I added a real-time chat to my blog, people used it to attack me
65 points by andros 8 hours ago | 91 comments

zetanor 7 hours ago
Talking about this like there's an "attack" feels very melodramatic. It seems to me like the non-constructive messages are either shitposts or just curious probes (testing whether certain codepoints make it through, testing whether bad no-no words make it through, testing how various things will render, testing whether the input is sanitized...). There's links to God knows what and some walls of inflammatory language, but I'm not noticing anything that could even remotely cause any harm.
reply
saaaaaam 6 hours ago
It’s a blog post written by AI. AI makes everything ponderously dramatic.
reply
verzali 6 hours ago
That explains the opening line:

>Sometimes the most irrelevant piece of a project becomes its absolute protagonist.

reply
FatalLogic 4 hours ago
That looks more like a very bad overly-literal translation of Spanish 'protagonista absoluto'. AI generated English would not probably use a phrase which doesn't normally happen in English.

'Main focus' would be better in this situation

reply
egypturnash 7 hours ago
The chat is still there in the corner of this post, with people typing nasty shit into it.

Well have fun delving into programmatic censorship I guess. Or just take it out. If you take the former path and post about trying to fix it here then I'm sure you'll get a lot more free testing of your attempts to enforce civility through regex or whatever. Enjoy learning about the Scunthorpe problem.

reply
hliyan 7 hours ago
Looking at the last few minutes of messages, I get the feeling that all it takes is a handful of motivated (i.e. jobless) malicious individuals to make an entire community or a corner of the Internet look like it has devolved into barbarism.
reply
dpkirchner 6 hours ago
By my recollection the devolution started around 30 years ago.
reply
schaefer 6 hours ago
Suspiciously close to the birth of the modern internet?
reply
saulpw 4 hours ago
That's not suspicious, that's the load-bearing smoking gun.
reply
mannanj 5 hours ago
Isn't that always how corruption/devolution has worked? Why not use the same tools we always had: accountability via transparency and then if needed shaming.

Don't want strangers to abuse your resources and community and hide being anonymous to avoid accountability? Adjust/tune that aspect of your community - why can't you be creative and try to solve the problem with ideas like how tribes and organisms deal with this in person.

maybe we can evolve chat interfaces for this obvious low-cost-noise age. Increase the cost somehow, not saying I know how, but it is definitely possible to filter out noise by being creative. edit: stay tuned and I'll probably figure out some solutions.

reply
9Ljdg6p8ZSzejt 6 hours ago
When I checked it out, the chat was a cesspool of racism, zionism, and horny dudes. Occasionally cool fish emojis.
reply
cestith 5 hours ago
Right now there’s some minor probing, trying to get the site to print variables. There’s racism against Blacks. There’s antisemitism. There are a few people actually trying to say hi to one another. Then there’s a bot that replies to absolutely everyone and invites them to their gay male Chaturbate channel.
reply
9Ljdg6p8ZSzejt 4 hours ago
Looked like people were trying to command inject the bot. Seemed to work a bit too
reply
barbazoo 7 hours ago
Neuralink will hopefully filter that out client side /s

If your audience is more than a handful of people, what's the purpose of chat?

reply
stronglikedan 7 hours ago
To get the handful of people to collaborate and hopefully bring their friends. It's currently at 160 and climbing, no longer a handful, so it seems to be working.
reply
barbazoo 6 hours ago
What I mean is that I get the purpose of chat when the target audience is a small group of people that might have a reason to talk to each other.
reply
brabel 6 hours ago
The counter seems broken. It jumps from 100 to 250 then back down to 120. It did that a few times while I was reading.
reply
dylan604 7 hours ago
From the earliest days of websites allowing text input from users, this has been a thing. The same with any website that allows you to draw things, it will quickly show people drawing crude (in content not skill) objects. This is just human nature. Once people realized you could use these forms as attack vectors, we were off to the races. Now that bots can do it for you, I'd only imagine the time before first bot using the form is in minutes. I have seen all sorts of things suggested as workarounds to mitigate bot form submissions, but eventually, you will be spammed at the least with the feature. Adding something like a bot chat, of course people are going to be abusive to it much more than a simple form field.

