How does Instagram "SEE" bot actions?

ChrisMonkey

Registered Member
Joined
Dec 7, 2017
Messages
64
Reaction score
16
When a bot (like Jarvee) sends an API call to execute an action, does Instagram see that as an action coming from the mobile Instagram application on a mobile phone? Or can Instagram detect that the action is coming from a software?

And does using the embedded browser from Jarvee or MP show up to Instagram as using a web browser, or the browser embedded inside a mobile application?

If it's the embedded browser, it doesn't really make sense to be doing liking/following/etc on that since that isn't something you can do in the embedded browser on the mobile application.

Just trying to figure out if Instagram is able to detect bot usage from other factors than just bad proxies or non-human looking actions, or too many actions per hour/day/month.
 
Instagram knows you're botting. If I had to guess, I'd say at least 95% of people get flagged the moment they create their bot accounts. Using pretty much any publicly available bot is an additional nail in the coffin (not saying that hiring a freelancer for a private one is any better).
 
Sure, that is what I am assuming. I am just wondering the methods they can use... besides of course the proxy/actions/non-human.
 
There is a line between
Normal safe user 1----normal users who get into mutual like groups/plataforms/shady apps2------limbo3--wannabe automation users that think nobody know they are bots4

As long you stay in the grey zone of 2 you will be fine, just dont be:
-BS
-Pretend you know yet just copy others
-Literally just dont mock people, its basically this

Yes, its that simple, people mock users 1 and 2 in multiple way, they are like fucking bad parasites that drian your blood and get you sick and pretend they are good.

Be like those bacterias in our stomach, we feed them and they let us poop without bleeding our ass :D
 
Most automation software emulate the IG app, so it's like you're connecting thru the regular mobile app. IG can detect anytime you connect using automation software because theres some information that's encrypted, that's sent in between app and server that automation software cant replicate since it's encrypted.

If they really wanted to seize bots, they easily could. Twitter purged over a million bots in one day, why wouldn't IG be able to? That's why I don't understand why people freak out anytime theres any update.
 
IG gets to know when you initiate a login using a bot. And most of the bot prints are quite familiar for them, just use bad proxies and they'll end the game.
 
Instagram knows bot action because it is very calculated. Unlike human action which is very unpredictable.
 
Most automation software emulate the IG app, so it's like you're connecting thru the regular mobile app. IG can detect anytime you connect using automation software because theres some information that's encrypted, that's sent in between app and server that automation software cant replicate since it's encrypted.

If they really wanted to seize bots, they easily could. Twitter purged over a million bots in one day, why wouldn't IG be able to? That's why I don't understand why people freak out anytime theres any update.

In my opinion, this is the only possible main reason, because every other thing can be emulated by a bot. However, I do not know if there is actually any encrypted communications between the APP and Instagram servers. Anyone here who has sniffed the communications between them before to confirm this?
 
Official apps send tons of data which are processed to tell if you're really using a app or just emulating as a bot. If IG were to rely on only on api endpoints to differentiate between bots and real users it would be hard. Why would they rely on metrics that can be spoofed easily ? Also real users don't follow and unfollow 400 a day . Gods knows if they might be logging when you have sex or go to poop
 
Official apps send tons of data which are processed to tell if you're really using a app or just emulating as a bot. If IG were to rely on only on api endpoints to differentiate between bots and real users it would be hard. Why would they rely on metrics that can be spoofed easily ? Also real users don't follow and unfollow 400 a day . Gods knows if they might be logging when you have sex or go to poop

So in a nutshell, botters are part of the unspoken Instagram business model, driving them revenue with numbers - until it gets excessive and they prune it down a bit and the game continues. What does this mean ? " To your botting battlestations mate!"..:):)
 
I wonder how botting is possible at all no normal user follows hundreds of people daily
 
I wonder how botting is possible at all no normal user follows hundreds of people daily

This

Nobody follows 800 people a day, 5/7

That's why I do way less than this
 
Let's leave aside the human like actions and the number of follows a day, etc. This last wave of penalties from Instagram seems way more random. For me it's been all over the map... no matter the IP, no matter the number of actions, no matter the randomness. That is why I wanted to start the thread.. to get an idea of ways Instagram can detect bots besides those things.

