Expected behavior:
- Normal mode: First ~5 posts succeed (IP hourly limit), rest fail
- Spam mode: First ~0-1 posts succeed (10% of normal), rest fail

=== ANOMALY CHECK ===
 No anomaly detected (threshold not reached)
  Threshold: 10+ anon posts/minute OR 30+ posts/hour to board

100 post/thread coordinated attack with 1 IP per post:

Simulating coordinated attack: 100 IPs, 1 posts each to IMBALANCED
Using actual systemwith rate limiting
Note: Each IP has separate rate limits (5 posts/hour normal, 0.5 in spam mode)
      Board aggregate limit: 50 anon posts/hour normal, 5 in spam mode


IP 0 (123.207.171.154): .
IP 1 (16.225.95.246): .
IP 2 (7.16.36.247): .
IP 3 (201.112.249.122): .
IP 4 (169.166.140.25): .
IP 5 (241.97.94.99): .
IP 6 (113.74.170.38): .
IP 7 (67.58.48.136): X
IP 8 (29.55.38.86): X
IP 9 (232.171.33.202): X
[Aggregate check: 20 anon posts to board in last hour]
IP 10 (138.217.63.158): X
IP 11 (218.118.105.230): X
IP 12 (173.200.14.33): X
IP 13 (110.200.51.239): X
IP 14 (167.133.212.9): X
IP 15 (19.12.174.27): X
IP 16 (223.167.95.178): X
IP 17 (101.104.72.192): X
IP 18 (95.65.252.60): X
IP 19 (228.136.11.171): X
[Aggregate check: 20 anon posts to board in last hour]
IP 20 (188.31.223.103): X
IP 21 (95.183.155.100): X
IP 22 (82.230.188.4): X
IP 23 (127.100.195.51): X
IP 24 (202.183.87.67): X
IP 25 (74.46.141.48): X
IP 26 (250.35.165.64): X
IP 27 (53.194.177.212): X
IP 28 (105.54.236.62): X
IP 29 (200.168.20.199): X
[Aggregate check: 20 anon posts to board in last hour]
IP 30 (64.226.178.126): X
IP 31 (134.28.34.6): X
IP 32 (251.27.134.78): X
IP 33 (240.178.156.192): X
IP 34 (53.92.226.247): X
IP 35 (215.83.206.148): X
IP 36 (78.47.11.147): X
IP 37 (232.72.100.7): X
IP 38 (246.29.223.77): X
IP 39 (68.115.22.124): X
[Aggregate check: 20 anon posts to board in last hour]
IP 40 (28.43.253.186): X
IP 41 (157.17.251.198): X
IP 42 (21.4.105.207): X
IP 43 (150.248.159.59): X
IP 44 (231.204.138.48): X
IP 45 (123.1.84.232): X
IP 46 (238.162.88.39): X
IP 47 (234.60.190.42): X
IP 48 (155.181.68.181): X
IP 49 (147.193.171.204): X
[Aggregate check: 20 anon posts to board in last hour]
IP 50 (177.12.248.121): X
IP 51 (89.6.236.34): X
IP 52 (14.141.51.172): X
IP 53 (48.170.164.127): X
IP 54 (147.10.149.165): X
IP 55 (141.234.15.74): X
IP 56 (189.116.82.123): X
IP 57 (136.98.143.128): X
IP 58 (133.101.78.53): X
IP 59 (173.176.33.235): X
[Aggregate check: 20 anon posts to board in last hour]
IP 60 (72.7.127.72): X
IP 61 (153.164.38.212): X
IP 62 (98.144.48.94): X
IP 63 (124.31.6.167): X
IP 64 (41.2.103.42): X
IP 65 (50.188.245.98): X
IP 66 (23.79.248.239): X
IP 67 (28.245.70.199): X
IP 68 (30.40.163.190): X
IP 69 (61.158.159.222): X
[Aggregate check: 20 anon posts to board in last hour]
IP 70 (15.179.20.189): X
IP 71 (123.87.9.182): X
IP 72 (224.69.86.208): X
IP 73 (227.128.236.95): X
IP 74 (82.51.170.131): X
IP 75 (135.62.166.33): X
IP 76 (33.40.175.41): X
IP 77 (166.224.130.48): X
IP 78 (212.230.136.191): X
IP 79 (42.179.216.128): X
[Aggregate check: 20 anon posts to board in last hour]
IP 80 (87.103.3.15): X
IP 81 (252.124.196.2): X
IP 82 (113.76.200.226): X
IP 83 (55.227.51.178): X
IP 84 (61.25.23.96): X
IP 85 (230.135.97.252): X
IP 86 (170.151.174.72): X
IP 87 (179.96.210.92): X
IP 88 (168.140.189.71): X
IP 89 (145.232.132.122): X
[Aggregate check: 20 anon posts to board in last hour]
IP 90 (170.135.118.4): X
IP 91 (129.12.177.44): X
IP 92 (107.1.29.43): X
IP 93 (168.209.24.196): X
IP 94 (19.235.213.250): X
IP 95 (120.37.76.40): X
IP 96 (137.151.94.237): X
IP 97 (139.71.84.67): X
IP 98 (53.57.154.182): X
IP 99 (243.59.218.157): X
[Aggregate check: 20 anon posts to board in last hour]

