I've seen this coming for a while, but didn't raise it in the hope that my concerns were unfounded - or I didn't want to give anyone hints.
It's real.
This user http://drupal.org/user/2090714
Has No posts available
And (for admins) no nodes and no comments.
So?
So there is no way to monitor what they've done.
What have they done? Horrible Handbook vandalism
(I'm leaving that there for a bit before reversal for now)
Given the thousand of vietnamese spams I delete weekly, I live in terror of the time a user like that finds a way to start modifying existing pages, which then triggers us to *delete* their pages without stopping to see if each or any one is just a repurposing of existing docs.
IF such an automated spammer changed their algorithm slightly to infect existing pages instead of making new ones (and they can) then the next spam-wipe (which we do several times daily) could eliminate half the handbook.
OTOH, seeing as (right now) spam injections are not attributed to the user - judging by user jozafhussy http://drupal.org/user/2090714
then we *cannot* revert that.
At least not with the spam-tool available to my role right now.
I have no way of knowing if that user has done this to one page or a hundred.
Is there previous discussion of this liability?
(Major because I find this scary)
Comments
Comment #1
heine commentedYou can see this via http://drupal.org/documentation/manage but it is a painfully slow way to restore. This won't scale.
Comment #2
kingandyOn the plus side - since these edits don't show up in the "Administer nodes" view - there's little risk of somebody nuking handbook pages accidentally through that method...
Comment #3
dman commentedThanks for the link to http://drupal.org/documentation/manage
Still, no filter by user, no user-based revert - and we can see the jozafhussy pollution there too (right now anyway)
This is hard.
Comment #4
dman commentedPS. has anyone ever heard of 'dofollow' actually being a thing anywhere (as opposed to being a random descriptive term - not an attribute- of links that are not explicitly 'nofollow'ed)
my first few pages of google-fu only describe it as an antonym descriptor, not an attribute ever respected by anyone ever.
Is this just more evidence that spamdexers should be violently eliminated from the gene pool?
Comment #5
silverwing commentedI've been trying to figure out the best way to display revisions (if we allow every authenticated user to create them, we need a way to track the changes.) I'm been thinking of a page of all revisions (sortable by content type.)
Would an "Administer revisions" tab be useful on the profile page?
(I generally go through the /doc~/manage to monitor spam revisions and book page nodes)
@dman - yes. :)
Comment #6
kingandyI think we can mark this as a duplicate of either #439348: When users edit book pages they are not put in that editors tracker or #1146518: Create view of revisions created by a user (for spam tracking), or both. Either of those solutions would show us a user's "contribution" to the docs.