It makes sense that the bots (liked Jarvee) are not able to completely emulate the communication from the Instagram mobile app. In that case, no matter all other factors, Instagram knows right away whether an account is connected to a 3rd party app the moment you log in.

By that logic Instagram knows every account betting and has just been tolerating bots because it helps their business.

So.. let's discuss ways around this? There is nothing inherently wrong with follow/unfollow (within reason), even Instagram recommends that as the best way to grow your account. Perhaps each account needs it's own real mobile phone with the Instagram mobile app. Then use a program like Zenndroid to physically push the button on the app, and that will be controlled by a bot. I may start experimenting with this as it's probably more cost effective than the Master/Slave method... I would have to charge customers around $300 a month for that, so it's a tough sell except for decent sized businesses.

And as anecdotal evidence for bot detection consider this:
One of my accounts that was blocked in this last wave was a personal account that runs on my residential IP. It only does a very modest amount of actions per hour/day/month. Follows of around 100 day / less than 3000 a month. Only lives in Jarvee, isn't being used on a mobile phone. Account was created on my own mobile phone which is on my same residential IP. Also very randomized actions. Almost never had blocks, and never got warning. Rested the account 2.5 days after the block. Started very slow after the rest, less than 20 follows first day. On 2nd day, after 2 follows got the very serious “You have been using a 3rd party application which is against our TOS and must change your password” warning. Never even got the “We are removing artificial likes…” warning first… just straight to the “we caught you, you better stop!” If there was ever an account that wouldn't get detected it would be this one.... that is why I think this all has to do with bot detection.
 
Ok, I take back what I said about bot detection... just found a research paper from Facebook... it's a great read. I don't think BHW will let me link it though. It's clear that the Instagram AI is able to detect ALL bot accounts, and can even recognize what users are using which specific bot. The "countermeasures" section is especially interesting as it shows how they mess with us. And something I never even saw before... they will delay the removal of your follows by 1 day so that you don't even notice your account is "blocked".

"“While Instagram is in a position to identify all AAS customer accounts, blocking these accounts is not a desirable outcome since Instagram users still use them to initiate legitimate actions that should not be blocked (even while they are also enrolled in an AAS).”"
 
Last edited:
Instagram have a massive developer force, they have smart people working for them, experts on different areas, machine learning, artificial intelligence, pattern detection, many many more super technical things they can do with all the data they have on user behavior, user interaction, usage patterns and gazillion variables to analize and play with.

They can detect almost everything and they are constantly updating and changing the algorithm, probably the algorithm is advanced enough that it also improves on its own using big data, machine learning and AI. So is super easy for them to spot bots from a mile away, all bots are pretty basic with the setup and actions, they don´t have much "random" behavior in them, the bots don´t use any advance techniques to prevent being spotted, just some basic tricks.

So the bot developers and the software will need to be massively updated in order to counter act IG techniques. This is a multivariable problem, and is a HUGE problem. Many companies will go bankrupt because they will not be able to adapt.

We must wait till we can gather more info after lots of trial and error.

Not much we can do about it until the dust settles after this massive ban.
 
Well if anyone has the resources to counteract the Instagram algorithm / AI its the commercial bot makers. In the Facebook paper they calculated Instazood / Boostagram / et al where grossing $800,000 to just over 1 million per month.
 
Check out this:

https://research.fb.com/publication...rizing-account-automation-abuse-and-defenses/

Abstract
Online social networks routinely attract abuse from for-profit services that offer to artificially manipulate a user’s social standing. In this paper, we examine five such services in depth, each advertising the ability to inflate their customer’s standing on the Instagram social network. We identify the techniques used by these services to drive social actions, and how they are structured to evade straightforward detection. We characterize the dynamics of their customer base over several months and show that they are able to attract a large clientele and generate over $1M in monthly revenue. Finally, we construct controlled experiments to disrupt these services and analyze how different approaches to intervention (i.e., transparent interventions such as blocking abusive services vs. more opaque approaches such as deferred removal of artificial actions) can drive different reactions and thus provide distinct trade-offs for defenders.
 
Back
Top