Showing posts with label Spam. Show all posts
Showing posts with label Spam. Show all posts

October 20, 2018

Comments as a Platform, Or Silencing the Trolls


Web content has typically divided into three camps - those who create, those who react, and those who just watch. The lurkers, if you will. From the very earliest days of blogging, those first posts awaited the inevitable comments, and, given a clear revenue stream, you would see early participants like Fred Wilson say that "comments are how bloggers get paid."

[Source: https://vanelsas.wordpress.com/2008/06/02/the-real-value-of-social-media-interaction/#comment-2531]

The earliest engagements we had with people who read our site gave us incredible discussions, and spawned more posts and even, in rare cases, changed minds. Sites like Digg, Reddit, Slashdot and others became known for their diverse threads, and those in the comments are why you showed up.

But we've also seen the pendulum swing the other way. Everybody knows to "never read the comments" on popular news sites, as the most aggressive vitriol and ignorance floats to the top. YouTube comments have long been notorious for their lack of quality (though I feel this has improved of late). And Twitter, for many who should be able to use the platform, their every move can attract trolls who have a vendetta to take them down - but somehow don't get banned.

As social media sites eclipsed the momentum of blogs, conversations moved. We adapted by integrating social discussions from FriendFeed, Facebook and Twitter and appended them to our blogs. We would all share our posts on social, and then engage where the content landed. The best bloggers would find their readers wherever they were. But others simply turned comments off. Maybe it is because they were full of spam (they were) or the quality wasn't there (often true), but also, because the total quantity declined.

Let's go back to talking about Twitter. Twitter drives me nuts because it's fantastic and so poor at so many things. They seriously have real-time on lockdown. There is no better place to see what is happening right now. If there's a calamity, search Twitter. A breaking news event? Search Twitter. A sporting event? Twitter.

But Twitter has this awful habit of giving all users an equal voice. Now hear me out what I mean.

If you tweet publicly, anybody who you haven't blocked can reply, and their content is appended to your tweet. It follows you around. If a Republican politician posts, left-leaning posters race to take down their message, while the MAGA crowds prop it up and try to gain eyeballs. If the Kardashians say something, the crowds pounce on the valuable real estate quickly to show their adoration or pimp whatever link they've got going.

And down the publicity food chain, if you're a woman, especially a visible one, you get awful men saying foolish things. I guarantee it. They may call you names or question your ability. You block one and ten more pop up. If you're black, or Jewish, the racists will find you. They all know how to tweet.

So what I recommend above all other Twitter changes is the ability for people to reclaim their space. Hillary and Trump should both be able to post information without the crowd's replies being appended. Just like blogs and YouTube stars can turn comments off, Twitter users should be able to as well. The thing about social networks (and most products, to be honest) is that you should give the users control. But they haven't done it, and I think it delivers a great disservice to the platform, which has become a hotbed of harassment and hate - as Reddit and others have too.

If you can trust your commenters enough to give them a voice, by all means, amplify their voices. But when they have shown you time and again that they cannot be trusted, turn it off.

September 04, 2014

Striving for Streams of Serendipity or Inbox Zero?

Nobody really likes spam - those unrequested commercial emails that join your email box. They interrupt you, distract you, mislead you, or maybe worse - trick you into giving up your money or personal information. And over time, most email services have been pretty good at determining just what is spam, and what's not, while we, as consumers, are getting better at refining just what content we want on all our screens, be it our email box, or our social streams.

With this experience, what we've labeled as spam now not only encompasses the obvious scam message, but practically anything that enters our view that we didn't explicitly ask for, or surprises us. Most of us living in a social media powered world have taken a lot of effort to refine our content sources, to the right sets of blogs, and the right friend groups on social networks. When we log in to Twitter, Facebook, Google+ or anywhere else, we pretty much know what we're going to get.

Many of these social networks, dating back to the first blogs, are sorted chronologically, with the newest content at the top. With some effort, you can quickly scan to where you last left off, and feel complete. There's no more to read, and you can move on to the next thing. It's a permuation of the famed "In Box Zero", which says your task is complete.

But increasingly, thanks to pressure to fill streams of less active users, or to increase engagement from regular users, it's become more commonplace to push content that's not explicitly requested into user streams. This can be "Friend of a Friend" content, like we saw back in early 2008 when FriendFeed first introduced the feature, or more recently, items that your friends on Twitter have retweeted or favorited, that Google+ friends have +1'd or Facebook friends have Liked.


It's assumed the more signals given to the network about what your friends like, the more likely it is that this piece of content is also relevant to you. It's not necessarily wrong, but it's a change, unwelcome to people who like to perfectly curate their streams - while possibly exciting to those who do want to take signals from the network - believing they aren't the one perfect arbiter on whether an item is interesting or not.

In 2008, FriendFeed spoke to this change, saying, "Our goal is to make the most interesting shared items more prominent so your FriendFeed has a higher percentage of interesting stuff and active discussions." And it worked. If I believed +Paul Buchheit had high quality interactions, I could be alerted to items on the stream that he had liked. But FriendFeed also gave me the option to turn it off, and many people did.

In 2014, Twitter is a lot bigger than FriendFeed was six years ago. It's a world-recognized stream for real time communication, so their moves get a lot of attention. Every minor change in the stream is especially scrutinized. After already taking for granted the fact that retweets from friends would be sent to my stream, the occasional tweet now appears, simply because someone I follow added it to their favorites. Unsurprisingly, this experiment, which is easy to spot on their mobile app, set the tech blog debates abuzz again - trying to figure out how it worked, and whether it was good or bad.


It's widely assumed putting content in user streams benefits the service provider. Twitter should see higher engagement, higher relevance and more clicks. For the OCD "In box zero" types, these serendipitous pieces disrupt their worldview, and, unsurprisingly, those who write about tech and social media all day are more likely to be of this type than the general population.

