<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #761: Spam account cull</title>
    <link>http://localhost:8080/trac/ticket/761</link>
    <description>&lt;p&gt;
There are bucketloads of spam accounts swamping us. Spam commeting is swarming again. I just did several pages of deleting spam accounts.  No doubt I nailed some humans too (sorry Sam if this comes back to you); but the overwhelming majority of new accounts are spam.
&lt;/p&gt;
&lt;p&gt;
It's crap and we need to have another spam sweep - especially if we're staying in D6 for a while.
&lt;/p&gt;
&lt;p&gt;
See work done in Feb 2013: &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/461" title="enhancement: Spam account war (assigned)"&gt;#461&lt;/a&gt;
See wiki page done in Feb 2013: &lt;a class="ext-link" href="https://wiki.transitionnetwork.org/Spam_accounts"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/Spam_accounts&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
SAM I'm going to suggest you start looking at it, and get your head around it, and the various modules and processes we've got running, then ask you to act/escalate accordingly.
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/761</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Thu, 17 Jul 2014 09:02:05 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:1</guid>
      <description>
        &lt;p&gt;
@Sam: let me know if you need more eyes on this.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 17 Jul 2014 12:10:19 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:2</guid>
      <description>
        &lt;p&gt;
I ran this report: &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/reports/spam/same-names"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/reports/spam/same-names&lt;/a&gt; and deleted all users with the same first/last name.
&lt;/p&gt;
&lt;p&gt;
I see that the registration form isn't currently protected by Mollom:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/settings/mollom/add"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/settings/mollom/add&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
This might be an easy win, unless you have tried before and run into problems?
&lt;/p&gt;
&lt;p&gt;
Shall I try it?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 17 Jul 2014 14:19:18 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/761#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
We could try the honeypot method?
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.drupal.org/project/honeypot"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/honeypot&lt;/a&gt;
&lt;a class="ext-link" href="http://www.midwesternmac.com/blogs/jeff-geerling/introducing-honeypot-form-spam"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.midwesternmac.com/blogs/jeff-geerling/introducing-honeypot-form-spam&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 17 Jul 2014 15:13:54 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:4</guid>
      <description>
        &lt;p&gt;
Hi Paul
&lt;/p&gt;
&lt;p&gt;
Just spotted that Mollom would set up a honeypot too if we enabled it on that registration form
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://mollom.com/features"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://mollom.com/features&lt;/a&gt;
"Hidden honeypots - In our Drupal Mollom module, we've added a basic honeypot to all forms protected by Mollom, through the use of a hidden field, a common way to trick spam bots into revealing themselves. This significantly reduces the number of spam bots attempting to game your web forms."
&lt;/p&gt;
&lt;p&gt;
I think we should give Mollom a try in the first instance, then look for additional solutions if it doesn't fix it.
&lt;/p&gt;
&lt;p&gt;
Any objections to enabling it for the registration form?
&lt;/p&gt;
&lt;p&gt;
On Wordpress sites I have found this helps a lot: &lt;a class="ext-link" href="http://blog.fili.nl/the-anti-captcha-challenge/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://blog.fili.nl/the-anti-captcha-challenge/&lt;/a&gt; the user does need to have javascript and cookies enabled.
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 17 Jul 2014 22:55:56 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/761#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:5</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.25&lt;/em&gt; to &lt;em&gt;0.375&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Hi Sam,
&lt;/p&gt;
&lt;p&gt;
Good.  Let's give that a try.
&lt;/p&gt;
&lt;p&gt;
Best, Paul
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Fri, 18 Jul 2014 09:02:11 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:6</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:6</guid>
      <description>
        &lt;p&gt;
Sounds good!
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Fri, 18 Jul 2014 10:23:10 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:7</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:7</guid>
      <description>
        &lt;p&gt;
I just enabled Mollom on the registration form and attempted to register a test user to check it's all OK.
&lt;/p&gt;
&lt;p&gt;
I did the initial &lt;a class="missing wiki"&gt;ReCaptcha?&lt;/a&gt; and all seemed to be OK
&lt;/p&gt;
&lt;p&gt;
Due to the spammy username I used I was additionally presented with the Mollom Captcha, answered it correctly.
