FS#51319 - {AUR} Make reporting abuse and spam easier
Attached to Project:
AUR web interface
Opened by Moabit (Moabit) - Monday, 10 October 2016, 23:18 GMT
Last edited by Doug Newgard (Scimmia) - Monday, 10 October 2016, 23:23 GMT
Opened by Moabit (Moabit) - Monday, 10 October 2016, 23:18 GMT
Last edited by Doug Newgard (Scimmia) - Monday, 10 October 2016, 23:23 GMT
|
Details
Currently there is no easy way to report abuse and spam in
AUR comments, nor abusive accounts. It would be great if
there were an easy way to do both of these, similarly to the
simply way one can flag packages.
As background, this package was recently spammed [1]. I searched for a way to flag the posts for deletion, and/or suggest banning the user, but there was no easy link I could click. This forum thread [2] mentions spam in another package's comments [3], where it's even worse. The poster was advised to join a mailing list, and request deletion of these comments there. However, this was never completed, presumably because it was too fiddly. Similarly, I'm disinclined to join a mailing list just to report a few spam messages on my package. (I'd bother if it were worse.) The second package has spam going back to 1.5 years ago. Any way in which the AUR could make fighting spam more easy would be welcome IMO. [1] https://aur.archlinux.org/packages/unicode/ [2] https://bbs.archlinux.org/viewtopic.php?id=215759 [3] https://aur.archlinux.org/packages/backbonejs/?comments=all |
This task depends upon
Perhaps, for starters, we can implement a captcha system for posting comments? That would take care of all the automated ones.
@x33a Ah yes, interesting find. I wonder if that means that the original identification of the site and registration are also automated? Registration might be another prevention point, but I guess would not stop the manually-registered but automatically-commented bots. Captchas for comments would stop almost all, but it's also the most intrusive for humans. I wonder if we could have some kind of tiered system, but I'm not sure what that could be based on.
It's not an uncommon tactic for stalling spammers. But of course it is no harder to check for users that have posted 100 comments over the last few hours. ;)
I seriously doubt any real user needs to post multiple comments within *5* minutes, certainly on the same package -- in fact, they should be encouraged to edit their comment instead!
If the prevention only operates on comments for a single package, then a bot could spam (e.g.) all packages at once. However, if the prevention operated on comments for *all* packages, this would be very annoying for users. I certainly have posted within 5 minutes on multiple packages, for example if the comment applies to foo and foo-git, or variants of this. I also probably have posted within 5 minutes on a single package, when there have been quick replies between me and another user.
[1] https://aur.archlinux.org/packages/unicode/
[1] https://aur.archlinux.org/packages/unicode/
More spam here. Spammers like to post links. Any way to block links for new users?
Any planned actions? I've seen some more spam recently.
Any way of actually reporting this yet?
User: https://aur.archlinux.org/account/sunny007/comments
Package maintainers and co-maintainers can pin comments, but not delete it.
Two suggestions:
1. Add a "mark as spam" option to the list of actions for package maintainers (same permissions as pinning comments)
2. Allow package maintainers delete comments from own package. This is the easy one, because there need just a little adjustment in the "can_delete_comment" function (use the logic from can_pin_comment).
This is a political question. Should package maintainers have the right to delete unwanted comments from their packages? IMHO this is the right way (giving the maintainers the right to delete comments on their own packages).
Of course, (1) is much more work intensive for the TUs, but more thorough overall. There's a few other proposals above that are also possible.
https://aur.archlinux.org/account/franklucido/comments
https://aur.archlinux.org/account/AdamEvans/comments
https://aur.archlinux.org/account/mlangenberg/comments
Please delete all spamming comments.
https://aur.archlinux.org/account/finestediting/comments
Note it has been flying under the radar for a loong time now. https://aur.archlinux.org/account/david230
https://aur.archlinux.org/packages/freetype2-cleartype/#comment-767513
https://aur.archlinux.org/packages/freetype2-cleartype/#comment-767515
https://aur.archlinux.org/packages/pomodoneapp/#comment-787206
Edit: it's gone now.