When +Barak Hachamov and I were working on my6sense, we were more than happy to rank social streams based on your activity and implicit interests. The solution, in my view, hasn't seen an equal, even in the three plus years it's been gone from consumer's hands. We offered a stream based on relevance, with your interests playing a huge role, a toggle to view the stream chronologically, and yes, we promised occasional serendipity to deliver surprise - to get you out of a knowledge rut, which can come from seeing the same topics debated and shared by like minded thinkers.

Relevance vs Time in my6sense

What we've learned from the Web is that we tend to gravitate to people who reinforce our own views and agree with us. Debate happens, but we don't actively seek out opinions from those with opposing takes on political, religious or even sports. (I wrote about this in 2006: Blogging Bifurcation - A Web Divided) The Web, despite being especially diverse, leads to us forming cliques, with friends, with what we read, and where we choose to congregate. Our three social pillars are what I called out back in 2009: Technology, Community, Relevancy. Most of us active in social streams have bought into the technology, and crafted our community, assuming the community's thoughts are themselves relevant. And by seeing new content, we immediately question its relevance.

For the 95%+ of people who haven't put hundreds of hours into scanning their streams to never miss a post, and who haven't taken time to set up lists, form circles, or fully understand Facebook sharing settings, the serendipity of surprise is as important as what they've explicitly asked for. While those of us on the tech edges react to the surprise with shock, we should know this is something we give in exchange for participation in somebody else's stream. The only thing I'd ask is that, like FriendFeed, we always have the option to please, kindly, be able to turn something off. Then we'll all be happy.

Standard Disclosures: I work on the Google Analytics team at Google, which provides Google+. Various services from Google partner with or can be assumed to compete with products from Twitter and Facebook. Also, from 2009 to 2011, I had a consulting relationship with my6sense as part of my work with Paladin Advisors Group. Disclosures are fun.

July 23, 2011

Automating Spam Removal Is A Tricky Challenge

Automating the detection and removal of spam accounts, fake profiles and other similar tasks is a tricky one. Assuming you have a 99% detection and response rate, the 1% "false positive" can be a humongous headache. With many people debating the right approach to taking down accounts, flagging spam and the like as this network evolves, check out this great article from the oddly titled "Laughing Meme".

See: Cost of False Positives on Laughing Meme

/via My Google+ Profile.

March 08, 2010

SocialToo Expands Twitter Phishing Protection to All Users

Increased use of Twitter has made the users sharing and clicking on links more attractive to both legitimate businesses and ill intended people looking to steal passwords or guide you to unsavory sites. Seemingly each week there are new stories about phishing attempts that prey on direct messages (DMs) from trusted people, and if compromised, these accounts could lead to more spam, just spreading the mess further. SocialToo, a company led by Jesse Stay, and one where I am an advisor, has opted to take a proactive approach to enable phishing protection for all users, not just those with a premium setup, or those who had manually enabled filters themselves. The result is a much-improved, and safer, Twitter environment.

The move, as outlined in Jesse's post from this morning, means that anybody who has ever created a SocialToo account, even a free one, is protected from receiving direct messages that contain known phishing attempts.

Prior to today's move, SocialToo had already blocked nearly 20,000 malicious messages, just on the 2,000 users who had enabled the feature, an average of about 10 per user. With phishing protection now enabled for 60,000+ accounts, the volume should similarly scale thirty-fold.

Over the time Jesse has been working on SocialToo, there have been multiple instances where his application has publicly noted phishing attempts faster than any official word from Twitter, or the press covering Twitter. Rather than leverage this opportunity to extract money from users, we agreed it made more sense to do the right thing and get these protections out to the much wider audience.

"As has always been a priority, we feel keeping your stream clean and the web in general a cleaner place is important," he writes. "Hopefully this makes a significant change in how clean the streams of Twitter users are."

As an advisor, and as a SocialToo user, I have had phishing protection enabled on my account for quite some time, and the coverage of such attacks almost catches me amused, as I never see the ill-intended direct messages targeting my mail box. In fact, SocialToo tells me more than 140 direct messages to me have already been filtered, automatically.

I believe that using Twitter without having SocialToo enabled would be as silly as running a Windows computer without having antivirus enabled. Even if you won't convert to the premium plans offered by SocialToo, you should set up an account to get your Twitter messages protected.

DISCLOSURE: I am an unpaid advisor to SocialToo. I hold a small equity stake in the company.

December 09, 2009

Fighting Bots With Bots on Twitter, Leveraging SocialToo

Many Twitter users are caught in an odd conundrum - between being open to random connections and being open to a glut of unfocused spam-like bot behavior. While I believe the allure of high follower counts has largely been eroded, thanks due in part to the controversial Suggested User List and growth of spam accounts with high connection numbers, many still see higher "value" in the raw numbers of the network. So how does one maintain an open door policy that allows for two way direct messaging all while keeping one's stream clean? the answer is different for everyone, it seems, but I thought I would share some of the ways I am leveraging SocialToo, a service I advise, to improve my Twitter experience.

When I first started using Twitter, I enabled autofollow by SocialToo, so I could automatically be connected to people, enable two way direct messaging, and not look disconnected. But as junk followers figured this out, my steam became overwhelmed with direct marketers and news repeaters that didn't add to the conversation. So, while avoiding the option to do a mass unfollowing of all (see a post on that from September), I first turned off the autofollow option and have taken subsequent steps to clean up the results.


TwitterCounter Shows the Drop In My Following Counts


First Step: Block all direct messages that are spam or for viral games.

SocialToo lets me block DMs that contain keywords or search strings like "Mafia Wars". I can either block those DMs outright, or have that person be unfollowed.

Second Step: Block all direct messages that are for phishing schemes.

SocialToo, once notified of an ongoing scam, blocks all direct messages that match a specified string for all SocialToo users, myself included. This way, even though I use a Mac instead of Windows, I won't even be tempted to click on a fake URL, because I'll never even see it.

But even then, I still saw a lot of marketing and garbage in my feed. Preferring not to unfollow everybody and make a mess of things, I started to unfollow junk one by one in my stream, separating the bots from the people. That worked, but it doesn't scale to the thousands of folks who might need 1-1 attention this way. But what I did notice was a pattern. The spammers and repeat Tweeters were almost all using automated tools to generate their dreck, usually from "API" or from TwitterFeed.

