CAPTCHAs and sign‑up quizzes annoy real people and barely slow down determined bots. As the fediverse grows, we need smarter, more humane defences, ones that don’t push away genuine newcomers. What creative, non‑intrusive ideas do you have? Trust‑based vouching, proof‑of‑humanity protocols, behavioural signals… what feels both effective and aligned with the open social web? I’m building a social media platform and I’d love to hear your thoughts on this topic.
This is just the thing an AI bot would ask, to try and better prepare how to be a human pretending AI bot :-p
I’ve already built the fediseer btw
It’s pretty much impossible IMO. You cannot possibly fortify every single instance against bots, there will always be ways around it. It’s just something that the open internet will have to deal with unfortunately.
They could also make an instance of their own and so it’s all useless
You could try Anubis? From what I’ve heard it works well against bots - but if not implemented properly can also block “good scrapers” like search engines and the internet archive that increase discoverability
Does not work well against propaganda bots, as those don’t mind wasting time on the CPU cycles. And propaganda bots are the ones we should fear the most on the fediverse.
https://xkcd.com/810/ was intended as a joke, but there is a kernel of truth to those thoughts…
While that would be cool, I don’t see how it would function as a CAPTCHA.
https://github.com/anomalyco/polaris does not exist. Is the url wrong?
They should publish their “23 nd Me” results or at least prove which parent they loved more. /s
It’d be nice to see public libraries take over this sort of thing. They can do community-based physical verification, without cost. They can assert that someone is legit, without revealing any private info. They’d have to be low-drama, boring infrastructure, in that they merely assert “This person is real”, without getting into “This person is good”.
It’s not sexy like a new protocol or blockchain or whatever, but IMO it’s one of the few ways to really handle the problem, and also is a good way to help build local community.
That’s a step away from showing ID. It’s not okay because your local (government owned) library does it. Even wirhout much info, it still becomes easier to dox if you have the person’s location.
It would also be insanely complicated. How many libraries would need to be contacted and taught how to use some kind of software for this. It would be a mess.
becomes easier to dox if you have the person’s location
Yeah, I guess “take over” is too strong vs “provide the option of”. It shouldn’t be the only way, but would be one very good option. They don’t need to actually keep any records of who they gave an account to, and can take steps to obfuscate any privacy-violating processes. Historically, they’ve been very amenable to this, such as not handing over records about who checked out books.
How many libraries
That’d be a great thing IMO. More skills like that should be distributed and federated. Libraries should be community centers of learning, including learning how to run servers. Information isn’t just books anymore, and libraries need to adapt.
They would have to do so without keeping records of anyone, which might be difficult. Otherwise, this could be subpoenaed by an authoritarian government.
Any verification system must be created with that in mind, these days.
It would be doable, and libraries have been amenable to this sort of thing, like not handing over records about checking out books. This is even easier than checking out books, since you don’t actually need to record who is attached to the account. Libraries could obfuscate information that could lead to invasion of privacy. And because it’s distributed and local, it’s much harder to abuse. If someone tried creating 100 accounts, the librarians would start remembering them and refusing to give them more. Going around to 100 libraries would also be much harder than spamming a new account page on some website.
There probably is no magic solution: I would focus on making abuse expensive instead of making honest users miserable. Gradual trust, optional vouching, sensible rate limits, reputation, and behavioral signals together will outperform almost any CAPTCHA while keeping the door open for real newcomers.
I created a honeypot that creates a link only bots would think is a link. Then it gives them random words with another link. If they click the link 3 times they get ip banned by fail2ban. Works wonders! I can see my logs and the difference it made.
I also have bots.txt that only the big players care about like google.
I’ve seen a few Discord servers I’m on use some bot that creates a honeypot channel. It immediately bans actions that posts in it. It’s so low tech that it perfectly handled the weird problem of people getting their account taken and posting spam in every channel. I can’t help but wonder if honeypots could appeal to the “loose with rules” nature of modern LLMs/AI tools.
Sometimes low tech is the best solution. Thats a good idea :)
Most bots are not sophisticated. If they were…they would just get a human being to do it. The whole point is to do something repetitive easy again and again.
liberal blocking and not worrying about not interacting with every single one of the 8 billion people on the planet.
It’s old school and expensive compared to what the social media companies use, but there is actually a way to verify they are human without requiring invasive facial scans or uploading your driver’s license to an insecure server. It’s a way to verify with near certainty that someone is human, without requiring them to upload any personal information whatsoever.
Really, this problem was solved a very long time ago. It’s a called a public notary. Traditionally these are used to certify signatures on important paperwork, but notaries could easily serve as a certified human checker.
Let people request or apply for a verified account. Have a system produce a form that lists the user’s screen name, lemmy instance, and the contact details and licensure of the notary. Have a place for the notary’s contact info, but nothing about the account owner’s contact info. The form will state something like, “I,___, licensed notary in the state of ____, observed the owner of this account successfully log in to the account listed on this form.” You could prevent spoofing by requesting that the account owner, while in front of the notary, log into an account, and post a verification code on some thread. Then the notary could confirm that posting through the notary’s own device.