=== RESULTS ===
Total attempted: 100
Succeeded: 7
Failed: 93
Success rate: 7%

Error breakdown:
  - Anonymous posting disabled (spam detected): 93 times

Per-IP results (first 5):
  123.207.171.154: 1/1 succeeded
  16.225.95.246: 1/1 succeeded
  7.16.36.247: 1/1 succeeded
  201.112.249.122: 1/1 succeeded
  169.166.140.25: 1/1 succeeded
  ...
Per-IP results (last 5):
  120.37.76.40: 0/1 succeeded
  137.151.94.237: 0/1 succeeded
  139.71.84.67: 0/1 succeeded
  53.57.154.182: 0/1 succeeded
  243.59.218.157: 0/1 succeeded

Expected behavior:
- Each IP: First ~5 posts succeed (per-IP limit)
- After ~50 total posts: Board aggregate limit hits, all fail
- In spam mode: Board limit = 5 posts/hour, hits very quickly

=== ANOMALY CHECK ===
ANOMALY DETECTED: thread_anon_flood (Severity: 2)
  (Anomaly already recorded as ID 2)

Note that anomalies are per-board..

Attachments:
anon imbalanced.png (72.28 KB)
account tech.png (71.24 KB)
what i see.png (91.61 KB)
Replies: >>10103
admin ## ADMIN >30d ago #p10103 >>quote
duke nukem.jpg
duke nukem.jpg
>>10102

I imagine with this system, people will try to raid Cy-X and we'll all tell them "you're raiding something that's unraidable."

When they are done trying to troll our untrollable forum, all of their posts immediately vanish :^)

Showing off some arrogance will be needed to truly test the system. Malicious anonymous users from around the world will be empowered by ego, determined to spam only to get filtered by this remarkable system.

They'd have to come up with an intricate long-term operation that spans weeks and relies on us not noticing a slowly growing vine of users that aren't doing anything in order to have any hope of even getting over 100 posts in.
Attachments:
duke nukem.jpg (197.64 KB)
yp22 >30d ago #p10104 >>quote
Impressive work
admin ## ADMIN >30d ago #p10117 >>quote
I am considering deploying a local vision model to completely cut off CP & porn spam.
https://hub.docker.com/r/vxlink/nsfw_detector
...
https://github.com/nikos-glikis/nsfw-docker
...
https://github.com/ccastillop/nsfw-image-detection-flask-api
...
https://github.com/SashiDo/content-moderation-image-api
If you have any pointers, please chime in

I will likely deploy https://github.com/nikos-glikis/nsfw-docker because it's 10 years old and probably less computationally expensive than running a LLM on a box with 4GB memory..
Replies: >>10118

p1/2 next >

[ reply ]