Third Step: Ask SocialToo to unfollow all Twitterfeed or Blip.fm or API bots.

I reached out to Jesse and asked him if he could enable SocialToo to automatically unfollow the bots in my stream who I identified were using these tools. In the first two days, more than 1,000 bots were cleaned up, and in the last few months, as I've used this unreleased feature, about 3-4,000 followed have evaporated, leaving me with a still large following count, but a much more relevant count.

Yes, there are some legitimate people using Twitterfeed, and so they too got unfollowed, which leads to stage four.

Fourth Step: Add people to my SocialToo whitelist to never unfollow.




Some of the people I automatically unfollowed noticed and let me know. On other occasions, I found it out myself, and thought that was silly, so I just logged into SocialToo and added them to my whitelist which means no matter the tool they use, they will still be connected.

In the few months of reducing the noise on Twitter, I have reduced the people I have been following from almost 15,000 at peak, to just over 10,000 today. I expect that barring my following more groups of people, this week I should drop below 10,000 total and the service will look better and better.

I may advise SocialToo, but I do so for reasons just like this. Sometimes issues I find can lead to real product features. And while Jesse hasn't yet rolled out the option to unfollow based on a specific source, he may in the future, and you'll see real benefit.

Disclosure: I am an unpaid advisor to SocialToo and have a minor percentage equity stake.

September 14, 2009

Automated Tweets Don't Always Mean Less Genuine Tweets

With the introduction of an updated terms of service last week, Twitter once again had people buzzing about what was accepted behavior on the fast-growing microblogging site, and what crossed the line. In one of the site's frequent list-based articles dedicated to the San Francisco company, Mashable claimed one of the targets of the update was what they termed "bots", which were updated by RSS feeds moreso than by humans. In the post, Jennifer Van Grove specifically used the popular IMDB account as an example of one that should "live in fear of death". But all drama aside, I don't think that's Twitter's intent, nor do I believe that the sole delineation of whether an account is pulled by RSS instead of through text, for example, calls for the label of "Spam".

The truth is that a significant number of news-based accounts are clearly automated, very often by the use of RSS, because Twitter has become more than just a place to send updates. It's infrastructure. And even if these accounts aren't automated through RSS, practically all of the top accounts are full of a stream containing only headlines and links, with Mashable being no exception. (See also: TechCrunch, Techmeme Firehose and ReadWriteWeb for example)

It's clear that while "The Twitter Rules" say that "If your updates consist mainly of links, and not personal updates" is one criteria for being labeled spam, it cannot be the only criteria. We must believe, and I do, that Twitter would know how to separate the good from the bad in this type of a case.

The truth is, and I have said this many times, that you should participate and make your data available where your audience may be. And often, even if you are initiating content in one place, the audience may be somewhere else - like Twitter. As a result, it makes sense to move that content to Twitter to give them access.


TwitterCounter Shows Growth for @lgshareditems and @scoblefaves

A recent experiment I kicked off on Wednesday was creating a dedicated Twitter account for my Google Reader shares and Delicious bookmarks at @lgshareditems. This combination has always been available on FriendFeed (and Facebook), but not Twitter. In parallel, Robert Scoble, also a guy well known for trying new things with social networks and data, has been tracking favorite tweets from those he follows with a dedicated account called @scoblefaves.

I have watched both accounts creep past the 100+ follower stage, even though both accounts are new, and both are exclusively feed-based. Each is a new way to try and utilize human filters and pass the results to Twitter, with the difference being that I am betting on content from outside of Twitter, and Robert is betting on other Tweeters. I bet both have strong value to separate audiences looking for news and tech updates - even though our data sets are different.

My shares to @lgshareditems are equally as genuine as my posts to @louisgray. While I may have more personal updates at the @louisgray feed, I do also post my new blog updates there, as well as my Delicious bookmarks, to give those authors additional exposure. And as noted above, practically every self-respecting blog and news source can see their Twitter feed to be extremely link heavy. So I expect it will take a lot more than you seeing a lot of blue underlines in my feed to be in danger of getting the big boot from Twitter, no matter what their TOS says.

September 03, 2009

SocialToo Extends Battle Against Twitter DM Spam With New Feature

SocialToo, a social Web utility aimed at enhancing your experience on Twitter, Facebook and other sites, is well known for its autofollowing capabilities. But with the rise of marketing and spam on some sites, Twitter especially, the noise has gotten out of control for some people - as you have seen a small number unfollow all their connections, in effect rebooting their accounts, and others complain mightily about the noise that has arisen from junk direct messages. With a new feature introduced today, SocialToo has made it very easy to stop those broadcasting junk into your stream with one click.

The new feature extends Twitter's capability of bringing direct messages to your e-mail, and adds options below to let you report the sender as spam, block them, or report them as sending automated direct messages. And unlike competitors, including Topify, it can be done without having to send this specific message to one of their dedicated e-mail addresses.

As an advisor to SocialToo, I often get access to some of the features early, and this enhancement has already paid dividends. Now, instead of just manually deleting the DM, I can click and send the person's annoyance away forever.



One DM via SocialToo I Was Ready to Zap


More than just this utility, SocialToo lets you set up a blacklist of keywords from within the site that you may never want to see in DMs, ever. That means you never have to see updates from Mafia Wars or Spymaster or whatever your least favorite junk spam of the week is. That can be found in your SocialToo account's preference tab here: http://socialtoo.com/twitter

If there is a way to communicate with people, spammers will do their part to find an exploit. SocialToo is trying to be part of the solution and helping to clean up your social networking experience.


