Page MenuHomePhabricator
Feed Advanced Search

Dec 22 2018

epriestley added a comment to T13215: Secure/Admin have many accounts with commercial links in profile blurbs.

$table = new PhabricatorUser();
$cache_path = 'progress.json';

Dec 22 2018, 10:15 PM · People, Phacility, Abuse
epriestley added a comment to T13215: Secure/Admin have many accounts with commercial links in profile blurbs.

I just deleted the users above and am backing away from D19933, at least for now, since it doesn't feel like an especially great fit for either secure or admin.

Dec 22 2018, 6:35 PM · People, Phacility, Abuse
epriestley added a comment to T13215: Secure/Admin have many accounts with commercial links in profile blurbs.

On admin, basically every user with a blurb is abusive. I've just disabled the field as a coarse reaction.

Dec 22 2018, 6:28 PM · People, Phacility, Abuse
epriestley updated subscribers of T13215: Secure/Admin have many accounts with commercial links in profile blurbs.

I'm planning to banish these users from secure. This is mostly: polish (?) SEO bots; printer fax spam; and "security researchers":

Dec 22 2018, 5:49 PM · People, Phacility, Abuse
epriestley added a revision to T13215: Secure/Admin have many accounts with commercial links in profile blurbs: D19933: Allow users to be "Banished", hiding their profiles and comments.
Dec 22 2018, 5:09 PM · People, Phacility, Abuse

Nov 15 2018

epriestley added a comment to T13215: Secure/Admin have many accounts with commercial links in profile blurbs.

A couple of narrow ideas here:

Nov 15 2018, 11:42 AM · People, Phacility, Abuse

Nov 6 2018

epriestley triaged T13215: Secure/Admin have many accounts with commercial links in profile blurbs as Low priority.
Nov 6 2018, 12:16 PM · People, Phacility, Abuse

Jun 12 2018

epriestley closed T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances as Resolved.

D19485 fixed one small remaining bug; I deployed that to admin.

Jun 12 2018, 8:25 PM · Mail, Phacility, Abuse
epriestley added a revision to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances: Restricted Differential Revision.
Jun 12 2018, 2:12 PM · Mail, Phacility, Abuse

Jun 8 2018

epriestley lowered the priority of T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances from Normal to Low.
Jun 8 2018, 1:54 PM · Mail, Phacility, Abuse
epriestley added a comment to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances.
  • I cherry-picked to stable and deployed to admin.
  • I launched a test instance, invited 32 users, and saw only 20 invites actually go out.
  • After accepting two invites, I saw more invites go out.
  • I cancelled some invites, for good measure.
Jun 8 2018, 1:51 PM · Mail, Phacility, Abuse
epriestley added a revision to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances: Restricted Differential Revision.
Jun 8 2018, 1:34 PM · Mail, Phacility, Abuse

Jun 7 2018

epriestley added a revision to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances: Restricted Differential Revision.
Jun 7 2018, 3:30 PM · Mail, Phacility, Abuse
epriestley added a revision to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances: Restricted Differential Revision.
Jun 7 2018, 1:49 PM · Mail, Phacility, Abuse

Jun 6 2018

epriestley added a revision to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances: Restricted Differential Revision.
Jun 6 2018, 2:04 PM · Mail, Phacility, Abuse
epriestley added a revision to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances: Restricted Differential Revision.
Jun 6 2018, 12:36 PM · Mail, Phacility, Abuse
epriestley added a revision to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances: Restricted Differential Revision.
Jun 6 2018, 12:27 PM · Mail, Phacility, Abuse
epriestley added a revision to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances: Restricted Differential Revision.
Jun 6 2018, 12:23 PM · Mail, Phacility, Abuse
epriestley added a revision to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances: Restricted Differential Revision.
Jun 6 2018, 12:19 PM · Mail, Phacility, Abuse

Jun 5 2018

epriestley added a comment to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances.

I think my plan here is basically:

Jun 5 2018, 9:51 PM · Mail, Phacility, Abuse

Jun 4 2018

epriestley added a comment to T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances.

The "Pending Invites" counter didn't seem to work correctly for this instance.

Jun 4 2018, 10:45 PM · Mail, Phacility, Abuse
epriestley triaged T13150: Limit the allowed number of open invites for Phacility instances, particularly test instances as Normal priority.
Jun 4 2018, 10:31 PM · Mail, Phacility, Abuse

Feb 14 2018

epriestley added a comment to T11989: Wage an endless war against HP Printer Fax Support.

