I added a real-time chat to my blog, people used it to attack me

en.andros.dev

67 points by andros 13 hours ago


skygazer - 13 minutes ago

Like an idiot, I once wrote a simple, internal, in memory chat room via web page at work. Because it let you pick a nickname, co-workers immediately gave themselves names of other employees and started sexually harassing each other and being asses. I pulled it down immediately before they got me fired. Anonymity does something to some people. They lurk among us biding their time, looking for any opportunity to be reputationally unrestrained.

zetanor - 12 hours ago

Talking about this like there's an "attack" feels very melodramatic. It seems to me like the non-constructive messages are either shitposts or just curious probes (testing whether certain codepoints make it through, testing whether bad no-no words make it through, testing how various things will render, testing whether the input is sanitized...). There's links to God knows what and some walls of inflammatory language, but I'm not noticing anything that could even remotely cause any harm.

egypturnash - 12 hours ago

The chat is still there in the corner of this post, with people typing nasty shit into it.

Well have fun delving into programmatic censorship I guess. Or just take it out. If you take the former path and post about trying to fix it here then I'm sure you'll get a lot more free testing of your attempts to enforce civility through regex or whatever. Enjoy learning about the Scunthorpe problem.

dylan604 - 12 hours ago

From the earliest days of websites allowing text input from users, this has been a thing. The same with any website that allows you to draw things, it will quickly show people drawing crude (in content not skill) objects. This is just human nature. Once people realized you could use these forms as attack vectors, we were off to the races. Now that bots can do it for you, I'd only imagine the time before first bot using the form is in minutes. I have seen all sorts of things suggested as workarounds to mitigate bot form submissions, but eventually, you will be spammed at the least with the feature. Adding something like a bot chat, of course people are going to be abusive to it much more than a simple form field.

For someone to be surprised by this today suggests to me that the person is really really new to managing a website.

alnwlsn - 10 hours ago

I've done this to myself too. I once had a thermal receipt printer I wasn't using, so I decided to point a webcam at it and put it on a webpage so anyone could print random crap to it (it's actually still up - alnwlsn.com/printer). Of course I went in knowing full well what I was getting into, and the types of messages posted to it are about what you expect and get here. Some highlights:

- It was once found by one of those worse-than-4chan places, who spent about 4 hours spamming the worst things you could imagine until it ran out of paper. I added some filtering after that to stop tons of duplicate messages from wasting so much paper and some regex, which reduced the volume of some particularly vile things. Some people do post nice messages too.

- The setup breaks often. Eventually, I'll notice and fix it, but it might have been broken for months. Inevitibly, there will be people using it again within days, with no announcement made. How enough people find it on this tiny corner of the internet is a mystery to me, but they do. I am convinced most of them are real people, because why even bother to point a bot at it?

The whole point was that I thought it would be more interesting than letting the thing sit around on a shelf, and to use up the box of rolls that came with it instead of throwing the whole thing in the trash. Intersting it is; I don't think I would describe it as plesant, but it is interesting.

JSR_FDED - 12 hours ago

I’d suggest one additional heuristic: once your bad word detector has triggered, shut down the chat for 10 minutes. That way waves of assholes don’t monopolize the chat, and when they move on to the next target the functionality returns to your site automatically.

fl4regun - 12 hours ago

I'm mostly curious why anyone would bother with doing attacks like this to some random individuals personal blog, was it one person or multiple people? What was the motivation? Is it just bots crawling the internet to spread hate?

A sad state of affairs, but certainly seems like having a strictly moderated comment section is a better option for a site like this.

elcritch - 12 hours ago

Reminds me of Maria Abramovic Rythym 0 performance art.

1: https://www.thecrimson.com/article/2023/3/30/maria-abramovic...

throwawayffffas - 12 hours ago

The obvious solution is shutting it down it does offer nothing.

Short of that shadow ban everyone everyone sees their own messages, and add a few fake ones every now and then.

embedding-shape - 12 hours ago

"What I learned" seems to missing what used to be shared to every starting web developer; "If you allow user input on public internet pages, people will put vulgar, racist, hacking attempts and worse there, sometimes constantly over long periods of time"

Almost anyone who had a "guest book" had pre-moderation some way or another, or was a tiny-tiny website with barely any visitors. The second the larger cyberspace ecosystem got a whiff of your user-input-enabled website, the spamming would appear.

skeeter2020 - 11 hours ago

>> The countermeasures

>> The first and most obvious one was a filter of inappropriate words and expressions.

Wouldn't the first and most obvious one be "drop real-time chat" from a blog?

cestith - 9 hours ago

The whole premise seems clueless about security, accountability, and human nature. A free, fully anonymous, unauthenticated, ephemeral chat is like a middle school bathroom at best. There’s not even a concept of screen names to carry a reputation like in open IRC chat. It was always going to be this.

Sidhant_ch - 12 hours ago

You just got yourself a product right there if it works and can market it as Roast me Blog with just trigger filters in your chat to make it healthy roast in place of abuse and highlight top roasters where people could upvote right there in your chat. Negativity turned into positive healthy banter ..

hmokiguess - 12 hours ago

Content moderation and social anonymous behaviour aside, your real-time chat is really poorly implemented UX wise.