Disclosure: I am an advisor to SocialToo

July 22, 2009

Proxifeed Delivers Automated Tweets and Ads Based on Keywords

Whether you think Twitter is about conversation or about broadcasting, there is no doubt many people use it to help distribute links to share with their followers. Marketers, PR people and spammers alike have also found the social network a strong place to congregate, as they track for mentions of their name, their competition or potential buyers. (See also Travis Murdock's Marketing In the Feed post)

Proxifeed, a new tool released by Stéphane Osmont, who you might remember from his work on YokWay, automates much of the process, creating a Twitter feed built on links related to keywords you feed, including some for revenue - should you be interested.


The Proxifeed Process: A Proxy For Human Input

Upon logging into Proxifeed with your Twitter credentials, the service asks you to provide some keywords for automated postings. The more specific the keywords, the more unique your content could be. You also have the option to present three types of feeds: Content only, advertising, or a mix. You can also add one or more RSS feeds to the mix, be they blogs or from any source.

To complete the feed, choose an update frequency, and Proxifeed will then do the work on the back end to keep your automated Twitter feed going around the clock, whether you publish once an hour or less often.


Three Potential Twitter Feeds From Me Based On My Keyword Choices

Curious what would happen if I turned over my Twitter posting to a machine filled with keywords, I tested Proxifeed with technology terms and sports terms, to see what would happen. Not surprisingly, Proxifeed searched through its bank of RSS feeds and selected specific items to go along my natural activity. By putting in the keyword "Facebook", I had an ad for a dress with the name Facebook. By putting in "Oakland A's", I got an Oakland A's lollipop.


Proxifeed Would Offer My Followers This Lollipop


Proxifeed Also Found a Facebook Dress for Sale

Proxifeed says its offering can create "exciting and engaging" Twitter streams that will get people with similar interests to follow and make your "follower base grow", so I can see how this might be enticing to a spray and pray marketer, or somebody who opts to turn off ads and then becomes a master aggregator on a specific topic. But for people who want to remain personal on Twitter, the most likely option would be to possibly use Proxifeed instead of TwitterFeed to distribute blog posts automatically. Otherwise, the clear non-authenticity of the updates and implied personal endorsement would be quickly exposed.

If you think creating an automated Twitter feed based on keywords and a few RSS feeds is right for you, Proxifeed absolutely fits the bill. But if you want your Twitter to be updated by a human (hopefully you), you can pass.

July 10, 2009

Real-time Search: What's Most Important Now, Not Most Accurate

This afternoon, at TechCrunch's Real-Time Crunchup event, representatives from many of the innovators in the real-time search space had a quick round table aimed at furthering the discussion, framed by a question by moderator Erick Schonfeld, who said that some on the panel may believe real-time search is defined by Twitter Search, while others believe it is "everything on the Internet, but with a freshness or recency component". And while many different companies, including the standard-bearers, like Google and Microsoft, are looking to take on this new challenge, how they are doing it differs greatly.

Danny Sullivan, author of Search Engine Land, said, "We need better definitions of what it is, so as consumers and users, we understand what we are interacting with. Through Twitter and a few other services, you have the option to publish in a few seconds. Maybe you call it social sharing search." (He also posted a summary of the players last night)

Some of the participants could be defined by how large a percentage of their data was initiated through Twitter, and how they worked with the data, including filtering.

"I would define it as what are people saying in real time about my topic," said Gerry Campbell of Collecta. "It's not what is most important, but it's what is in real time now."

This bifurcation of the "one right answer", often championed by the existing search leaders, versus what's most right "now" is helping to separate the old school search engines from this new breed. But don't think that the more-established companies are taking this lying down.

Google's Matt Cutts, who has been at the company since 2000, said "we have always talked about freshness of content." He relayed a history of his time at Google, saying they once had a "war room" of how they could refresh their search index as frequently as a month. By 2003, the company had moved from monthly updates to daily updates, and a few years later, in 2007, integrated the company's Blog Search product into its main search results. "We have rearchitected our system to be as recent as possible," Cutts said.

As updates flow in at an ever-increasing pace from all corners of the Web, search engines have the daunting task of getting accurate responses out there, while ignoring off-topic or harmful data, such as spam. And those who manage to get the formula right will have a serious leg up over those who don't filter well, making their results more noise than signal.

"Drinking from the firehose is a ticking time bomb," said Kimbal Musk of OneRiot. "Even by filtering 90 percent of what is going on with the Iran election, you're still only going to get a tiny slice, and a good portion of that is spam. If you don't filter content, you are going to get more and more spam." He later added, "If you stick to Twitter alone, you will have a spam-filled and biased data set."

With Twitter's API getting to a point where more and more companies are relying on it as their engine and data source, each is working of a common data set, and how they interact with the information will make the difference. And yes, Microsoft or Google may give you one result that is most accurate, but not for this moment, and not with any kind of impact from your friends or in terms of how that data is being interacted with in real time.

Sean Stutcher of Microsoft clearly stated this information is becoming more relevant, saying, "The sentiment around a link could be changing, and that might become very relevant to a user."

In an isolated search world, where an index is an index and the right answer is the right answer, that might not matter. But in real-time, it could matter immensely. As each of these companies works through their user interfaces, their data sets, and improves filters and social aspects, it should be very interesting to see how they separate from the pack and help define their goal.

May 18, 2009

Alright, When I Say Go, Hit the Spam Twitter Button With All Accounts

When a product becomes ubiquitous, it means you get the good with the bad, the well-meaning with the nefarious, the intellectual with the sloppy. As we saw with e-mail being overtaken with aggressive marketers, spam and eventually, viruses, the same activity has propogated to every social network with momentum - including the 419 scam on Facebook we discussed in January, and the many different reports of spam on Twitter. (See: TechCrunch's coverage of similar nonsense earlier today: A Bunch Of Hot Spammers Had The Day Off Of Work LOL.)

Like any good egotist, I regularly check references back to the site, be they on Google, in my referral stats, and the two T's - Technorati and Twitter. Today, I was amused to find that simultaneously, nearly two dozen different accounts referenced an article this I wrote this last weekend. Never mind that their link didn't work. Never mind that they all used the same exact way to write it, including the exact same description or tags. Even more interesting was the fact that all of the accounts (be they robots or real people) used the exact same Twitter client, HootSuite, and the automated messages look like they were executed in alphabetical order, starting with the account labeled "18tweets" and finishing with "Tweetingale".


