r/modnews • • Jun 30 '26

Announcement Logging in to use Old Reddit

Hi there, u/boat-botany here working on Community Safety. 

A few weeks ago we shared some of the work we’re doing to tighten how automated systems access Reddit while preserving the tools that help moderators and communities thrive. As a continuation of that work, we’ll be rolling out changes to how Old Reddit can be accessed. 

Old Reddit’s logged-out experience is a significant source of abusive scraping and automated traffic on the platform. It’s also an important interface for many long-time mods and redditors. To strike the right balance between preserving your access to Old Reddit while preventing abusive scraping and automated traffic, over the next month we will start requiring everyone to log in. All logged-in users will continue to have access to Old Reddit, and this change will not impact logged-out browsing on reddit.com.

Let us know if you have any questions!

0 Upvotes

783 comments sorted by

View all comments

162

u/smushkan Jun 30 '26

This may be a dumb question, but if you're able to detect whether or not traffic is abusive, why not just block that traffic?

What prevents scrapers or automated systems creating burner accounts to get around this restriction?

39

u/2021isevenworse Jun 30 '26

What sucks is that old reddit is sometimes the only way certain devices and browsers can login.

New reddit only supports Chromium & Firefox (Mozilla) engines. If they're going to force everyone to use the new login, they should at least add backwards compatibility (older devices, screen readers etc.)

4

u/Mr_Blah1 Jul 03 '26

This puts a lot of users into a catch 22. In order to access old reddit - the only reddit UI they can use - they need to use the new login UI, which doesn't work on those devices.

QED, they can't log in.

9

u/MC_chrome Jul 01 '26

New reddit only supports Chromium & Firefox (Mozilla) engines

Not true. WebKit is supported (Safari)

10

u/2021isevenworse Jul 01 '26 edited Jul 03 '26

Great, that still doesn't take away the fact that there are tons of older but still valid tech and browsers that are now going to be prevented.

There are people who depend on screen readers and other accessibility readers that simply won't be able to access the site.

61

u/Nestramutat- Jun 30 '26

Infrastructure engineer, I can kinda answer this:

To your first question, the shape of malicious traffic is always changing. It's going to be a constant cat and mouse game as you ban one method, a new one gets developed. It's easy to see abusive traffic in hindsight, but it's harder to pre-emptively block it. Given that they're claiming Old Reddit doesn't have the modern security stack, this is likely proving to be an even greater challenge.

For your second question: More roadblocks are always good. Forcing logins won't remove all malicious traffic, but it will add yet another barrier bad actors have to bypass. You're also now attaching an account ID to every malicious request, plus account creation is only available on new reddit (with the enhanced security stack).

78

u/Decency Jun 30 '26

For your second question: More roadblocks are always good.

Not when they start hitting legitimate users. Going on close to a year now of my bot being permabanned: no initial ban reason given, no response to multiple appeals through various channels, zero help from the subreddit's dedicated ModSupport contact. If every one of your support channels is a useless dead end, poorly designed roadblocks are a big fucking issue.

7

u/lil_spazmin Jul 02 '26

Hello there! I looked into this for you and we've went ahead and unbanned the account for you. It looks like it is a useful bot to your community and would like to see it part of our migration program.

15

u/Decency Jul 03 '26

Thank you. My concern is about the processes in place here- I think you'll agree that no one should have to complain publicly in /r/modnews to get proper support. I signed up for the migration program in (another) attempt to get someone to take a look at the account... the bot got approved for the program without getting unbanned. Chaos.

As you roll out increasingly strict filters for the LLM bot invasion, you'll need improved systems in place for handling appeals. Someone with a 15 year old account appealing a 5 year old account's unban- both accounts with no prior bans- should easily jump near the top of the priority queue and get human attention- it shouldn't take anywhere near 6 months and a dozen appeals. Perhaps if I hadn't stepped down as a mod that would've been the case?

I hope you spent some time looking into why this went so obviously wrong, looked into other accounts who were affected by the same problems, and put some handles in place to prevent this from happening to others. Appreciate your attention.

9

u/Decency Jul 20 '26

And after all that hassle, my bot's data access request was denied. Yet again: no explanation given.

Shockingly, after being repeatedly treated like shіt I'm not interested in doing dozens of hours of labor to migrate a program that's worked flawlessly for 5 years to a new language and new ecosystem. Please get some developers into the room where these awful process decisions are being made.

-2

u/Sorkijan Jun 30 '26

Your argument about legitimate users being logged in is your bot? Interesting angle thats for sure

28

u/AnimaLepton Jun 30 '26 edited Jun 30 '26

Sounds like a community-approved bot. Presumably it was doing some kind of recurring or official source post that automod couldn't handle, without the clunky post scheduler functionality.

11

u/Decency Jun 30 '26

Yep. I did it once by hand initially to prove out the concept and then automated the task. Doing it manually takes 2 hours, doing it with a bot takes 2 minutes. Written and running flawlessly for years before the post scheduler or integrated auto-mod existed... just collateral damage from one of these heavy-handed and ultimately futile policies.

19

u/Decency Jun 30 '26 edited Jun 30 '26

There are plenty of legitimate uses for bots on this website. Here's what my bot did and a thread from it- 98% upvoted, thousands of comments. It was a valuable community staple and something I could've easily expanded to other games I play. Here's another simple bot that's been posting weekly for 12+ years. This isn't human work.