&lt;/p&gt;
&lt;p&gt;
I was then blocked from proceeding, I'm pretty sure by Botcha (based on the error message): &lt;a class="ext-link" href="https://www.drupal.org/project/botcha"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/project/botcha&lt;/a&gt; Looking at the new issues, 27 open bugs &amp;amp; non existent developer response rate it looks to me like this module is falling into disrepair. It seems that at the moment it's not working in that it's blocking real users and allowing spammers in.
&lt;/p&gt;
&lt;p&gt;
I see this issue has history here: &lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/ticket/514"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/ticket/514&lt;/a&gt; And I do get a trickle of support enquiries from users having problems getting registered.
&lt;/p&gt;
&lt;p&gt;
I propose that we disable the Botcha module for 24 hours, leave &lt;a class="missing wiki"&gt;ReCaptcha?&lt;/a&gt;, Spambot &amp;amp; Mollom enabled on the form and see what happens.
&lt;/p&gt;
&lt;p&gt;
If in 24 hours there is a marked increase in Spam registrations we could turn it on again.
&lt;/p&gt;
&lt;p&gt;
Any objections?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 18 Jul 2014 10:29:17 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/761#comment:8</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:8</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.375&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Sounds like a good plan. +1
&lt;/p&gt;
&lt;p&gt;
I had to remove that module to get a local version of the site running.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Fri, 18 Jul 2014 12:58:11 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:9</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:9</guid>
      <description>
        &lt;p&gt;
OK so over the last 24 hours we have had 8 users register.
&lt;/p&gt;
&lt;p&gt;
These one is definitely a spammer
&lt;a class="ext-link" href="https://www.transitionnetwork.org/user/20282/spambot"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/user/20282/spambot&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
These two seem to be likely spammers
&lt;a class="ext-link" href="https://www.transitionnetwork.org/user/20286/spambot"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/user/20286/spambot&lt;/a&gt; (Forex, sex returned on google search for email address
&lt;a class="ext-link" href="https://www.transitionnetwork.org/user/20282/spambot"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/user/20282/spambot&lt;/a&gt; ('how to remove virus's' returned on google search for the  xxx.mail.ru email)
&lt;/p&gt;
&lt;p&gt;
The remaining five appear to be legit users at first glance
&lt;a class="ext-link" href="https://www.transitionnetwork.org/user/20285/spambot"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/user/20285/spambot&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/user/20283/spambot"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/user/20283/spambot&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/user/20290/spambot"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/user/20290/spambot&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/user/20287/spambot"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/user/20287/spambot&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/user/20288/spambot"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/user/20288/spambot&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I have disabled the Botcha on the registration form. I'll check back in an hour to make sure I haven't opened the floodgates, then in 24 hours see if the proportion of legit/ spam accounts has changed significantly.
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Fri, 18 Jul 2014 13:06:54 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:10</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:10</guid>
      <description>
        &lt;p&gt;
Actually the webgui won't work to disable it on a per-form basis. Seems even that is broken.
&lt;/p&gt;
&lt;p&gt;
So I have disabled the module. As before I'll check back in an hour.
&lt;/p&gt;
&lt;p&gt;
Test registration successfully completed now too.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Sat, 19 Jul 2014 12:45:35 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:11</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:11</guid>
      <description>
        &lt;p&gt;
Well that didn't work on two counts.
&lt;/p&gt;
&lt;p&gt;
1, More spammy looking users registered over the last 24 hours
&lt;/p&gt;
&lt;p&gt;
2, We went over the limits of spam lookups set for the Mollom free version.
&lt;/p&gt;
&lt;p&gt;
I have therefore restarted the Botcha module and disabled Mollom on the registration form.
&lt;/p&gt;
&lt;p&gt;
Looking at Botcha a bit more these are the Honeypot/checks it carries out:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/user/botcha/recipebook/default"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/user/botcha/recipebook/default&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing wiki"&gt;NoResubmit?&lt;/a&gt; (working without &lt;a class="missing wiki"&gt;JavaScript?&lt;/a&gt;): The method consideres as spam all submissions made using already submitted forms.