The last time we talked about Twitter spam, it was with the issue of repeated following. In that example, theories suggested the repeated followers were to gain visibility and more real followers from duped Twitter accounts. So what are the purposes of this type of nonsense this time? Is it thought that those people searching for these keywords would find these accounts and sign up? It's not as if they pushed any traffic to my story, thanks to their not providing HTTP code.

Yet another "stupid human trick" executed on an increasingly sketchy network.

April 22, 2009

Google Reader Limits Your RSS Article Spam Potential

As Google Reader is my main jumping off point to gather all the news of the day, it's no secret the RSS reader also plays a major role in how I help distribute the news, be it through hitting share to add items to my link blog, or by e-mailing articles out to others. In October I mentioned how e-mailing RSS pieces can help to evangelize the service, and I've continued to make it something I do, for friends or for colleagues. But of late, I've found more restrictions being added that make it seem people have maliciously mass distributed articles out of Reader, so more safeguards have been added to slow me down.


Captcha me if you can

The first and most noticeable addition is that of a captcha, which requires you to fill it out each time you e-mail an article out of Google Reader. The minor annoyance didn't use to be there until recently, and presents the opportunity to test how well you read words that are slanted and blurred every which way.


Thou shalt not e-mail your entire address book this article

The second addition, which I just ran into today, is a cap to the number of people you can send an article to. While at the office it's no rarity to forward news to a dozen or more people, Google Reader now stops you once you pass ten recipients. This means that I will have to be more selective for whom I choose to send updates, and just maybe those left off will feel left out.

Having said limits in Google Reader won't dramatically change the way I use the service, with the exception of being more picky about my recipient lists, but I have to wonder who was violating protocol so much that this became a necessity. What robots do you think were mass e-mailing articles to all of their cyber buddies?

March 07, 2009

The Newest Annoyance on Twitter: Follow and Refollow Spam

Unless you've turned off notifications when users follow you on Twitter, you are no doubt used to the e-mail messages you get when somebody has opted into seeing your updates. Follower updates are a staple of social services - and if you are maniacal about keeping e-mail like I am, you can start to see trends on the data, including when people are oddly manipulating the system, in a way that's not normal. And for whatever reason, a small number of Twitter accounts look like they regularly follow me multiple times a day.

I use auto-follow capabilities from SocialToo, letting me automatically opt in to see followers' updates. The way I use Twitter means there is little downside to having new incremental users in my feeds. So, in theory, if the user follows me just once - it's one and done. And I just don't see too much benefit to these new follow and refollow bots, even if I try to get creative.

Take a look at two examples: @PoliticalUpdate and @twtr.us.

Twice a day, starting on February 27th, I have been followed by @twtr.us, the first time at 3:56 a.m. my time, and a second time, at 5 p.m. that same day. Every day.


Also starting on February 27th, the account @PoliticalUpdate has been following twice a day - at 2:34 a.m. my time, and a second time after 11:35 a.m. (only nine hours later). Again, every single day.


So what is the benefit of such a clearly robotic practice? Is the idea that the follow notifications are a form of advertising, giving me a chance to see their name more than once, and increasing the times I'll go to check out their Twitter page? Do they also think we're naive enough to not notice?

Whatever product it is that both @PoliticalUpdate and @twtr.us are using does not contribute to the community in any way, and should be turned off. There is some good news, I guess, in that the twtr.us account looks to have been suspended, but my bet is that there are more accounts out there using the same service, and it should be stopped.

Know any other accounts who are using follow and refollow spam? Let me know in the comments. Jesse Stay, who runs SocialToo, and I would absolutely be interested in keeping them out of your in box.

(Also: See an earlier discussion on FriendFeed)

January 24, 2009

419 Scammers Set Up Roost on Facebook

The art of the largely Nigerian-based '419' e-mail scam is a unique one, but a familiar one. Anybody who has had an active e-mail account for any amount of time has seen the heartfelt pleas for assistance and funding to help safeguard huge amounts of assets that need to be moved, allegedly due to a stressful situation, be it a political coup, a horrific accident or simply death, followed by inheritance. The scams themselves have migrated from snail mail to fax machines, e-mail, and most recently Facebook, as noted by Network World back in November.

Yesterday, I got a note from a Stella Moroba via Facebook. Stella and I are not friends, so far as I can tell, which makes sense, as I doubt she is connected to anyone at all. Stella, in the most ardent way she knew how, told me she has access to "the sum of Two million Five hundred thousand United State Dollars", which I could gain a portion of on two conditions: that I "serve as a guardian to me and then assist me transfer the money into your bank account" and second, "make arrangement for me to come over to your country to further my education and then settle there parmanently". (sic)


Unfortunately for Stella, what with working full time, twins and all this online nonsense, I don't have too many cycles to pass her way to ensure her financal and personal freedom. But I did have a few, so I did a quick search on Facebook and found 214 different results for Stella Moroba, including the occasional Moroba Stella. Unsurprisingly, none of the handful I checked out had any friends, or even bothered to put up a profile picture. So disappointing!


Facebook has taken aggressive measures to ban members who violate the network's terms of service. Seemingly every day we hear about new people who believe they have been unnecessarily booted - and we covered one of those issues last summer. Before any unsuspecting victims rise from Ms. Moraba and her clones, don't you think Facebook would notice the creation of more than 200 identical accounts, and the inevitable onslaught of spam within the system? I certainly didn't accept Ms. Moroba as a friend, and don't believe she should be sending me messages. Isn't that the purpose of friending in Facebook, so you can avoid getting messages from people you don't really know?

If you are interested in helping Ms. Moroba and her family with their strife, e-mail me. I can hook you up. Even if Facebook does eventually delete her account, she helpfully provided her e-mail address and phone number.