The exact procedure could be tweaked, but the basic idea is to use public notaries (or whatever the local equivalent is) to verify that an account is owned by a human. Now, there wouldn’t actually be anything physically stopping someone from certifying any number of accounts this way. But this is where the hassle factor of in-person verification actually benefits us. Notaries are relatively cheap, but not free. They usually charge around $20 where I’m at. People pay that much for Twitter verification, why not a one-time notary fee? But while the fee is relatively modest, it breaks spammers. Accounts are no longer disposable. They’re pseudo-anonymous, but not disposable.
Online accounts are increasingly necessary to just live in society. And the rise of LLMs means that telling a human from a bot based just on their online behavior is a fool’s errand. And other methods such as uploading IDs and facial scans are privacy nightmares, vulnerable to spoofing, and often biased against minority groups.
Ideally this would be done on a larger scale than just one site. You could have some sort of third party service that just served as a repository for notary-validated human accounts, and then that central repository could send out verification tokens for individual site logins. So you pay $20 to verify you are human once, and you can use that one $20 check to verify your humanity across any number of websites.
That is how you can actually do this without making Orwell spin in his grave.
Plus, I’m sure the notaries could use the business. I’m sure docusign hasn’t helped them out much.
require dick pics
Having manual account approvals combined with a short questionnaire asking why they want to join and which communities interest them has been extremely effective on my instance so far, as most bots reveal themselves at this step.
Survivorship bias. How do you guarantee that you don’t have a few dozen accounts that were set up by a human who then collected the credentials and setup an automated OpenClaw-like thing system?
I didn’t and can’t guarantee that, I merely said that most bots reveal themselves with the technique I described.
I suspect that using human applications to get an AI through the door will be somewhat uncommon, as hiring people to do that for profit seeking reasons is likely not terribly viable, as a human can only write so many applications per day, and that labor isn’t free, I just don’t see the economics working out. Bot spam is likely only profitable when it is entirely automated.
But if a human specifically targeted an instance in that way, that certainly could happen. I suspect that at least for now, other users may be able to suss-out a bot that gets through, as they still have some tell-tale signs they give off in their writing style, but it’s plausible that at some point they will be able to blend in seamlessly. At that point, we’ll need to devise new ways to weed them out if they begin to take over.
I already answered the first part your question at the end of my previous comment. As to the idea that they become more useful/beneficial than actual human members, I personally find actually interacting with other humans more fulfilling than interacting with a machine in a social context, regardless of how ‘useful’ they are.
If AI gets to the point where it’s all pervasive, indistinguishable from real people, and we somehow cannot devise a way of weeding them out of online communities, I’d honestly probably just stop participating socially in public internet spaces, and instead restrict myself to private invite-only communities that do more intense vetting to ensure only humans are in that space, or participate in and help build up local mesh-networks, where people can actually meet up with who they talk to online.
That would probably mean a lot less time spent online overall, and instead going outside and finding connection with people in real life.
f AI gets to the point where it’s all pervasive (…) I’d honestly probably just stop participating socially in public internet spaces
I think you are missing what I am trying to say: there is a significant probability we already are at this point, and I don’t think we can beat this cat-and-mouse game. If you are serious about you mean, then the only reasonable course of action is to get out of the race entirely. If more people think like you, then the scale will tips even further in favor of the bots.
All of this to say, if are so AI averse that the mere possibility of having AI around should be enough for all of us to drop this whole thing here and go back to connection only in the physical world. In a way, I wouldn’t be against the idea (maybe because I look at the internet as a source of utility and not to fulfill any emotional/social need) but on the other hand it would suck precisely because the internet can be quite useful as a tool, but its utility depends on having people around participating.
short questionnaire
“You’re in a desert, walking along in the sand, when all of a sudden you look down, and see a tortoise. It’s crawling towards you. You reach down and you flip the tortoise over on its back…”
Tortoise? What’s a tortoise?
Most low-cost and primitive bots. It costs nothing for ChatGPT to pretend to be a human in text. Are you sure they aren’t still there, lurking? Look up survivor bias.
I remember encountering my first request to write an essay in order to join an instance. I was flabbergasted and chose an instance without this madness and it appeared this instance was shadowbanned by major ones. Was close to giving up on Fediverse at this point.
They are still quite evident in the way they construct their messages, and of course any em-dash usage is a big giveaway.
Someday they’ll likely be able to answer those questions more convincingly, but right now it works for the most part.
Em dashes are the correct way to type—substituting them with hyphens is a typographical mistake.
Also, look up Human or Not game.
What’s wrong with Anubis?
Doesn’t help with APIs or federated access.
Other instances seem to be using Anubis. Perhaps join the matrix chat for Lemmy?
That helps to reduce load on the web UI and reduce not registrations, but it will not help after the bot is registered or if the bot is registered in another instance.

