&lt;/p&gt;
&lt;p&gt;
Timegate (working without &lt;a class="missing wiki"&gt;JavaScript?&lt;/a&gt;): During the form generation hidden by CSS field is added to the form containing the timestamp. At the moment of submission this timestamp is used for spam check: if the form is submitted too fast, the submission is considered as spam. The minimum number of seconds that must elapse from the time of form generation is an adjustable parameter.
&lt;/p&gt;
&lt;p&gt;
Honeypot: Implementation of honeypot-trap. The gist of it is that the field is added to the form with a certain value, which is then modified by JS. Spam is any form submission, the calculated value of which is not the same as we need.
Honeypot2: The same as above, but using as a source of calculation not the value of a particular field, but the data from CSS.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing wiki"&gt;ObscureUrl?&lt;/a&gt;: Similar to the previous recipe: constructed by JS is compared to the need. The difference is that the initial value is passed through the GET-parameter.
&lt;/p&gt;
&lt;p&gt;
Not sure where we go from here. Personally I'm a bit concerned about the false positives we are getting from Botcha. For every user that emails me I guess there will be 5? 10? 20? who just give up. We could try selectively disabling some of the recipes its using and see if we can eliminate the false positives?
&lt;/p&gt;
&lt;p&gt;
That doesn't of course address the spam registrations. I had Mollom set to 'normal' so I could try it on 'strict' and see if that helps, however even if it does we'd then need to pay $30/month for the increased number of submissions we get from the registration form.
&lt;/p&gt;
&lt;p&gt;
Anyone got any ideas for free solutions we could try?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
&lt;p&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Mon, 21 Jul 2014 08:44:26 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:12</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:12</guid>
      <description>
        &lt;p&gt;
and there is a long history of the work done before on &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/461" title="enhancement: Spam account war (assigned)"&gt;#461&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 21 Jul 2014 09:03:36 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:13</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:13</guid>
      <description>
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/761#comment:11" title="Comment 11 for Ticket #761"&gt;sam&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Well that didn't work on two counts.
&lt;/p&gt;
&lt;p&gt;
1, More spammy looking users registered over the last 24 hours
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
We will always get spammy looking registration accounts on any of our public websites. If these accounts start leaving spammy content we will then need to disable their account and block their Ip address.
&lt;/p&gt;
&lt;p&gt;
Having a look a the website logs ...
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
2, We went over the limits of spam lookups set for the Mollom free version.
&lt;/p&gt;
&lt;p&gt;
I have therefore restarted the Botcha module and disabled Mollom on the registration form.
&lt;/p&gt;
&lt;p&gt;
Looking at Botcha a bit more these are the Honeypot/checks it carries out:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/user/botcha/recipebook/default"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/user/botcha/recipebook/default&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing wiki"&gt;NoResubmit?&lt;/a&gt; (working without &lt;a class="missing wiki"&gt;JavaScript?&lt;/a&gt;): The method consideres as spam all submissions made using already submitted forms.
&lt;/p&gt;
&lt;p&gt;
Timegate (working without &lt;a class="missing wiki"&gt;JavaScript?&lt;/a&gt;): During the form generation hidden by CSS field is added to the form containing the timestamp. At the moment of submission this timestamp is used for spam check: if the form is submitted too fast, the submission is considered as spam. The minimum number of seconds that must elapse from the time of form generation is an adjustable parameter.
&lt;/p&gt;
&lt;p&gt;
Honeypot: Implementation of honeypot-trap. The gist of it is that the field is added to the form with a certain value, which is then modified by JS. Spam is any form submission, the calculated value of which is not the same as we need.
Honeypot2: The same as above, but using as a source of calculation not the value of a particular field, but the data from CSS.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing wiki"&gt;ObscureUrl?&lt;/a&gt;: Similar to the previous recipe: constructed by JS is compared to the need. The difference is that the initial value is passed through the GET-parameter.
&lt;/p&gt;
&lt;p&gt;
Not sure where we go from here. Personally I'm a bit concerned about the false positives we are getting from Botcha. For every user that emails me I guess there will be 5? 10? 20? who just give up. We could try selectively disabling some of the recipes its using and see if we can eliminate the false positives?