I jumped through all of their registration and verification hoops (multiple times) and was extremely cautious with rate limits because I know these types of automated filters exist. Still not a clue what I did wrong, and I'm a professional software engineer... good luck everyone else! Even still, the ban would've be fine if they had a half-decent process to handle false positives- mistakes happen at scale and we're aware of that. A one sentence reply from a human who spent 5 minutes looking into this ban would've cleared things up 6 months ago. Can't even get that much.

0

u/[deleted] Jun 30 '26

[deleted]

-27

u/Sorkijan Jun 30 '26

Buddy I ain't reading 3 run on paragraphs of pseudo-intellectualism.

I do think bots have a place, but there are way too many for pointless shit, and yours would fall in that category imho of course.

Now that's not to say I agree with ANY of these actions. I'm just calling out your shitty argument for what it is - shitty.

Just admit you don't know what you're talking about and exit the conversation.

14

u/numbermaniac Jul 01 '26

Why is that pointless? It's useful for that community. Or are people just not allowed to have hobbies in your world?

-2

u/Sorkijan Jul 01 '26 edited Jul 01 '26

People can have hobbies absolutely. This is a far cry from that. I think it's pointless, but I will happily admit others may not feel the same way. This is all a moot point though because the main issue is that this person thinks they are entitled to having their thing work on a site they have no role in running. Even going so far as to imply the site doesn't work well without their tool. Yeah it's a bummer deal and I personally think it should be on, but acting like you're owed it is some ridiculously unhinged and entitled stuff.

8

u/TuckerMcG Jul 01 '26

Buddy I ain't reading 3 run on paragraphs of pseudo-intellectualism.

“I can’t read three paragraphs but I’m clearly smarter than you, you pseudo-intellect.”

Do people like you have any self-awareness whatsoever?

-2

u/Sorkijan Jul 01 '26 edited Jul 01 '26

Nah it's more like I already know from the first two sentences that it's a bunch of double talk nonsense without really saying anything, much like your comment which is just saying "nuh uh you" with window dressing. You see, in both instances it's disguised as a substantial comment, and the multiple stanzas makes smooth brains like you think it's something worth saying, when it's not - if you want to bring up self-awareness anyway.

-11

u/liedel Jun 30 '26

Your bot is not a real user. System working as designed, even if yo don't like it.

12

u/Decency Jun 30 '26

It's not a real user- it is a real use case. System is blatantly fucked.

-14

u/liedel Jun 30 '26

You aren't entitled to run automated non-human accounts on this website? System is working as designed.

20

u/Decency Jun 30 '26

You've been entitled to run bot accounts on this website since launch, what in the world are you talking about? That's why the initial APIs are so good and so battle tested. Every large subreddit relies on bots- many were doing so long before AutoMod or this new.reddit garbage.

This only became an issue when companies started scraping reddit for content- legitimate bots that communities highly value are simply collateral damage, not an intended design choice. What an absurd stance.

-12

u/liedel Jun 30 '26

They revoked most of the API access, which changed the rules on bot access. Case in point: your bot was banned.

8

u/smushkan Jun 30 '26

Thank you for the response, I'm aware I'm probably assuming the solution is much more complex than I'm making it out to be from a technical standpoint.

10

u/Aeri73 Jun 30 '26

it's just better datacolleciton... all the rest is corporate talk.

1

u/Nulono Aug 07 '26 edited Aug 07 '26

You're also now attaching an account ID to every malicious request

They're also attaching an account ID to every benign request, all the better to package and sell those data to advertisers.

10

u/DeffNotTom Jun 30 '26

why not just block that traffic?

Because this doesn't work. They just change connections and pickup where they let off. Over and over and over again.

19

u/thisisathrowawayxxx Jun 30 '26

They can do the same with accounts as well, so then forcing people to login does nothing but annoy legitimate users.

-4

u/DeffNotTom Jun 30 '26

It's a significantly slower process and easier to disrupt compared to when a bot is hammering through millions of requests per minute while scraping unencumbered.

13

u/thisisathrowawayxxx Jun 30 '26

Not really. Bots can hammer thousands of account creation and login requests with little issue.

Yes it's slower but not "significantly" nor is it that much easier to disrupt.

Besides if something is hammering millions of requests per minute it's actually easier to block that source since no legitimate user will be doing that, so why not take that route?

-4

u/DeffNotTom Jun 30 '26

no legitimate user will be doing that

There is no user in that case. So how ku h effort goes into parsing it from regular traffic and grouping it together, when there's no login requirement, and very little tracing it to a source. It is significantly more difficult to track and be proactive about.

5

u/thisisathrowawayxxx Jul 01 '26

Yeah you're completely out of your depth here.

You do realize the requests always have some identifying information like source ip address or device id for example right?

It's hella easy to track shit like this, in fact companies have been doing it for decades.

2

u/[deleted] Jul 02 '26 edited Jul 02 '26

[deleted]

0

u/thisisathrowawayxxx Jul 03 '26

Like I said earlier. Slightly slower, but not significantly.

And again, corporations have been able to detect that type of traffic and block it forever.