January 11, 2009

SocialToo Helps Prevent You From Auto-Following Spammers


DISCLOSURE: I am an advisor to SocialToo. (Background Here)
The debate of whether you should automatically follow Twitter accounts that follow your updates is one that has no single answer. In fact, this weekend saw a pair of posts with opposing views on the matter. The first, from CNET, said auto-following was the way to go. The second, from Techwag, said it was in fact, the wrong idea. One of Dan Morrill's major reasons to "NOT follow everyone", as he put it, was the high amount of Twitter spam on the service, as he encountered examples of people who followed him but had later been suspended.

There's no question that Twitter spammers have caught on to the auto-follow game. When I first signed up for SocialToo and started to get daily e-mails dictating how many new followers I had, and how many followers I had lost in a single day, I noticed names in both lists in just about every single e-mail. On December 23rd, I posted to Twitter: "SocialToo shows that more than 1/2 of my Twitter unfollows each day are from those who followed on the same day, hoping to be auto-followed."

The ensuing discussion, which involved Jesse Stay, the author of SocialToo, led to a new feature he rolled out last night - letting SocialToo users automatically filter who they auto-follow. (See: Fight Twitter Spam With Unfollow Filters) The new wrinkle to the "all in" or "all out" strategy essentially says if a user unfollows you in a set number of days which you specify, you'll unfollow them as well. Does it sound like too much of a niche? Well, it's not. Now, any would-be spammer who follows me and unfollows in the next two days goes away. I'll never see their tweets (assuming I actually used the regular Twitter interface, which I don't), and they won't show up in my "following" list - which is more important.


Speaking of synching up your followers and who you follow, which I did on my Twitter stream last night, SocialToo also quietly added a feature that lets you go back and follow every single person who is following you now, for just five bucks. So if you've somehow ended up with a lot more people following you than you're watching, SocialToo has a quick solution that won't have you going one by one in Twitter and clicking. So, check that out as well, especially if your follower count is up and to the right, like many people of late.

We may not all agree on whether you should be following all who pass through your feed, but I'm sure we all agree we shouldn't be following spammers. SocialToo's approach is a good start, until Twitter can remove all the evil-doers from the database.

January 04, 2009

Twitter's OAuth Target Slipping Amid Increased Security Pressures

Over the weekend, more than one exploit, sent by way of Twitter's Direct Message feature, has made it around the Web. As Twitter's growth has continued, the microblogging service looks to be a new domain for scammers and spammers, previously contained to traditional e-mail. And as the shenanigans gain in momentum, so too does the call for Twitter to implement OAuth, the open protocol that allows for secure API authorization, which has become popular among many Web tools in use today. But Twitter employees' postings in the service's development group, and their own notifications on the site, show a shifting roadmap, while they also try to divert criticsm by separating the need for OAuth from the weekend's incidents.


An example of one Twitter phishing attempt.

Twitter's success has seen a groundswell of applications being developed that require users to enter their user name and password on third party sites. Given Twitter's lack of OAuth support, Twitter users have grown used to posting their data whenever they are asked, and in the rare case a site has been found to malicious, it forces them to once again change their passwords to protect their account.

The OAuth Web site spells out the reason behind the project's development, saying: "If you're storing protected data on your users' behalf, they shouldn't be spreading their passwords around the web to get access to it."

The weekend's activity featured a mock Twitter login page, where users were prompted to enter their credentials. (See: CNet: Twitter phishing scam may be spreading) While this specific attack would not have been solved by OAuth, but instead by users simply paying attention to where they were logging in, you can see Twitter's attitude on the current process.

Alex Payne, a lead developer of Twitter told one user on Saturday: "Right now, you can't see which apps are using your requests. You can change your password, though.", and later told another user, "We're trying to discourage against clicking on the link." Pretty basic stuff.

When pressed on whether Twitter was going to implement OAuth, and reduce users' growing too comfortable with posting their passwords everywhere, Alex said, "OAuth isn't a panacea against phishing and other web security issues. We're still going to support it," and following on, echoed the OAuth site by saying, "A main benefit is that OAuth limits the scope of activities that can be done with a user's credentials," while also linking to a post from April of 2008 that showed how phishing scams could not be stopped by OAuth. See: Phishing Fools?

So, we get that the phishing problem won't get solved through adding OAuth, but we do see more and more applications getting your password. As the New Year came in, Twply managed to get many passwords, and then was sold the same day. (See: Scobleizer: Twitter spam, effective or idiotic?)

Alex mentioned Twitter is going to support OAuth. But when?

In the Twitter Development Talk forum, you can see the target continues to move.
Alex, on November 24th of last year, wrote: "We're currently waiting on our User Experience team to put the final touches on a BETA release of our OAuth support. It's going to have bugs, to be sure, but we should have it out there soon. "
On November 26th, after being pressed for a date, he said, "As I don't know the entire schedule of our UX team, I can't. I would say less than a month and closer to a week by far, but please don't hold me to that."
On December 8th, Alex gave more specific timing: "It won't be available for testing this week, but should be available before the end of the month. I'd definitely encourage you not to launch on it, though, as it will be a beta."
Now more than a month from the first comment, amidst more developer pressure, Alex says the next major version of the API will be OAuth-only, but deflects some of the criticism by pointing fingers at other services that have not yet jumped on the OAuth bandwagon.

This afternoon, January 4th, Alex said:
"Of course, once we offer OAuth, it would be nice to see the same community pressure that's been applied to us put towards companies like Amazon. The Amazon.com iPhone app collects my username and password, and that account is actually tied to my credit card information. Where are the blog posts about their anti-patterns?"
Now, there's no question I'm no security expert. Don't forget that on November 12th, I once wrote, Twitterank Can Have My Password, No Questions Asked, and Alex looks to be feeling the strain of other non-experts, like me, pushing the team to get more robust. He commented on Twitter this evening, "It doesn't help that web folks generally have next to zero security/crypto education," a bucket I'm no doubt in.

The groundswell of demand on Twitter to improve its security measures, to get to OAuth as quickly as possible has no doubt reached a crescendo in the wake of this week's exploits - both those solvable by the project and those that are merely phishing scams. But it looks like Twitter developers' confidence has been shaken by so many promises being out there, and the deadline continuing to move.