For someone to be surprised by this today suggests to me that the person is really really new to managing a website.

reply
dillutedfixer 6 hours ago
Exactly. I remember a website from the late 90s that let anonymous users control an LED sign in some shopping mall in Japan. More often than not there were things like swastikas and penises on the board. This type of behavior is nothing new, unfortunately.
reply
dylan604 6 hours ago
Did these LED controls actually control lights or did they just switch out images?
reply
dillutedfixer 4 hours ago
It controlled lights. IIRC there was a grid of squares on the website that you could click on to turn specific lights on or off. There was a webcam pointed at the sign that refreshed every few seconds so you could see the changes. I remember the sign being right above an escalator.
reply
alnwlsn 5 hours ago
I've done this to myself too. I once had a thermal receipt printer I wasn't using, so I decided to point a webcam at it and put it on a webpage so anyone could print random crap to it (it's actually still up - alnwlsn.com/printer). Of course I went in knowing full well what I was getting into, and the types of messages posted to it are about what you expect and get here. Some highlights:

- It was once found by one of those worse-than-4chan places, who spent about 4 hours spamming the worst things you could imagine until it ran out of paper. I added some filtering after that to stop tons of duplicate messages from wasting so much paper and some regex, which reduced the volume of some particularly vile things. Some people do post nice messages too.

- The setup breaks often. Eventually, I'll notice and fix it, but it might have been broken for months. Inevitibly, there will be people using it again within days, with no announcement made. How enough people find it on this tiny corner of the internet is a mystery to me, but they do. I am convinced most of them are real people, because why even bother to point a bot at it?

The whole point was that I thought it would be more interesting than letting the thing sit around on a shelf, and to use up the box of rolls that came with it instead of throwing the whole thing in the trash. Intersting it is; I don't think I would describe it as plesant, but it is interesting.

reply
JSR_FDED 7 hours ago
I’d suggest one additional heuristic: once your bad word detector has triggered, shut down the chat for 10 minutes. That way waves of assholes don’t monopolize the chat, and when they move on to the next target the functionality returns to your site automatically.
reply
operation_moose 7 hours ago
Great way to get someone to create a bot that swears in the chat every 10 minutes and 1 second to permanently shut it down.
reply
phoghed 7 hours ago
But then one asshole can denial of service your chat very easily
reply
dylan604 7 hours ago
Yeah, shutting down to that specific browser fingerprint would be the better way. Sometimes, being able to recognize a user has it's benefits for good /s
reply
lesostep 6 hours ago
Or just drop websocket connection to them.

Refreshing pages to establish connection again is semi easy for someone who made a honest mistake (and Could make them more cautious), but if someone wants to trigger web-socket disconnect all the time, it would become cumbersome.

Add something like fail2ban, and you're set enough against passing trollers, but not interesting enough to draw attention from people that like the challenge.

reply
Retr0id 6 hours ago
But don't let them know they've been shut down, use a shadowban.
reply
nickthegreek 5 hours ago
Agreed. I'd just have 2 chat pools, once you break rules, you get moved to the rule breaker pool with the other like minded individuals. Well behaved individuals wouldn't even know or care about the separation.
reply
effseven 6 hours ago
[dead]
reply
fl4regun 7 hours ago
I'm mostly curious why anyone would bother with doing attacks like this to some random individuals personal blog, was it one person or multiple people? What was the motivation? Is it just bots crawling the internet to spread hate?

A sad state of affairs, but certainly seems like having a strictly moderated comment section is a better option for a site like this.

reply
SoftTalker 6 hours ago
Bored kids. Bots. And scammers/spammers. On the scale of the internet, there are a lot of all of these.

Same reason any blank wall in a city will soon be covered in graffiti.

reply
elcritch 7 hours ago
Reminds me of Maria Abramovic Rythym 0 performance art.

1: https://www.thecrimson.com/article/2023/3/30/maria-abramovic...

reply
artur_makly 7 hours ago
[dead]
reply
cestith 3 hours ago
The whole premise seems clueless about security, accountability, and human nature. A free, fully anonymous, unauthenticated, ephemeral chat is like a middle school bathroom at best. There’s not even a concept of screen names to carry a reputation like in open IRC chat. It was always going to be this.
reply
throwawayffffas 7 hours ago
The obvious solution is shutting it down it does offer nothing.