We got a printer fax spam support request into the completely private Support app today. 😑

Feb 14 2018, 3:43 PM · Abuse

Dec 13 2017

epriestley triaged T13029: Provide some way for administrators to remove/reset a user's profile image as Wishlist priority.

As @avivey suggests, the remaining cache can be cleared with:

Dec 13 2017, 1:30 PM · Abuse, People
epriestley added a comment to T10215: Provide tools to combat and recover from abuse.

Anecdotally, Disqus uses Akismet and the hit rate isn't great (I've observed both a high false positive rate, and a high false negative rate).

Dec 13 2017, 1:26 PM · Abuse
epriestley edited projects for T13029: Provide some way for administrators to remove/reset a user's profile image, added: Abuse; removed Feature Request, Policy.
Dec 13 2017, 1:13 PM · Abuse, People
epriestley added a subtask for T10215: Provide tools to combat and recover from abuse: T13029: Provide some way for administrators to remove/reset a user's profile image.
Dec 13 2017, 1:13 PM · Abuse

Jul 27 2017

chad added a comment to T11989: Wage an endless war against HP Printer Fax Support.

Mooooooo

Jul 27 2017, 6:16 PM · Abuse
epriestley closed T11989: Wage an endless war against HP Printer Fax Support as Resolved.

We've closed registration on this install, mooting this.

Jul 27 2017, 4:45 PM · Abuse
epriestley closed T11989: Wage an endless war against HP Printer Fax Support, a subtask of T10215: Provide tools to combat and recover from abuse, as Resolved.
Jul 27 2017, 4:45 PM · Abuse

Jul 16 2017

epriestley closed T12134: Develop a Nuance-based Phabricator reporting/support flow as Resolved.

The new paid support application is now in closed beta. This will become publicly available in the relatively near future, then become then channel for SAAS support after that. It may later become the channel for some types of free/community support (most likely bug reports, per above) but this probably won't happen for a while.

Jul 16 2017, 11:23 AM · Abuse

Jul 12 2017

epriestley added a revision to T11989: Wage an endless war against HP Printer Fax Support: D18213: Finally end the printer fax war for good.
Jul 12 2017, 8:10 PM · Abuse

Jul 9 2017

chad removed the image for Abuse.
Jul 9 2017, 7:20 PM

Jun 12 2017

chad added a comment to T11989: Wage an endless war against HP Printer Fax Support.

https://secure.phabricator.com/conpherence/1336/#42940

Jun 12 2017, 5:27 AM · Abuse

Jun 10 2017

20after4 added a comment to T7593: Allow administrators to disable files to prevent "l33t w4r3z" abuse cases.

FWIW we have seen several users attempting to distribute l33t w4r3z via Wikimedia's instance of Phabricator. I had to set file upload limits to < 8MB in order to prevent chunked file storage.

Jun 10 2017, 12:36 AM · Abuse, Files

May 26 2017

chad added a comment to T11989: Wage an endless war against HP Printer Fax Support.

lol, sigh

May 26 2017, 2:19 PM · Abuse
epriestley added a comment to T11989: Wage an endless war against HP Printer Fax Support.

A handful of users had created Conpherence threads to help the community find HP printer fax support. I destroyed these threads manually. There's currently no "Can Create Threads" permission and I probably wouldn't want to lock this down today since we get some legit uses out of it too.

May 26 2017, 2:18 PM · Abuse

May 22 2017

Bezalel added a comment to T12134: Develop a Nuance-based Phabricator reporting/support flow.

You could pay reviewers with Mana ;)

May 22 2017, 12:37 PM · Abuse

Apr 3 2017

Volans added a comment to T10215: Provide tools to combat and recover from abuse.

As a small step towards a more general solution I think it would be very helpful to allow the admins to easily revert changes, where revert means that there will be no traces left of the vandal action after the revert.

Apr 3 2017, 8:50 AM · Abuse

Apr 2 2017

epriestley merged T12492: Allow an admin to delete files from the Web interface into T7593: Allow administrators to disable files to prevent "l33t w4r3z" abuse cases.
Apr 2 2017, 5:37 PM · Abuse, Files

Mar 10 2017

chad added a comment to T12383: Accumulate Phabricator changelogs applicable from a current install.

Good job triggering the spam filter.

Mar 10 2017, 5:11 PM · Feature Request, Installing & Upgrading
cspeckmim created T12383: Accumulate Phabricator changelogs applicable from a current install.
Mar 10 2017, 5:09 PM · Feature Request, Installing & Upgrading

Mar 2 2017

MZMcBride added a comment to T11989: Wage an endless war against HP Printer Fax Support.

Press F to pay respects.