December 04, 2008

Disqus Gets Serious About Growing Comment Spam Problem

In the months I've had Disqus installed as the comments engine to my blog, I've been lucky enough to see some great engagement with readers of the site. The centralization and tracking of my comments around the Web, in addition to managing my comments in one place, and via e-mail have been a big help also, as has the service's extensibility and tracking via sites like BackType and FriendFeed. But one of the downsides of Disqus' popularity is that it has grown a bigger target for comment spammers aiming to shill for their prescription drug of choice, and all too frequently offering up ridiculous items, like gold for the game World of Warcraft. But as of tonight, Disqus has rolled out some new spam moderation functions that let you help fight the spam battle and, hopefully, reduce the amount of spam going forward.

In July, I suffered my first Disqus comment spam attack. Though it remains the largest flare-up to date, hundreds of spam messages have flowed into my mail box through the blog. Every morning, and at various points during the day, I'm faced with the routine of hitting reply to each e-mail and saying "Delete", to get the offensive gunk off my blog. I'd rather do that than leave the automated barnacles hanging on my posts, but the situation hasn't been getting better of late.


My Archive of Removed Messages Is Expanding

In addition to the 40 real comments I got on the blog today, I also got about 10 fakes - with about three or so a day in recent weeks. The topics themselves don't vary, but the names do.


Disqus Asks for Us to Help Them Fight Spam

Now, according to the Disqus blog, I can reply back to assumed spam with the simple one word command of "Spam", adding to the service's knowledge and helping them form a blacklist. You can also go into the admin section of your Disqus site and block the comments as spam there.

The war between Web services, e-mail, comments and spammers will never be over, I am afraid, but at this point, the move is yours, spammers. Disqus isn't taking this fight lying down. The service also promises some new features coming soon, including a new interface and internationalization.

November 07, 2007

Sending Me Spam Makes Us Friends, Right?

I don't mind the occasional note from someone I don't know (or know well) asking me to be friends on Facebook, or to connect on LinkedIn. Over time, I've gotten used to people wanting to pad their network stats through finding my e-mail and expecting us to act as if we're the best of character references. After all, with the value of what a "friend" means online going down seemingly by the day, after a while we'll have to find a new name for the "real world" version, and I don't think "BFF" is going to be it.

But now, new social networking sites, or even warmed-over old ones, are starting to fill my e-mail with absolute junk, under the guise of "real world" friends reaching out and begging me to share our similarities - to compare books I like with their own preferences, exchange favorite movie listings, or see if we've traveled to the same countries. In fact, in some cases, these little features or would-be Facebook apps are sometimes masquerading as full networks on their own, when that guise is frivolous.

The first is Plaxo Pulse - who jumped on Google's Open Social bandwagon last week to gain membership in the "Everybody Except Facebook" club. Since the network's roll-out, I've gotten dozen of Plaxo Pulse invites that have me begging to hit "Return to Sender", if only e-mail worked that way. In my opinion, LinkedIn won the business networking challenge years ago, and Plaxo never got past its spammy beginnings, so we're not going to be making that move any time soon.

Now, even more mind-numbingly, I'm starting to get alerts from people joining Shelfari, hoping I can share book rating and reviews, or even join book clubs. News to all who sent me those invites today - no frickin' way. If I wanted to join a group of folks to review books, I'd already be doing it on Amazon.com. Even worse, it looks like the service isn't wired well enough to tell the difference between a small invite list and spamming the planet. As one person wrote me, when I declined his invitation to Shelfari, "This was really embarrassing. I accidentally sent this one to everyone in my address book!"

With so many social networks out there now, it's become a full-time job for some just to keep current, let alone adding more and more services as they debut. Hence the rise of services like FriendFeed and Spokeo. But each of these social networks are chasing a finite number of heavy Internet users, and there's no question you'll see invite fatigue and eventual saturation. Barring the impossible, I've made my preferred selections, and I'm done. So if you really want to be my friend, stop spamming me. If you want to compare books or movie preferences, pick up the telephone and call. My number's on the top right of the blog.

August 25, 2007

eBay Locks Me Out for My Own Good

I must receive dozens of fake phishing scam e-mails a week, from spammers who think I'm dumb enough to log in to their fraudulent Web sites to enter my login and password, whether for eBay or PayPal, Amazon or Wells Fargo. I even get junk e-mail asking me to update my information for banks I've never had anything to do with, including Bank of America, Washington Mutual, and others. That's why when I received a note from eBay on July 31st saying my account had been compromised and locked down, I deleted it. Obviously spam.

So last night, I tried to log in to eBay and it didn't work. And it wasn't an issue with my memory. I've used the same login/password combination on eBay since 1998, and I was sure I had it right.

I hit the "Forgot Password" button, and eBay asked me to get two of three things right, my mother's maiden name, my zipcode, and my primary phone number. Sounds easy, right? Wrong. Mother's maiden name I got right away, but if you keep in mind I registered my eBay account almost 10 years ago, I've moved a few times since, from my shared apartment in Berkeley to Belmont, Palo Alto and now, here in Sunnyvale. So I had to try a few zip code combinations, not to mention phone numbers. Those changed too.

Eventually, I figured it out, and luckily, the e-mail I had on file at eBay was current, or that would be yet another mess. Now back in eBay, I had a note that said "It appears the password for your eBay account may have recently become compromised. As a result of this, we have reset your password and secret question." That's why I had been locked out. But I didn't see any odd bidding, so I have no idea what triggered the issue.

Now, I have a new password. And now, unfortunately, this just may make me look at the phishing e-mail scams as if they might actually be real, and that's not an improvement. Although I have the utmost respect for Web leaders like eBay, Paypal and Amazon, I have to imagine the fraud business dramatically impacts their ability to do e-mail marketing and customer service, and that must be incredibly frustrating.