I saw the same message appearing more than once, I never saw my own message appear, it has a weird lag/delay feel to it. I didn't really enjoy that experience at all.

dwroberts - 12 hours ago

Obviously insults and attacks are unreasonable, but I think the tag injection etc should be an expected one if you’re posting on HN right? Like somebody is going to try it for kicks and I wouldn’t say it’s even necessarily malicious

wasmitnetzen - 12 hours ago

Well, you've just painted a big target on your blog. This is the internet, after all.

vivzkestrel - 11 hours ago

``` The first and most obvious one was a filter of inappropriate words and expressions. I won't explain which ones or how it works inside, for obvious reasons, but it is quite effective. The machinery is in the heuristics.

The second, and most natural, was to cut the maximum number of characters way down. Less room is less ammunition to cover content and less space to hide a link. ```

- you forgot the third fix, disable copy paste inside chat boxes, remove all swear words by replacing them with **

CerebralCoding - 12 hours ago

This should come as a surprise to absolutely nobody.

But hey traffic is traffic I guess.

- 11 hours ago
[deleted]
none_to_remain - 11 hours ago

There seems to be one category of technological "attack", which failed - the script injections.

Otherwise:

OK: A guy insults the Tailwinds devs at length

Not OK: Anyone insults that guy briefly

Of course it is his own platform (blog) but that is on another platform (hosting) which could maybe decide they don't want their platform used to attack open source projects.

(I personally have no opinion on Tailwinds except a default negative valence regarding front-end)

pjc50 - 12 hours ago

"Every input is hostile until proven otherwise": you said it yourself. One of those sad things that somebody new learns on the Internet every day.

tennisflyi - 6 hours ago

Never used the actual internet, eh?

tenderfault - 11 hours ago

Look. It works. I just spent 5 minutes reading the messages posted on your glorious chat app. If I'd be you, i'd plant an ad just above it. Why are you complaining.

dabinat - 12 hours ago

This sounds like the kind of feature that ends up being quick to initially implement but takes up way more engineering time to maintain than everything else combined. The author concedes at the end that most genuine uses of the feature are people just saying hello. So maybe the solution here is to disallow unrestricted input and just have a few buttons with fixed things to say.

maCDzP - 11 hours ago

If the chat is saved as an example of how lot to talk. Can that be used for training an LLM on how to talk or what to remove from a chat?

Deukhoofd - 13 hours ago

I'll have to be honest here man, yeah no shit. I can't think of any good reason of why you would add something like this. A standard comment section is typically bad enough, and at least you're able to moderate that. An anonymous real-time chat embedded within your own blog? That's just asking for issues.

thataccount - 12 hours ago

The social web has become the adversarial web, unfortunately. You have to have a huge squelch knob if you want any meaningful signal now.

axus - 12 hours ago

Next we're going to hear a complaint from Mark Zuckerberg about how people are using Facebook and LLaMa to attack Meta.

Funes- - 11 hours ago

Wait. Is it not against the HN guidelines to regularly submit links to your own sites? Isn't that considered self-promotion and, thus, against the rules? I've got nothing against the author, personally, as I'd do the same, but seeing his submission page, I'd like to know how normal getting in trouble is for this practice or if the guidelines are enforced at all in this sense.

alansaber - 12 hours ago

SLM language filters might actually be a good application of AI? As well as very sparing regex for bad words.

TheBuciyo - 12 hours ago

Humans will really take any chance they can to troll, I would definitely get more moderation

amelius - 12 hours ago

According to dead internet theory, these might just as well be bots.

mmh0000 - 11 hours ago

There is a well-reviewed study on this from 2004 -

Greater Internet Fuckwad Theory[1]

[1] https://www.penny-arcade.com/comic/2004/03/19/green-blackboa...

grapeorangesoda - 12 hours ago

Well, Django sucks for real-time chat

morkalork - 12 hours ago

I was watching porn recently and the particular site I was on had recently added a real time chat widget too! Aside from scam bots trying to lure users off onto telegram, the last few messages were guys talking about Monty Python's The Life of Brian.

busymom0 - 12 hours ago

> The first and most obvious one was a filter of inappropriate words and expressions

I don't think those countermeasures are working because as of this moment, there's plenty of obvious naughty words being passed through in that chat window.

homeonthemtn - 12 hours ago

What if he filled the chat with bots and is using all of this as stealth marketing?

jdw64 - 12 hours ago

The homepage design is nice, and I think anonymous chat is fun too. Even though the programming topic probably has a pretty clear target audience, I'm surprised that kind of hateful chat still shows up.

Locketgoma - 11 hours ago

real-time chat is....... oh that is likely Live streaming channel. (but 's not have Chat Manager) :facepalm:

elendilm - 12 hours ago

The attempt to run Javascript as the author mentions is pathetic.

latexr - 12 hours ago

> What harm could a box that only broadcasts plain, ephemeral text do to me? You're thinking the same thing I was, I'm not crazy, right?

Not right. As soon as I saw the box (when the other article was posted), my immediate thought was that it was distracting, frankly a bit creepy (even just the counter is so), and obviously ripe for abuse. About one second after I had the thought, I saw it happen in real time.

> The goal, I suppose, was twofold: (…) and to make the article look bad in front of the aggregators and networks where it was being shared.

I think you’re reading too much into it. I bet all (or essentially all) the people doing that don’t care one iota about you or how you look to whatever aggregator and network. They’d write those same things on an empty wall if you gave them a can of paint. You gave them an avenue and they used it, simple as that.

grapeorangesoda - 12 hours ago

lol hate speech (fun speech lbh) drives traffic

nicechianti - 12 hours ago

[dead]

nivertech - 12 hours ago

TL;DR: this is a toy example, so it doesn't require BEAM VM

Hard to take this seriously without the loadtest with the the large number of concurrent users.

For a number of users concurrently reading a long-tail blog post - you will get good results even using DotCom era HTTP polling.

---

See:

Django LiveView vs Phoenix LiveView: a real benchmark

https://en.andros.dev/blog/80134668/django-liveview-vs-phoen...

phoghed - 12 hours ago

So that’s what’s beneath the usual HN tech bro libertarian veneer.

Oh my bad are yall under the impression that HN is not the majority of the traffic right now lmao