Still no official word on this?
nope.
Hi.
We have taken steps over the years to reduce comments (and forum) spam. A verified email is already required for comment posting. Also the account has be 1 day old to post a comment. And we do have IP address floodchecking for account creation and post floodchecks.
All the bots you see posting comments have a verified email, have existed for more than a day, and used IP address masking to get past floodchecks. They are highly motivated to do whatever it takes to post comments, because it makes them money on the black market. They will adapt to post CAPTCHAs by hiring human solvers. They will adapt to game play requirements by having their bots play the game for however long it takes to meet the requirement.
We are not ignoring this issue. Weâre working on shorter and longer term fixes. Thatâs all I can say about it at this time.
Human solvers canât do this:
Thatâs well over a thousand consecutive spam comments on a popular game. This is what every game looks like right now.
I really think the hackers will have to put more money into having humans solve the CAPTCHAs than they make off of scamming. Are they willing to spend money in the first place? I know adding a CAPTHCAs wont fix the issue, but it will be more effective than the verified email and the steps we have now.
I can only imagine how many of these posts would be created if these checks were active.
I agree with this. How sophisticated even are these bots? Even if the person behind them is serious about trying to scam people, a captcha would still slow these bots down. Its reached crisis point if you ask me.
Theyâre already spending money running servers to spam like this. Capchas arenât expensive to crack either.
Letâs say capchas are implemented. The spammers will have to spend, letâs say 50% of their revenues cracking the capchas. Any sane person would rather spend half of their earnings than have no earnings at all. The issue wouldnât stop.
True, but over time, less people will fall for it, thats when that 50% would really start to bite.
The Current Incentive:
- Largely spammable, with some passable protection
- Moderation team is only human, will take time to catch on
- ITS FREEE, printing monay.
Post-Captcha - Largely spammable, with some passable protection, however youâve got to spend X to begin to spamming it.
- Moderation team is only human
- No longer free. Got to actually put some money in.
So, post-captcha what is the current incentive?
Make as much as possible, as quickly as possible.
If they are after more, theyâll spend more, the more they spend, the more theyâll have available to lose.
If the moderation team were able to catch up with them even by a day or so, theyâd still be making a net loss.
Thats my understanding of the pseudo-situation tho, not really invested in the world of spam so I could be wildly wrong, but if the only people its truly going to hurt are the spammers, then theres no real question.
That or moving comments to a like-dislike system where youâve actually got to play the game youâre commenting on, much like steam.
A single person can run a comment spamming empire. Once one person has a bypass, everybody does. Even if 50% of the current spam botters get discouraged, all you need is one guy to make everything hell for everyone. Thatâs why a âthis should discourage peopleâ situation isnât useful.
A total solution is necessary. I have no idea what that solution is - but it isnât a capcha.
A single person can run a drug empire. Once one person has a way to distribute drugs, everybody gets them. Even if 50% of the current drug distributors get discouraged, all you need is one guy to make everything hell for everyone. Thatâs why a âthis should discourage peopleâ situation isnât useful.
Sounds unreasonable when I change the thing the comment spammers do. think of captcha like DEA, it stops some, but it is better than none.
Thatâs a really horrible analogy.
All comments go through robloxâs system before being posted on the website. Not all drugs go through a single conveyor belt to get into a countryâŚ
cough certain politicians think otherwise smh cough
What happens to it when it goes through Robloxâs System? A lot of us have started suggesting things that could be done, but I donât think any of us have a real understanding of what is actually done.
And how feasable would the only comment after playing a game system go in terms of stopping spammers?
Bringing this back up again cause there are new threads about it.
We already have this thread, no need to make a seperate one. We also heard from Becky, so there is nothing left we can do about it
This is the Steam comments section on games:
This is on a popular game that just got released (Civilization VI). On ROBLOX, the comments section would be flooded with thousands of scam-spam comments.
I donât see any spam. I see well-written, helpful reviews, even though thereâs just as much incentive to scam people out of items on Steam as there is on ROBLOX. There is real money involved on that platform as well, and you could use a bunch of stolen cheap items to build up your steam funds, buy more expensive items and then sell them way below their Steam price on a âblack marketâ of sorts and earn real money. The incentive to scam is there, but comments donât seem to be a viable way to go about this. Why is that?
Using bots to spam comments isnât much more difficult.You have to get past a verified email and you also need to allow a device to access the account. Once you have that, your bot can spam comments all day until your account gets banned.
The issue that youâd face then is that even if you can get someoneâs login details, you need to be able to get into their email to authenticate your device. This is a one-time thing. Once youâve authenticated the device, you donât ever have to do it again for that device, so a simple username/password combination wouldnât get you anywhere if you managed to trick someone into giving you it.
Iâm not saying this should be done exactly the same way on ROBLOX, but if it were a requirement to make trades with people or buy items from users that arenât ROBLOX on a verified device, scamming people would be much less viable than it is now, because youâll need access to their E-Mail account as well as their ROBLOX account in order to steal from them.
Then, you can actually make good reviews because there isnât a 200 character limit. 200 characters isnât enough to say anything constructive at all, so no one ever posts constructive comments on ROBLOX in the first place, because itâs impossible.
And finally, they have a system where you can up/down-vote comments. Very helpful comments will naturally rise to the top and spam comments will naturally fall to the bottom. Yes, this would make it difficult to see newer comments, but as you can see, Steam solved it by showing the most recent comments in a âsecondaryâ comments section for new comments - and as you can see, there isnât really much spam in that section either, because itâs not viable to spam on that platform.
I agree that a Captcha wouldnât be a good solution to the problem, so why donât we look at other platforms that have gotten it right and take ideas from there?
EDIT: Also, Steam doesnât allow newly authenticated devices to trade, change passwords, etc. so even if the E-mail account was compromised, the owner of the account would have time to act upon their account being compromised. Furthermore, Steam sends you an E-mail whenever a new device was authenticated so you always have a way of knowing someone got in. If we had such a system on ROBLOX, scamming wouldnât be nearly as viable anymore.
2FA requirement for posting comments and a longer text limit would both potentially increase quality and decrease quantity.
Thatâd be amazing.
Additionally, there could be an official blog post / youtube video to engage with the Roblox crowd. If you engage with the spammerâs targets and inform them, wonât that also remove part of the incentive? Sure, its not a solution for the spam itself, but its something productive while the issue is being worked on.
Would truly be a viable solution, and much more so then removing comments and the server list.
Edit: Sorry, didnât read post you were replying to â only the title.
Your explaination for why captchas doesnât work was that botters can hire âcaptcha slavesâ, that complete captchas for money. The way I imagine this works is by sending these slaves a picture of the captcha, and they will return the answer.
If ROBLOX was to take usage of reCaptcha, it would be another story.
And to be completely fair, your response was way out of context.
The âWould truly be a viable solutionâ was aimed towards the upvoting / downvoting system that Anon928 suggested, and had nothing to-do with Captchas.
Adding to that, it would slow down bot creation from 10/s to 10/min
Seriously, if captcha is even added for a trial itâll work