HelloZeroNet / HelloZeroNet/ZeroNet

Antibot/antispam system to help prevent spam and allow community moderated sites

Ouverte
#1,310 2 commentaires 1 réaction 0 personnes assignées Voir sur GitHub
Langage dominant
JavaScript
Étoiles
18.8k
Forks
2.3k
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

### Step 1: Please describe your environment

* ZeroNet version: 0.6.2

### Step 2: Describe the problem:

Zeronet may be missing some system which will prevent bots or malicious users to create many identities and use them to either SPAM or manipulate certain functions like voting system. Voting system can be used to allow users to moderate zites content (example vote to move some content to different category, vote to rank some content better or worse, vote to move some content into recycle bin or hide for moderation by reputable users). I think community driven sites is the future, not to rely on a single point of failure (a zite admin). But there is needed the system that will prevent abuse of the voting system by the bots and it will also prevent bulk spam.

### Step 2: Ideas on the antibot/antispam/anti-voting-abuse system:

1. ID authority like zeroid will require new user to solve antibot challenge (i would not be against temporarily using https://hcaptcha.com it is reasonable privacy), sort some elements)
2. Generating some identity key based on device hardware or software and allow developers to rate-limit one device regarding number of actions it can do on site (number of votes, number of topics created)
3. calculating user karma/reputation score based on account age, posting frequency, number of deleted posts by moderator, number of downvotes issued by reputable members
4. Work with user's IP and /26 or /24 subnet maybe transformed into some hash/key for privacy will be rate-limited on how many posts/votes it can do no matter number of IDs used - btw. another P2P tool is having SPAM problem too, [developer says](https://github.com/zlatinb/muwire/issues/63#issuecomment-892915912) that devoted SPAMmer can build custom version of the app for spamming, but how to prevent this?

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

No files, tests, or entry points are named. Start by tracing ZeroID identity creation and the voting and moderation flows described in the issue, then define a bounded anti-abuse design with explicit acceptance criteria before implementation.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Domaine
authentication, authorization, security
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
À l'abandon
Clarté
À clarifier
Accessibilité débutants
15/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.