Mar 2 2017, 5:50 AM · Abuse

Feb 22 2017

20after4 added a comment to T12134: Develop a Nuance-based Phabricator reporting/support flow.

FWIW I think this is pretty genius. Especially the repro-or-it-didn't-happen aspect.

Feb 22 2017, 6:36 AM · Abuse

Feb 20 2017

epriestley added a comment to T12134: Develop a Nuance-based Phabricator reporting/support flow.

Here's an attempt to manually classify recent feature requests. I'm not sure how much value we're really getting out of this channel except from users who are already part of Community:

Feb 20 2017, 12:28 PM · Abuse

Feb 16 2017

epriestley added a comment to T11989: Wage an endless war against HP Printer Fax Support.

Recently, we've started seeing a handful of attacks where human users appear to read a discussion, formulate a human-sounding, contextual reply (e.g., discussing the thread topic in what appears to be a human way, just with a very shallow understanding of the issue), and then include a link to a site offering various services (mostly essay writing?) in the footer.

Feb 16 2017, 12:29 PM · Abuse

Feb 13 2017

epriestley closed D17323: Add more phone numbers to "Shields Up" action by committing R25:515f367b0e36: Add more phone numbers to "Shields Up" action.
Feb 13 2017, 4:46 PM · Abuse
chad accepted D17323: Add more phone numbers to "Shields Up" action.
Feb 13 2017, 4:12 PM · Abuse
epriestley updated the diff for D17323: Add more phone numbers to "Shields Up" action.
  • Add unit tests.
  • Match "o" and "O" for 0, etc.
Feb 13 2017, 3:55 PM · Abuse

Feb 1 2017

chad added a comment to T10215: Provide tools to combat and recover from abuse.

We can also let installs send us all their data, we'll decide if it's spam or not, then we remotely delete any data that we feel like deleting. But we'd have to charge like a gorillion dollars per message to make this sustainable today.

Feb 1 2017, 7:10 AM · Abuse

Jan 31 2017

aklapper added a comment to T10215: Provide tools to combat and recover from abuse.

A while ago on some Phab instance I experienced people uploading copyrighted material as either files or Pholio mockups, then creating custom panels embedding those files plus creating a dashboard. Very creative and convenient. :) My guts also tell me that Conpherence rooms only accessible to specific users were involved to communicate/coordinate, but as admins are not all-powerful no-one could prove, I'm afraid.

fs.png (626×672 px, 19 KB)

"Recent Activity" on /p/username/ seems to not display a user's panel + dashboard creations/edits, even if I had rights to access those items. This might be something to reconsider?

Jan 31 2017, 12:12 PM · Abuse

Jan 20 2017

epriestley merged T9212: Community Feedback: How should we handle free support? into T12134: Develop a Nuance-based Phabricator reporting/support flow.
Jan 20 2017, 6:00 PM · Abuse
epriestley created T12134: Develop a Nuance-based Phabricator reporting/support flow.
Jan 20 2017, 5:32 PM · Abuse

Jan 11 2017

epriestley removed a subtask for T10215: Provide tools to combat and recover from abuse: T9741: Default Edit Policy for Differential.
Jan 11 2017, 5:03 PM · Abuse
epriestley removed a parent task for T9741: Default Edit Policy for Differential: T10215: Provide tools to combat and recover from abuse.
Jan 11 2017, 5:03 PM · Differential
testingtesting added a subtask for T10215: Provide tools to combat and recover from abuse: T9741: Default Edit Policy for Differential.
Jan 11 2017, 5:02 PM · Abuse
testingtesting added a parent task for T9741: Default Edit Policy for Differential: T10215: Provide tools to combat and recover from abuse.
Jan 11 2017, 5:02 PM · Differential
testingtesting added a project to T9741: Default Edit Policy for Differential: Abuse.
Jan 11 2017, 5:01 PM · Differential

Jan 5 2017

epriestley added a comment to T11989: Wage an endless war against HP Printer Fax Support.

That one is somewhat interesting because the user created a safe-looking object, then edited the objectionable content into it. I had hoped we might see a few years of uneasy peace before things escalated so far.

Jan 5 2017, 3:33 PM · Abuse
johnny-bit added a comment to T11989: Wage an endless war against HP Printer Fax Support.

Endless war continues with E1323 😉

Jan 5 2017, 10:58 AM · Abuse

Dec 23 2016

epriestley updated subscribers of T11989: Wage an endless war against HP Printer Fax Support.

Users @techhelpuk and @antivirussupportuk each created one new Calendar event this morning, offering help with anti-virus software instead of printers and encouraging users to call new numbers.