Short of that shadow ban everyone everyone sees their own messages, and add a few fake ones every now and then.

reply
netsharc 7 hours ago
Hah, or burn lots of GPU cycles for an LLM-enhanced echo-chamber of one... (For each troll an echo chamber/an LLM troll responder)
reply
embedding-shape 6 hours ago
"What I learned" seems to missing what used to be shared to every starting web developer; "If you allow user input on public internet pages, people will put vulgar, racist, hacking attempts and worse there, sometimes constantly over long periods of time"

Almost anyone who had a "guest book" had pre-moderation some way or another, or was a tiny-tiny website with barely any visitors. The second the larger cyberspace ecosystem got a whiff of your user-input-enabled website, the spamming would appear.

reply
skeeter2020 6 hours ago
>> The countermeasures

>> The first and most obvious one was a filter of inappropriate words and expressions.

Wouldn't the first and most obvious one be "drop real-time chat" from a blog?

reply
Sidhant_ch 7 hours ago
You just got yourself a product right there if it works and can market it as Roast me Blog with just trigger filters in your chat to make it healthy roast in place of abuse and highlight top roasters where people could upvote right there in your chat. Negativity turned into positive healthy banter ..
reply
hmokiguess 7 hours ago
Content moderation and social anonymous behaviour aside, your real-time chat is really poorly implemented UX wise.

I saw the same message appearing more than once, I never saw my own message appear, it has a weird lag/delay feel to it. I didn't really enjoy that experience at all.

