Join us at the Oolite Anniversary Party -- London, 7th July 2024, 1pm
More details in this thread.

FaceBook [Linkcheck]

General discussion for players of Oolite.

Moderators: winston, another_commander

Post Reply
User avatar
Cholmondely
Archivist
Archivist
Posts: 5134
Joined: Tue Jul 07, 2020 11:00 am
Location: The Delightful Domains of His Most Britannic Majesty (industrial? agricultural? mainly anything?)
Contact:

FaceBook [Linkcheck]

Post by Cholmondely »

FaceBook [Linkcheck]

Just saw this listed on the Board Index page as a registered user which was currently online.

How come this gets membership of our Bulletin Board? How does this add in any way to our community? And why is Facebook spying on us?



And what on earth is the point of hiding everything (lists of Developers, Spam Bot Assassins etc) and then allowing "FaceBook [Linkcheck]" bots in?
Comments wanted:
Missing OXPs? What do you think is missing?
Lore: The economics of ship building How many built for Aronar?
Lore: The Space Traders Flight Training Manual: Cowell & MgRath Do you agree with Redspear?
User avatar
Wildeblood
---- E L I T E ----
---- E L I T E ----
Posts: 2321
Joined: Sat Jun 11, 2011 6:07 am
Location: Western Australia

Re: FaceBook [Linkcheck]

Post by Wildeblood »

Cholmondely wrote: Fri Jun 07, 2024 9:27 am
FaceBook [Linkcheck]

Just saw this listed on the Board Index page as a registered user which was currently online.

How come this gets membership of our Bulletin Board? How does this add in any way to our community? And why is Facebook spying on us?
It's a frequent visitor. Very frequent. More frequent than Bing, in my estimation. Presumably, it follows links people have posted to Facebook, and censors posts containing broken links. As long as there is one message somewhere on FB linking back here, it will visit periodically. Also presumably, locking out Linkcheck would inconvenience someone who is a member both here and on FB.

We appear to have those bots right where they want us.
"Would somebody stop that bloody music!"
User avatar
hiran
Theorethicist
Posts: 2209
Joined: Fri Mar 26, 2021 1:39 pm
Location: a parallel world I created for myself. Some call it a singularity...

Re: FaceBook [Linkcheck]

Post by hiran »

Wildeblood wrote: Fri Jun 07, 2024 4:21 pm
Cholmondely wrote: Fri Jun 07, 2024 9:27 am
How come this gets membership of our Bulletin Board? How does this add in any way to our community? And why is Facebook spying on us?
It's a frequent visitor. Very frequent. More frequent than Bing, in my estimation. Presumably, it follows links people have posted to Facebook, and censors posts containing broken links. As long as there is one message somewhere on FB linking back here, it will visit periodically. Also presumably, locking out Linkcheck would inconvenience someone who is a member both here and on FB.

We appear to have those bots right where they want us.
I believe the reasoning to be correct. But how/why there is a user account for a bot is still a question mark for me.

However someone could have registered an account, then put the credentials into the bot. And to mark it up changed the username in the aftermath.

If we block this user I guess the bot will conclude the links to be invalid and remove them from Facebook. Do we want that?
Sunshine - Moonlight - Good Times - Oolite
User avatar
Wildeblood
---- E L I T E ----
---- E L I T E ----
Posts: 2321
Joined: Sat Jun 11, 2011 6:07 am
Location: Western Australia

Re: FaceBook [Linkcheck]

Post by Wildeblood »

hiran wrote: Fri Jun 07, 2024 4:34 pm
But how/why there is a user account for a bot is still a question mark for me.

However someone could have registered an account, then put the credentials into the bot. And to mark it up changed the username in the aftermath.

If we block this user I guess the bot will conclude the links to be invalid and remove them from Facebook. Do we want that?
Somewhere deep in the phpBB admin settings, you'd find a setting to allow/disallow known safe bots. The BB shows bots on that list as "registered users", but no registration process ever occurred. (It's been a looong time since I installed a phpBB, so I can add no more detail.)
"Would somebody stop that bloody music!"
User avatar
hiran
Theorethicist
Posts: 2209
Joined: Fri Mar 26, 2021 1:39 pm
Location: a parallel world I created for myself. Some call it a singularity...

Re: FaceBook [Linkcheck]

Post by hiran »

Sunshine - Moonlight - Good Times - Oolite
User avatar
hiran
Theorethicist
Posts: 2209
Joined: Fri Mar 26, 2021 1:39 pm
Location: a parallel world I created for myself. Some call it a singularity...