Dec 23 2016, 2:49 PM · Abuse

Dec 19 2016

Herald added a project to T9530: Release Server / Workflow app / Future of Releeph : Abuse.
Dec 19 2016, 10:13 AM · Restricted Project, Harbormaster

Dec 12 2016

epriestley updated subscribers of T11989: Wage an endless war against HP Printer Fax Support.

We scored our first kill today. @dgdfgdg slipped through our defenses in his initial volley, but we reacted quickly and the system automatically deflected his second salvo.

Dec 12 2016, 11:14 PM · Abuse

Dec 11 2016

epriestley added a comment to T11989: Wage an endless war against HP Printer Fax Support.

I have a not-so-bad version of this in mind but it seems that the printer faxers are too terrified of our advanced defenses to even attack us any more.

Dec 11 2016, 8:41 PM · Abuse

Dec 10 2016

lewellyn added a comment to T11989: Wage an endless war against HP Printer Fax Support.

OK, so just unfortunate timing then. Ignore the smell of smoke, there's no fire apparently. :)

Dec 10 2016, 9:04 PM · Abuse
chad added a comment to T11989: Wage an endless war against HP Printer Fax Support.

I turned on email verification if you previously made an account here and never verified it, you were probably prompted.

Dec 10 2016, 8:12 PM · Abuse
lewellyn added a comment to T11989: Wage an endless war against HP Printer Fax Support.

If you are not an administrator and create a task with THE FAX SUPPORT NUMBER THAT SHALL NOT BE NAMED in the title or body, you will now be immediately logged out of all your sessions and your task will be quarantined.

Dec 10 2016, 7:36 PM · Abuse

Dec 9 2016

chad added a comment to T11989: Wage an endless war against HP Printer Fax Support.

I thought it was OK for us to test various revenue streams?

Dec 9 2016, 9:07 PM · Abuse
epriestley added a comment to T11989: Wage an endless war against HP Printer Fax Support.

If you are not an administrator and create a task with THE FAX SUPPORT NUMBER THAT SHALL NOT BE NAMED in the title or body, you will now be immediately logged out of all your sessions and your task will be quarantined.

Dec 9 2016, 7:37 PM · Abuse
epriestley added a revision to T11989: Wage an endless war against HP Printer Fax Support: D17017: Add a state-of-the art defense against HP Fax Support.
Dec 9 2016, 7:26 PM · Abuse
epriestley created T11989: Wage an endless war against HP Printer Fax Support.
Dec 9 2016, 7:25 PM · Abuse

Dec 5 2016

epriestley closed T11950: jkhkjhkjh as Invalid.
Dec 5 2016, 2:19 PM · llvm, Abuse
kobbygl added a project to T11950: jkhkjhkjh: llvm.
Dec 5 2016, 2:12 PM · llvm, Abuse
kobbygl created T11950: jkhkjhkjh.
Dec 5 2016, 2:12 PM · llvm, Abuse

Nov 17 2016

9700pro added a watcher for Abuse: 9700pro.
Nov 17 2016, 11:19 PM

Oct 21 2016

epriestley updated the task description for T11780: Consider quota systems.
Oct 21 2016, 2:44 PM · Phacility, Abuse
epriestley created T11780: Consider quota systems.
Oct 21 2016, 2:44 PM · Phacility, Abuse

Oct 19 2016

sergey.vfx added a comment to T10215: Provide tools to combat and recover from abuse.

That is quite hard to protect against real people dedicating their time on spamming projects. As @epriestley mentioned, there are paid systems for that.

Oct 19 2016, 9:24 AM · Abuse
mont29 added a comment to T10215: Provide tools to combat and recover from abuse.

From what we've seen on this install, the "printer fax support" spammers are humans willing to go to significant lengths to overcome access barriers (they fill out Captchas, register and link GitHub/Google accounts, validate email addresses, successfully navigate workflow changes, originate from different remote addresses, and take actions slowly), so I suspect no automated system designed to deter bots will be effective against them. My best guess is that they're being recruited through Mechanical Turk or some similar system.

Oct 19 2016, 8:44 AM · Abuse

Oct 18 2016

epriestley added a comment to T10215: Provide tools to combat and recover from abuse.

I can't remember if Phabricator already requires a confirmed e-mail address to do anything.

Oct 18 2016, 10:46 PM · Abuse
MZMcBride added a comment to T10215: Provide tools to combat and recover from abuse.
  • Custom Blender specific captcha or question that bots can't answer
Oct 18 2016, 10:39 PM · Abuse
brechtvl added a comment to T10215: Provide tools to combat and recover from abuse.