reply
dwroberts 7 hours ago
Obviously insults and attacks are unreasonable, but I think the tag injection etc should be an expected one if you’re posting on HN right? Like somebody is going to try it for kicks and I wouldn’t say it’s even necessarily malicious
reply
wasmitnetzen 7 hours ago
Well, you've just painted a big target on your blog. This is the internet, after all.
reply
happosai 7 hours ago
Well it looked pretty quiet until HN linked to it. So the people writing that terrible stuff are from here...
reply
pamircake 7 hours ago
[dead]
reply
vivzkestrel 6 hours ago
``` The first and most obvious one was a filter of inappropriate words and expressions. I won't explain which ones or how it works inside, for obvious reasons, but it is quite effective. The machinery is in the heuristics.

The second, and most natural, was to cut the maximum number of characters way down. Less room is less ammunition to cover content and less space to hide a link. ```

- you forgot the third fix, disable copy paste inside chat boxes, remove all swear words by replacing them with **

reply
CerebralCoding 7 hours ago
This should come as a surprise to absolutely nobody.

But hey traffic is traffic I guess.

reply
none_to_remain 6 hours ago
There seems to be one category of technological "attack", which failed - the script injections.

Otherwise:

OK: A guy insults the Tailwinds devs at length

Not OK: Anyone insults that guy briefly

Of course it is his own platform (blog) but that is on another platform (hosting) which could maybe decide they don't want their platform used to attack open source projects.

(I personally have no opinion on Tailwinds except a default negative valence regarding front-end)

reply
pjc50 7 hours ago
"Every input is hostile until proven otherwise": you said it yourself. One of those sad things that somebody new learns on the Internet every day.
reply
tenderfault 6 hours ago
Look. It works. I just spent 5 minutes reading the messages posted on your glorious chat app. If I'd be you, i'd plant an ad just above it. Why are you complaining.
reply
maCDzP 6 hours ago
If the chat is saved as an example of how lot to talk. Can that be used for training an LLM on how to talk or what to remove from a chat?
reply
dabinat 7 hours ago
This sounds like the kind of feature that ends up being quick to initially implement but takes up way more engineering time to maintain than everything else combined. The author concedes at the end that most genuine uses of the feature are people just saying hello. So maybe the solution here is to disallow unrestricted input and just have a few buttons with fixed things to say.
reply
brownieman1325 6 hours ago
[flagged]
reply
thataccount 7 hours ago
The social web has become the adversarial web, unfortunately. You have to have a huge squelch knob if you want any meaningful signal now.
reply
krapp 6 hours ago
Ages and ages ago I had a guestbook, forum and chatroom on my site just because I could, just because it was fun. I think only one other person ever used it, though. But the possibility of having a random interaction with someone was what made it interesting.

Now my comments feed is my curated Mastodon account, very much a filter for nonsense. I wouldn't even think of putting a chat up on my site, it would almost entirely be bots, and then trolls. There's literally no point in trying to interact with people online anymore without some kind of curation or moderation, every possible interaction has to be treated as hostile.

reply
thataccount 6 hours ago
I tried Mastodon for awhile but found the fediverse was almost as bad as the centralized control verse. It sounds like it works for you, though.
reply
krapp 6 hours ago
It helps that I have a small, single user hosted instance so I don't need to worry about admin drama. It also helps that I generally align with the culture politically but also avoid posting about politics (because I think doing so is mostly performative and not useful.)

But I think just about any layer of moderation will do. I'd be using Disqus except it's too "engagement" oriented and collects analytics I don't want or need.

reply
thataccount 5 hours ago
Someday people will be able to disagree politically again without having to de-platform each other for doing so.
reply
krapp 5 hours ago
On the one hand, sure, but on the other hand I'm not hosting a Nazi bar and there are some political conversations I'm simply not interested in having.

But I'm not even trying to filter for politics, really, so much as literal humanity and basic decency. Just that has become a hard problem. Dealing with trolls whose entire identity is performative politics is another.

reply
thataccount 5 hours ago
I totally get that, but I also understand that the word "Nazi" has been redefined to mean something other than what it originally meant. This whole "redefinition" of language business has muddied the waters of trying to find literal humanity and basic decency. It is akin to redefining the word "hate" or "love". What you or I feel subjectively as hate or love in a given moment may be due to Vaseline on the lens of reality. If we start making decisions for everyone on that basis, well, all we are doing is getting confirmation of the reality we are projecting.
reply
krapp 4 hours ago
"What even is a Nazi" is a perfect example of a conversation I'm not interested in, because at the end of the day it's just an endless semantic treadmill.

My definition is what matters to me. If you're a white supremacist, white separatist, antisemite, transphobic or homophobic, if you support fascist ideals and violence as a means to political ends, If you think Hitler did nothing wrong, if you think immigration and multiculturalism are objectively harmful to "civilization," that Islam is a "religion of evil" or that the "degenerates" needs to be put against the wall, then I'm going to call you a Nazi and I don't want to hear what you have to say about anything. No I'm not interested in litigating those terms either.

And yes, some of these can be laid at the feet of the left as well as the right. I don't fuck with tankies and BRICS-pilled socialists either.

Not every platform has to be a culture war battleground.

reply
Funes- 6 hours ago
Wait. Is it not against the HN guidelines to regularly submit links to your own sites? Isn't that considered self-promotion and, thus, against the rules? I've got nothing against the author, personally, as I'd do the same, but seeing his submission page, I'd like to know how normal getting in trouble is for this practice or if the guidelines are enforced at all in this sense.
reply
dijksterhuis 5 hours ago
emailing hn@ycombinator.com is possibly a better way to raise a question about moderation like this fyi. mods may not see this comment but they probably will see a direct email.

theyre probably the only ones who can answer your question / nudge you in a direction of understanding appropriately.

reply
Funes- 5 hours ago