&lt;/p&gt;
&lt;p&gt;
That doesn't of course address the spam registrations. I had Mollom set to 'normal' so I could try it on 'strict' and see if that helps, however even if it does we'd then need to pay $30/month for the increased number of submissions we get from the registration form.
&lt;/p&gt;
&lt;p&gt;
Anyone got any ideas for free solutions we could try?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 21 Jul 2014 09:04:25 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/761#comment:14</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:14</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.5&lt;/em&gt; to &lt;em&gt;0.75&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Sorry, forgot to add time
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 21 Jul 2014 10:21:43 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/761#comment:15</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:15</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.75&lt;/em&gt; to &lt;em&gt;1.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/761#comment:12" title="Comment 12 for Ticket #761"&gt;ed&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
and there is a long history of the work done before on &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/461" title="enhancement: Spam account war (assigned)"&gt;#461&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Thanks Ed. I had a quick read through this to get up to speed.
&lt;/p&gt;
&lt;p&gt;
Some additional thoughts on way to reduce spam:
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;Only allow users who have a *member* role access to post content  / comments on the site - without moderation. This member role could be :
&lt;/li&gt;&lt;/ol&gt;&lt;ol class="lowerroman"&gt;&lt;li&gt; requested for: from the editor
&lt;/li&gt;&lt;li&gt;automatically given to a new user after the user has done a few things on the website (validated their email address, posted a comment (accepted by a moderator) , ..)
&lt;/li&gt;&lt;li&gt;automatically given to the user after being signed up a paid member.
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
The third option  would also eliminate spam user accounts as well as spam content.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Mon, 21 Jul 2014 10:38:12 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:16</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:16</guid>
      <description>
        &lt;ol class="lowerroman"&gt;&lt;li&gt;That would upset the bloggers - and we don't really have the resources to handle pre-moderation generally
&lt;/li&gt;&lt;li&gt;We looked into 'whitelists' whereby you pre-moderate once then they get access - can't do it in D6
&lt;/li&gt;&lt;li&gt;no paid members in this system...
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
there is a set up which deletes all un-authenticated accts after a period of time
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 21 Jul 2014 10:48:36 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/761#comment:17</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:17</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.25&lt;/em&gt; to &lt;em&gt;1.375&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Ed
&lt;/p&gt;
&lt;p&gt;
Is there is anything documented for (ii)  It should be possible to do this. May need to write some of the code. Let me know if you want to explore this further.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Mon, 21 Jul 2014 15:58:15 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:18</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:18</guid>
      <description>
        &lt;p&gt;
Paul - nothing documented for ii.
&lt;/p&gt;
&lt;p&gt;
And no custom code on old site if at all possible... :)
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 21 Jul 2014 16:01:59 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:19</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:19</guid>
      <description>
        &lt;p&gt;
I forgot! Cool. Thanks Ed
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Thu, 14 Aug 2014 13:48:21 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:20</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:20</guid>
      <description>
        &lt;p&gt;
Sam any progress/news on this?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 14 Aug 2014 14:57:30 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:21</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:21</guid>
      <description>
        &lt;p&gt;
Hi Ed.
&lt;/p&gt;
&lt;p&gt;
I have just manually purged the spammy comments again.
&lt;/p&gt;
&lt;p&gt;
We could do this;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Require comments to be pre-moderated for 'Authenticated' users (in permissions Skip Comment Approval check box)
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Create a new role as Paul has suggested, 'Trusted' or whatever.
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Create a rule that adds this 'Trusted' role to users who have had a comment approved.
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Allow 'Trusted' users to comment without pre-moderation
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
I realise this would increase admin overhead slightly, but honestly if we are checking comments anyway I think it would be a similar workload.
&lt;/p&gt;
&lt;p&gt;
The other thing I thought of is to not allow links in comments or forum posts..
&lt;/p&gt;
&lt;p&gt;
Could do this by simply adding &amp;lt;a&amp;gt; to the disallowed tags on 'basic html' input, only editors and admins could then create links..