Re: FaceBook [Linkcheck]

Post by hiran »

Wildeblood wrote: Fri Jun 07, 2024 4:48 pm
hiran wrote: Fri Jun 07, 2024 4:34 pm
But how/why there is a user account for a bot is still a question mark for me.

However someone could have registered an account, then put the credentials into the bot. And to mark it up changed the username in the aftermath.

If we block this user I guess the bot will conclude the links to be invalid and remove them from Facebook. Do we want that?
Somewhere deep in the phpBB admin settings, you'd find a setting to allow/disallow known safe bots. The BB shows bots on that list as "registered users", but no registration process ever occurred. (It's been a looong time since I installed a phpBB, so I can add no more detail.)
Good hint. Here is the relevant part from the documentation:
https://www.phpbb.com/support/docs/en/3 ... m_spiders/
Sunshine - Moonlight - Good Times - Oolite
User avatar
Cholmondely
Archivist
Archivist
Posts: 5134
Joined: Tue Jul 07, 2020 11:00 am
Location: The Delightful Domains of His Most Britannic Majesty (industrial? agricultural? mainly anything?)
Contact:

Re: FaceBook [Linkcheck]

Post by Cholmondely »

hiran wrote: Fri Jun 07, 2024 5:16 pm
No activity since 24th February....

And the bot is back again.





Edited to say: almost 2 hours later and this blasted bot is still in our BB spying on us.
Comments wanted:
Missing OXPs? What do you think is missing?
Lore: The economics of ship building How many built for Aronar?
Lore: The Space Traders Flight Training Manual: Cowell & MgRath Do you agree with Redspear?
User avatar
hiran
Theorethicist
Posts: 2209
Joined: Fri Mar 26, 2021 1:39 pm
Location: a parallel world I created for myself. Some call it a singularity...

Re: FaceBook [Linkcheck]

Post by hiran »

Cholmondely wrote: Sun Jun 09, 2024 6:53 am
And the bot is back again.

Edited to say: almost 2 hours later and this blasted bot is still in our BB spying on us.
The forum is publicly viewable. So anyone can spy on us - a decision we never questioned. But we can change it to only allow registered users.
What I want to point out though is that this bot, although scanning us without specific user account, is detected and treated with 'bot provileges'. And this shows up in logs, online users etc. So nothing harmful is happening.

But we can switch the discussion to: Should the board be visible to anonymous users?
Sunshine - Moonlight - Good Times - Oolite
User avatar
Cholmondely
Archivist
Archivist
Posts: 5134
Joined: Tue Jul 07, 2020 11:00 am
Location: The Delightful Domains of His Most Britannic Majesty (industrial? agricultural? mainly anything?)
Contact:

Re: FaceBook [Linkcheck]

Post by Cholmondely »

hiran wrote: Sun Jun 09, 2024 11:11 am
Cholmondely wrote: Sun Jun 09, 2024 6:53 am
And the bot is back again.

Edited to say: almost 2 hours later and this blasted bot is still in our BB spying on us.
The forum is publicly viewable. So anyone can spy on us - a decision we never questioned. But we can change it to only allow registered users.
What I want to point out though is that this bot, although scanning us without specific user account, is detected and treated with 'bot provileges'. And this shows up in logs, online users etc. So nothing harmful is happening.

But we can switch the discussion to: Should the board be visible to anonymous users?
I've no desire to make the board invisible. Just restricting access to (eg) details about our members to non-members.

What are these "bot-privileges"?
Comments wanted:
Missing OXPs? What do you think is missing?
Lore: The economics of ship building How many built for Aronar?
Lore: The Space Traders Flight Training Manual: Cowell & MgRath Do you agree with Redspear?
User avatar
hiran
Theorethicist
Posts: 2209
Joined: Fri Mar 26, 2021 1:39 pm
Location: a parallel world I created for myself. Some call it a singularity...

Re: FaceBook [Linkcheck]

Post by hiran »

Cholmondely wrote: Sun Jun 09, 2024 12:19 pm
hiran wrote: Sun Jun 09, 2024 11:11 am
What I want to point out though is that this bot, although scanning us without specific user account, is detected and treated with 'bot provileges'. And this shows up in logs, online users etc. So nothing harmful is happening.
I've no desire to make the board invisible. Just restricting access to (eg) details about our members to non-members.

What are these "bot-privileges"?
So bots can only read data. They are not allowed to write anything, not even registering accounts is forbidden. They are completely anonymous - while still their presence is detected. Why then detect them?