No, I don't think it is. I didn't want to reach the mods necessarily. I wanted to check what the picture was regarding the general opinion on this kind of practices, hopefully with personal experiences from regular users rather than, potentially, getting some kind of formal statement that is further from what the actual moderation activity is like, either coming from moderators themselves or from users flagging or downvoting content.
reply
Deukhoofd 7 hours ago
I'll have to be honest here man, yeah no shit. I can't think of any good reason of why you would add something like this. A standard comment section is typically bad enough, and at least you're able to moderate that. An anonymous real-time chat embedded within your own blog? That's just asking for issues.
reply
Larrikin 7 hours ago
Most people aren't awful in real life. Seems like a good idea to have a honey pot to just ban everyone in real time that tries to be an awful person on your own blog
reply
jdw64 7 hours ago
My blog posts don't get any replies even when I post them on Hacker News, but everyone wants to communicate with others. I actually think anonymous chat isn't that bad. I think the problem is people who abuse the goodwill of writing. Once you step away from Medium and Substack, you start wondering how to even get comments on your own site.
reply
axus 7 hours ago
Next we're going to hear a complaint from Mark Zuckerberg about how people are using Facebook and LLaMa to attack Meta.
reply
alansaber 7 hours ago
SLM language filters might actually be a good application of AI? As well as very sparing regex for bad words.
reply
TheBuciyo 7 hours ago
Humans will really take any chance they can to troll, I would definitely get more moderation
reply
onion2k 7 hours ago
While that's undoubtedly true, the level of trolling varies a lot so I don't think it's quite as simple as "if people can troll then they will." There's a crazy level of trolling on 4chan, quite a lot on Reddit or YouTube, and much less on HackerNews (cue troll replies to this post :D ).

I suspect that the owner, or the users, of a site are able steer how much trolling there is by incentivizing good conduct and 'policing'. If people actually value the content they won't troll, or they'll actively keep things tidy using the available tools. If people don't really care about the content (or if they only care about their relatively small corner) then they'll happily trash the bits they don't see value in.

reply
amelius 7 hours ago
According to dead internet theory, these might just as well be bots.
reply
doublerabbit 7 hours ago
According to current internet theory, these are bots.
reply
felooboolooomba 7 hours ago
You are absolutely right.
reply
mmh0000 6 hours ago
There is a well-reviewed study on this from 2004 -

Greater Internet Fuckwad Theory[1]

[1] https://www.penny-arcade.com/comic/2004/03/19/green-blackboa...

reply
grapeorangesoda 7 hours ago
Well, Django sucks for real-time chat
reply
morkalork 7 hours ago
I was watching porn recently and the particular site I was on had recently added a real time chat widget too! Aside from scam bots trying to lure users off onto telegram, the last few messages were guys talking about Monty Python's The Life of Brian.
reply
jdw64 7 hours ago
It's interesting to hear a story about 'Life' in the very place where 'Life is created.'
reply
busymom0 7 hours ago
> The first and most obvious one was a filter of inappropriate words and expressions

I don't think those countermeasures are working because as of this moment, there's plenty of obvious naughty words being passed through in that chat window.

reply
homeonthemtn 7 hours ago
What if he filled the chat with bots and is using all of this as stealth marketing?
reply
Sidhant_ch 7 hours ago
Well then it would be one product itself - something like i created bots who roast me on my blog ;)
reply
jdw64 7 hours ago
The homepage design is nice, and I think anonymous chat is fun too. Even though the programming topic probably has a pretty clear target audience, I'm surprised that kind of hateful chat still shows up.
reply
Locketgoma 5 hours ago
real-time chat is....... oh that is likely Live streaming channel. (but 's not have Chat Manager) :facepalm:
reply
grapeorangesoda 7 hours ago
lol hate speech (fun speech lbh) drives traffic
reply
elendilm 6 hours ago
The attempt to run Javascript as the author mentions is pathetic.
reply
krapp 6 hours ago
You'd be surprised how often it still works.
reply
elendilm 6 hours ago
Yes. The mindset is pathetic.
reply
latexr 7 hours ago
> What harm could a box that only broadcasts plain, ephemeral text do to me? You're thinking the same thing I was, I'm not crazy, right?

Not right. As soon as I saw the box (when the other article was posted), my immediate thought was that it was distracting, frankly a bit creepy (even just the counter is so), and obviously ripe for abuse. About one second after I had the thought, I saw it happen in real time.

> The goal, I suppose, was twofold: (…) and to make the article look bad in front of the aggregators and networks where it was being shared.

I think you’re reading too much into it. I bet all (or essentially all) the people doing that don’t care one iota about you or how you look to whatever aggregator and network. They’d write those same things on an empty wall if you gave them a can of paint. You gave them an avenue and they used it, simple as that.

reply
nicechianti 7 hours ago
[dead]
reply
nivertech 7 hours ago
TL;DR: this is a toy example, so it doesn't require BEAM VM

Hard to take this seriously without the loadtest with the the large number of concurrent users.

For a number of users concurrently reading a long-tail blog post - you will get good results even using DotCom era HTTP polling.

---

See:

Django LiveView vs Phoenix LiveView: a real benchmark

https://en.andros.dev/blog/80134668/django-liveview-vs-phoen...

reply
JSR_FDED 7 hours ago
What is there to take seriously? Sending a ~50 bytes to ~200 listeners over a websocket about once a second is trivial even for a Raspberry Pi.
reply
nivertech 7 hours ago
It pretends to be serious with 5 tables / charts:

Django LiveView vs Phoenix LiveView: a real benchmark

https://en.andros.dev/blog/80134668/django-liveview-vs-phoen...

reply
andros 4 hours ago
How would you have approached it?
reply
rkangel 7 hours ago
Yeah, maximum concurrent clients being 50 is nothing and you're already seeing a large gap. That is the whole point of the BEAM - it scales well with concurrent stuff which is important with web in general and very important for LiveView.
reply
andros 4 hours ago
50 is the hardware limit, not a personal choice. The code is free and accessible from the article itself. If you can run tests with more, I'd be happy to update the graphs and the conclusion.
reply
phoghed 7 hours ago
So that’s what’s beneath the usual HN tech bro libertarian veneer.

Oh my bad are yall under the impression that HN is not the majority of the traffic right now lmao

reply
effseven 6 hours ago
[dead]
reply