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 14 Aug 2014 15:09:21 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/761#comment:22</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:22</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.375&lt;/em&gt; to &lt;em&gt;1.5&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Another idea is to have a team of moderators who can contribute time to check comments that need approval. I could be your first volunteer!
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Thu, 14 Aug 2014 15:26:08 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:23</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:23</guid>
      <description>
        &lt;p&gt;
Thanks both. OK. It's a start on the commens, if not the user accounts. SO:
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;Let's proceed with the proposal from &lt;a class="missing wiki"&gt;Paul/Sam?&lt;/a&gt; - please use this wiki page to document our proposal: &lt;a class="ext-link" href="https://wiki.transitionnetwork.org/Spam_accounts"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/Spam_accounts&lt;/a&gt; to get agreement *first* before we do anything on TN.org. I will need a very very clear page to refer to when we handle the grizzling from users.
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="2"&gt;&lt;li&gt;disabling tags in comments: would that put off bots and human spammers? It would certainly upset some honest users
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="3"&gt;&lt;li&gt;team of moderators: have tried variants of it in the past - notably the fora - without success - in the past, people show interest, then agree, then don't do it. am happy if paul you want to volunteer, and foresee Sam and Ed enjoying this
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="4"&gt;&lt;li&gt;We need to be careful about timing and communicating this change - August is a good time to do it, but ED to write up a blog ready for the newsletter, approve with Sarah, let Rob know when he's back etc...
&lt;/li&gt;&lt;/ol&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 14 Aug 2014 16:55:19 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:24</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:24</guid>
      <description>
        &lt;p&gt;
Ah slight flaw in this plan; we don't have the rules module installed. ( I was just checking Rules can trigger on comment publish, Not 100% sure it can)
&lt;/p&gt;
&lt;p&gt;
I'll investigate whether we can do the role adding using Triggers &amp;amp; Actions instead (which is already installed)
&lt;/p&gt;
&lt;p&gt;
Thinking about it some more, perhaps we (as a wider team) could just pre-moderate the first comment from a user that contains a URL? It would mean that most users would publish straight away, &amp;amp; we'd have to look at a smaller number of posts..
&lt;/p&gt;
&lt;p&gt;
Not sure how we would do it technically, but seems like a good compromise between usability &amp;amp; spam?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Fri, 15 Aug 2014 09:25:13 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:25</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:25</guid>
      <description>
        &lt;p&gt;
interesting ideas!!
i'm only vaguely following this but i have done a lot of work with triggers and actions, so let me know. i guess this is something that will change a lot when we move forward to TNv3. i wander how WP4.0 handles spam? some research would be useful. i'll keep it on the TODO.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 18 Aug 2014 12:38:55 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/761#comment:26</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:26</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.5&lt;/em&gt; to &lt;em&gt;1.75&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/761#comment:24" title="Comment 24 for Ticket #761"&gt;sam&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Ah slight flaw in this plan; we don't have the rules module installed. ( I was just checking Rules can trigger on comment publish, Not 100% sure it can)
&lt;/p&gt;
&lt;p&gt;
I'll investigate whether we can do the role adding using Triggers &amp;amp; Actions instead (which is already installed)
&lt;/p&gt;
&lt;p&gt;
Thinking about it some more, perhaps we (as a wider team) could just pre-moderate the first comment from a user that contains a URL? It would mean that most users would publish straight away, &amp;amp; we'd have to look at a smaller number of posts..
&lt;/p&gt;
&lt;p&gt;
Not sure how we would do it technically, but seems like a good compromise between usability &amp;amp; spam?
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I think all the approaches mentioned above would require some custom code.
&lt;/p&gt;
&lt;p&gt;
@Sam
Would you advise how much comment spam you have seen over the last week? and any other information that would help to build a picture of the current problem for later reference.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Tue, 19 Aug 2014 08:12:13 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/761#comment:27</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/761#comment:27</guid>
      <description>
        &lt;p&gt;
I just deleted about 15-20 comments from node types blog and Transition Network news - mostly from the first page of the listings &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/content/comment/recent?type=network_news"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/content/comment/recent?type=network_news&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>