Of course there's no totally automatic and reliable system, we're just trying to find something better than manually removing dozens of spam tasks every day.

Oct 18 2016, 8:50 PM · Abuse
epriestley added a comment to T10215: Provide tools to combat and recover from abuse.

We can also let installs send us all their data, we'll decide if it's spam or not, then we remotely delete any data that we feel like deleting. But we'd have to charge like a gorillion dollars per message to make this sustainable today.

Oct 18 2016, 8:10 PM · Abuse
chad added a comment to T10215: Provide tools to combat and recover from abuse.

Nuance (Phabricator Help Desk) is the only reasonable way forward here I can think of, which puts new tasks into a private queue). Anything else is cat & mouse with spammers and that's just a huge time sink for us with no obvious benefit (99% of installs are private).

Oct 18 2016, 7:19 PM · Abuse
epriestley added a comment to T10215: Provide tools to combat and recover from abuse.

What sort of reliable and automatic solution are you hoping for? How could the system reliably, automatically detect that a user is a spammer or that a task assignment is unwanted?

Oct 18 2016, 7:07 PM · Abuse
brechtvl added a comment to T10215: Provide tools to combat and recover from abuse.

The past few days we've had a lot of spam on the Blender phabricator instance. These spammers are also assigning tasks to random users, who then get emailed. See here for examples:
https://developer.blender.org/maniphest/query/all/

Oct 18 2016, 6:23 PM · Abuse

Sep 11 2016

chad closed T11616: khdgfdh as Spite.
Sep 11 2016, 5:12 PM · Abuse
zuberahmed1987 created T11616: khdgfdh.
Sep 11 2016, 4:10 PM · Abuse

Aug 23 2016

epriestley closed T4909: Rate limit or restrict access to comment removal as Wontfix.

As far as I know, no users have actually gone berserk and deleted all their comments in nearly two years now, so I don't plan to specifically build comment removal rate limiting: this action does not seem particularly more dangerous or abuse-prone in practice than other actions like adding comments, merging tasks, etc. If a user did do this, recovery is likely not very difficult even without limiting.

Aug 23 2016, 10:38 PM · Abuse, Wikimedia

Jul 9 2016

eadler added a comment to T11254: Provide a way for quick revert of all activities of the most recent task editor..
Jul 9 2016, 4:09 AM · Abuse, Maniphest, Wikimedia, Feature Request

Jul 8 2016

epriestley added a comment to T11254: Provide a way for quick revert of all activities of the most recent task editor..

This is enormously complex to implement in the general case.

Jul 8 2016, 11:49 AM · Abuse, Maniphest, Wikimedia, Feature Request

Jul 3 2016

Danny_B added a comment to T11254: Provide a way for quick revert of all activities of the most recent task editor..

Suggestion from one chat I had:

I mean even having just a "Revert" button for each change would be easier
Even if you had 50 to click, it's better than manually undoing :)

Jul 3 2016, 8:53 AM · Abuse, Maniphest, Wikimedia, Feature Request
eadler added a project to T11254: Provide a way for quick revert of all activities of the most recent task editor.: Abuse.
Jul 3 2016, 5:49 AM · Abuse, Maniphest, Wikimedia, Feature Request

Jul 1 2016

epriestley added a subtask for T10215: Provide tools to combat and recover from abuse: T11254: Provide a way for quick revert of all activities of the most recent task editor..
Jul 1 2016, 7:18 PM · Abuse

Jun 7 2016

epriestley closed T11106: Prueba as Invalid.
Jun 7 2016, 5:40 PM · Abuse
cristomanuel created T11106: Prueba.
Jun 7 2016, 5:06 PM · Abuse

May 23 2016

epriestley closed T11014: Voluptas soluta ut quod vel vel voluptatem quo provident autem reprehenderit dolorem quibusdam ullamco at reprehenderit natus obcaecati labore debitis as Spite.
May 23 2016, 2:33 PM · Abuse
hacker924 created T11014: Voluptas soluta ut quod vel vel voluptatem quo provident autem reprehenderit dolorem quibusdam ullamco at reprehenderit natus obcaecati labore debitis.
May 23 2016, 2:26 PM · Abuse

May 7 2016

epriestley removed a project from T7593: Allow administrators to disable files to prevent "l33t w4r3z" abuse cases: Facebook.
May 7 2016, 1:15 PM · Abuse, Files
rubenriverae added a project to T7593: Allow administrators to disable files to prevent "l33t w4r3z" abuse cases: Facebook.
May 7 2016, 1:03 PM · Abuse, Files