July 12, 2007

Time for a BlogRoll Revamp

A couple weeks ago, when Kent Newsome and I had a public disagreement over his gaming Technorati, Kent had some observations on my blog, which he saw as typical pandering to A-Listers. Just like I hadn't polled his intentions for engaging in viral link tagging, he didn't poll me on the origins of the BlogRoll I've run with for the better part of a year. He thinks I was off with my comments, and I know he was off on his, but it's got me thinking it's time for some changes.

Somewhere in late 2005 / early 2006 timeframe, I somehow stumbled on the wonders of Technorati and the A-list. It seemed like everywhere I turned, there were more and more blogs focused on Web 2.0 and capturing the live conversations that have redefined media, news dissemination and how we communicate. Robert Scoble's blog led to TechCrunch, which led to Om Malik, Steve Rubel and so on... Within a few days, I'd stumbled on everything from ValleyWag to TechMeme, and rediscovered both Dave Winer and Guy Kawasaki. I felt as if I'd opened up a vault of information previously hidden and it was all I could do to leave the laptop to function offline, rather than take in this new world like a sponge, 24/7.

As the blog is a personal blog, first and foremost, I linked to those I found most interesting, but in retrospect, it's a lot like how in Web 1.0, so many homepages would have links to Yahoo!, ESPN and CNN, as if the casual Web surfer wouldn't know how to get there. Now, as all these A-Listers are as commonly visited as the old media kingpins, my links there are just as useless and redundant. The same goes for the Politics links as well, especially as I've moved away from Politics here for the most part. Though Kent saw the A-List links as pandering, that wasn't the original intent, but now, it's easy to see how that could be implied.

As a result, thanks to Kent's promptings and my own consideration, I'm getting rid of the A-List blogs that don't belong, and in their place, I aim to add those blogs which most closely mirror my interests and those I consider my closest peers - not necessarily in size or popularity, per se, but in consistency, focus and approach. And of course, I'm willing to listen to any feedback you have on what I'm still lacking.

Therefore, some big names are going to get cut. Sorry, guys.

But not every one is getting the axe.


And what you've been waiting for, of course...


I have also opted to replace the Politics section with a more generic "Resources" box that includes sites like Mashable, Read/Write Web, TechMeme, and Robert Scoble's shared link blog. Though I was at first skeptical that Robert's surfing would be fun to watch, his shared link blog has introduced me to many a blogger who has a story to tell.

On the Web, nothing is in stone, so even this revamp may not be long-lasting. I will continue to add and cut, as I see fit, but I'm glad this change has been made. Comments always welcome.

July 01, 2007

Is There an Antidote to the Link Tags Virus?

After Thursday's comments on how a few misguided individuals have tried to finagle better Google PageRank showings and higher Technorati Authority through the promotion of viral link tag spam, there has been some discussion in the blogosphere on the practice, and whether it's as bad a move as I made it out to be. One of the biggest outstanding questions is if there is indeed a loophole in how popular search engines rate authority and influence, is the onus on the individual not to exploit it, or instead on the technology provider to make a change?

While Kent Newsome, a great blogger with strong observations on a near daily basis (See: From Creation to Abandonment: the 5 Stages of Blogging for a great example) seemed to take the brunt of my comments, the issue is more than one individual, as there are many people trying to scream loud enough to be heard in a blogosphere that may favor the strong over the weak. While Chip Camden amusingly said that Kent was playing "Robin Hood" to my "Sheriff of Technorati", I've seen others who considered getting in on the viral links scheme reconsider the practice when they realized it could have some long-lasting, impactful, negative results. Kent's Robin Hood may have been trying to rob the rich to feed the poor, but at least in that storied tale, Robin Hood distributes the loot to others, something Kent can't do while his own Technorati Authority skyrockets.

Earl Moore, who also participated in the viral links scheme, writes:

"If it’s a fraud, then it’s one I’ve participated in as well... I’ll admit for myself that I don’t feel one hundred percent positive about “Viral Tag” links. Going with my gut, I wouldn’t post another one and am even considering pulling the post I have (yes, after the horse has already left the barn)."

Another poster, on a blog called Planet Apex, who just this Friday had opted to join in on the viral tags exchange, quickly realized the error of his ways, writing:

"I have decided to pull out of the Viral-Tags link exchange scheme. I did not realise the risks involve when I joined it. I now understand that instead of increasing your PageRank it can actually decrease it or even get you banned on Google."

Google's power on referring traffic cannot be understated. As much fun as it is to gain the occasional reciprocal links from fellow bloggers, upstream, sidestream or downstream, Google drives anywhere from 50 to 90 percent of all traffic for most sites, making it true that It’s Google’s Way or The Highway, as Garry Conn wrote this week, when he said, "I have made a major mistake. And I don’t want you to do the same thing."

Basically, Google's guidelines specifically prohibit statistical cheating like viral link tags. Google's Webmaster Guidelines state:

"Don’t participate in link schemes designed to increase your site’s ranking or PageRank. In particular, avoid links to web spammers or “bad neighborhoods” on the web, as your own ranking may be affected adversely by those links.

So, it's not so much as Kent says when he wrote on Warner Crocker's site that "The blogosphere is like Deadwood and (Louis) is trying to paint it as Miletus." This isn't the Wild West, even though it's certainly no utopia either. There are guidelines written up by some powerful technology companies that have direct impact on how our content is indexed, searched and presented, and as bloggers who work under this scenario, we should have an eye on what are good links versus bad links, good practices and bad.

Some last notes on viral links and search engine optimization come in the comments of an excellent "Search Engine Optimization Do’s and Don’ts" post at Thought Sparks. I'll let them speak for themselves:

"Plain and simple, honesty and integrity always pays. Short-cuts will not have lasting value and many of these folks will someday soon have a rude awakening. They will also frustrate themselves with the volume of time they’ve spent on futility... And even if you are successful, does one achieve that end at the cost of personal integrity?"

It may be one thing to exchange links. It's quite another to exchange integrity for scheming. Rather than making this a personal issue between those who have sinned and those who have not, we should just eliminate the practice and ask Technorati and Google to clean up the mess.