As bots just come to scan and index (to be able to verify links are valid or to guide users to us when keywords match), they do not enjoy some complex styled website. In contrary, it takes the forum effort to add all the formatting while the bot then spends effort to ignore all of it. Therefore phpBB offers to configure a special, minimalist style for bots to ease off that burden. This minimalist style could e.g. omit links to user details or the member list.

So all you are worried about is already there, I just cannot say if it is configured to an optimum. On the other hand this board no longer lists the admins or moderators, and that decision was not taken because of bots but because of privacy reasons. Privacy applies not just for bots but for all users and reduces our attack surface.
Sunshine - Moonlight - Good Times - Oolite
User avatar
Cholmondely
Archivist
Archivist
Posts: 5134
Joined: Tue Jul 07, 2020 11:00 am
Location: The Delightful Domains of His Most Britannic Majesty (industrial? agricultural? mainly anything?)
Contact:

Re: FaceBook [Linkcheck]

Post by Cholmondely »

hiran wrote: Sun Jun 09, 2024 12:37 pm
So bots can only read data.
That's my concern. If the bot only has the same access as a guest, fine.

But the things are registered. This presumably gives them access to things which are kept secret from unregistered users. (Have you tried seeing what you lose access to without being logged in?) Such as possibly the list of members with the details published there in that database. And our chats on the Riedquat Space Bar: “Whiskey Business”.

I thought that this worry was pretty obvious from my previous posts.

I do not see why we have to allow facebook access to any of that information. I think that Cody might share my concerns, and I'm sure that other members of our community do too...

I really think that you should expel that bot immediately. It has been nosing around all day...
Comments wanted:
Missing OXPs? What do you think is missing?
Lore: The economics of ship building How many built for Aronar?
Lore: The Space Traders Flight Training Manual: Cowell & MgRath Do you agree with Redspear?
User avatar
hiran
Theorethicist
Posts: 2209
Joined: Fri Mar 26, 2021 1:39 pm
Location: a parallel world I created for myself. Some call it a singularity...

Re: FaceBook [Linkcheck]

Post by hiran »

Cholmondely wrote: Sun Jun 09, 2024 2:29 pm
hiran wrote: Sun Jun 09, 2024 12:37 pm
So bots can only read data.
That's my concern. If the bot only has the same access as a guest, fine.

But the things are registered. This presumably gives them access to things which are kept secret from unregistered users. (Have you tried seeing what you lose access to without being logged in?) Such as possibly the list of members with the details published there in that database. And our chats on the Riedquat Space Bar: “Whiskey Business”.

I thought that this worry was pretty obvious from my previous posts.

I do not see why we have to allow facebook access to any of that information. I think that Cody might share my concerns, and I'm sure that other members of our community do too...

I really think that you should expel that bot immediately. It has been nosing around all day...
Again: That bot comes in as unregistered user. It does not attempt to authenticate but it does not hide itself either. That's why the forum software is able to identify it. How would you expel an anonymous user without locking the forum for only registered users?
Sunshine - Moonlight - Good Times - Oolite
User avatar
Cholmondely
Archivist
Archivist
Posts: 5134
Joined: Tue Jul 07, 2020 11:00 am
Location: The Delightful Domains of His Most Britannic Majesty (industrial? agricultural? mainly anything?)
Contact:

Re: FaceBook [Linkcheck]

Post by Cholmondely »

hiran wrote: Sun Jun 09, 2024 5:43 pm
Again: That bot comes in as unregistered user. It does not attempt to authenticate but it does not hide itself either. That's why the forum software is able to identify it. How would you expel an anonymous user without locking the forum for only registered users?
Sorry. Did not understand what you were saying earlier.
Comments wanted:
Missing OXPs? What do you think is missing?
Lore: The economics of ship building How many built for Aronar?
Lore: The Space Traders Flight Training Manual: Cowell & MgRath Do you agree with Redspear?
User avatar
hiran
Theorethicist
Posts: 2209
Joined: Fri Mar 26, 2021 1:39 pm
Location: a parallel world I created for myself. Some call it a singularity...

Re: FaceBook [Linkcheck]

Post by hiran »

Cholmondely wrote: Sun Jun 09, 2024 6:04 pm
hiran wrote: Sun Jun 09, 2024 5:43 pm
Again: That bot comes in as unregistered user. It does not attempt to authenticate but it does not hide itself either. That's why the forum software is able to identify it. How would you expel an anonymous user without locking the forum for only registered users?
Sorry. Did not understand what you were saying earlier.
Maybe I was too technical. :oops:
Sunshine - Moonlight - Good Times - Oolite
Post Reply