GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Okay, this made me laugh.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The long story short with the Mastodon spam woes this weekend is it’s a deliberate attack exploiting Fediverse and Mastodon issues.

They’re using Tor exit nodes and everything is automated. I think they can just keep running it, as there is no barrier to stop them.

To keep it in perspective, though, I don’t think it’s a big deal at present. People should just ignore it.

anarchic_teapot,
@anarchic_teapot@lingo.lol avatar

@GossiTheDog Typos in the last paragraph, should read:
"To keep it in perspective, though, I don’t think. People should just ignore me."

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

deleted_by_author

  • Loading...
  • anarchic_teapot,
    @anarchic_teapot@lingo.lol avatar

    @GossiTheDog Statement of fact, laugh that off.

    wollman,
    @wollman@mastodon.social avatar

    @GossiTheDog oh shit. The Tor node (non-exit) that we host was the target of a DoS from random Linode VMs on Friday. Could it be part of the same thing?

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    There is a bunch of technical issues it highlights, which is that Fediverse is very open to abuse at present. There’s no spam filtering at all. It’s like email from 1996. It’s wide open to abuse.

    IMHO Mastodon admins should enable CAPTCHA for registration - it’s supported out of the box - if they run open sign ups.

    Ideally Mastodon would add easy install third party plugins (a la Wordpress etc) so people could develop optional plugins for anti-spam and anti-malware.

    jbiserkov,
    @jbiserkov@mas.to avatar

    @GossiTheDog How is CAPTCHA the solution? Isn't it trivially defeated with "AI" these days?

    syntaxseed,
    @syntaxseed@phpc.social avatar

    @GossiTheDog Captcha isn't enabled by default??? Omg.

    michael,
    @michael@thms.uk avatar

    @syntaxseed i suspect because you need an api key for captcha, so a bit hard to truly enable by default.

    syntaxseed,
    @syntaxseed@phpc.social avatar

    @michael There really should be some kind of basic one (not by a 3rd party) enabled by default.

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    Now, it does become a bigger problem if the current spammers publish their source code and more join in.

    There’s absolutely no effective controls to stop it - here is the Wild West still - so the elephant is the room is anybody can flip the table at present.

    The good news is much of the anti spam and anti phish technologies over the years (Real time Block Lists etc) can be reworked for here. The bad news is that’s a long way off realistically.

    jonpainterphoto,
    @jonpainterphoto@lawfedi.blue avatar

    @GossiTheDog is this only attacking signups? Or does it lead to accounts auto-spamming if registration is open?

    benroyce,
    @benroyce@mastodon.social avatar

    @GossiTheDog "the elephant in the room is that anybody can flip the table at present"

    it's called a mastodon

    🏃‍♂️

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    Another knock on impact from the spam run - the pictures of spam in the posts are chewing up disk space if file system without deduping is used, and there’s extra Sidekiq load (it’s the biggest Saturday ever on cyberplace.social).

    Also a bunch of instances have gone to failing in federation admin page, presumably because smaller instance admins got annoyed and switched them off.

    renchap,
    @renchap@oisaur.com avatar

    @GossiTheDog or because they are overloaded with the spam + reports

    FinchHaven,
    @FinchHaven@sfba.social avatar

    @GossiTheDog

    Not going to doxx anyone, but this just came down my Home timeline:

    "My instance also got a lot of those spam account requests. But guess what, I didn't approve any of them. It's not the purpose of a instance to grow as large as possible, it is to keep it in the manageable scale.

    I will give some time to the instances sending spam to get it under control before I start suspending whole instances for negligence."

    So, yeah

    "suspending whole instances for negligence"

    Collateral damage, eh?

    Easy to bake up conspiracies, but what might be a potential motivation beyond being mere shit-posting edge lord script kiddies?

    cc @renchap

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    Mastodon has been in deep decline for months (eg active user numbers have halved), but now the metrics are turning around due to one Japanese Discord spammer 🤣

    soupglasses,
    @soupglasses@hachyderm.io avatar

    @GossiTheDog Still -6% tho :blobfoxlaughsweat:

    GossiTheDog, (edited )
    @GossiTheDog@cyberplace.social avatar

    For context on the spam problem, hundreds of Mastodon servers are chucking out thousands of spam messages.

    One example instance: https://opensimsocial.com/public/local

    It’s all one dude on Discord who has realised they can script spam. Thankfully they haven’t published source code. (And yes, they’re really just trolling a Discord server, lolol).

    johnefrancis,
    @johnefrancis@mastodon.social avatar

    @GossiTheDog it's just this kind of thing that keeps cats.mastodon.musk.sucks closed to registration

    haploc,
    @haploc@fedi.cr-net.be avatar

    @GossiTheDog …yet

    alastair,

    @GossiTheDog I had an attempted follow from one and it was a relatively realistic profile. One of the main giveaways was there was far too much content for the time it had been online.

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    An update on the Fediverse spam issue:

    • It’s not just Mastodon.

    • Most of the targets receiving the spam use Misskey, and are in Japan.

    • Most Mastodon users aren’t being targeted, so aren’t seeing it.

    • It is a dispute between two people over a social issue, after asking them about it.

    • It is fully automated.

    • The spam continues to be sent and probably won’t stop any time soon, these guys need to star in a BL drama and make up.

    jupiter,
    @jupiter@mastodon.gamedev.place avatar

    @GossiTheDog

    Sooo it's not possible to just reject federation from any misskey instances?

    Do mastodon instances not have a user agent equivalent when federating content? (goes to read the spec)

    Again, this isn't about killing the infection, it's about getting people isolated until enough masks and vaccines are available. As a species, we should have internalized this by now.

    Oh. Wait.

    cadey,
    @cadey@pony.social avatar

    @GossiTheDog oh god this is just yaoi foreplay in mastodon spam form?

    gabrielesvelto,
    @gabrielesvelto@fosstodon.org avatar
    Marie,

    @GossiTheDog Actually point two is more so

    "Most of the targets receiving the spam use Misskey or a fork of Misskey and communicated at least once with a Japanese user or mentioned a big japanese instance (mostly misskey.io)"

    deborahh,
    @deborahh@mstdn.ca avatar

    @GossiTheDog ok, so they are fighting.

    Why, then, are they messing with our servers?

    Private
    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    If anybody wants another hilarious online dispute issue, back in 2016 two teens had a dispute over Minecraft, so one DDoS’d the Minecraft server’s DNS server - that broke Dyn, which took down internet access across the US East Coast as they were such a key supplier.

    I had to do a radio show on NPR about that one and the presenter kept asking me if it was Putin — and I was like, no, it’s teenagers. Advanced Persistent Teenagers. The show went on for an hour of me just saying ‘yo the net sucks’.

    root,
    @root@sms.cybik.moe avatar

    @GossiTheDog "technology falls to the dick-measuring contest of two teenagers" is a time-honored tradition at this point.

    nogweii,
    @nogweii@nogweii.net avatar

    @GossiTheDog I'd love to find that radio interview; seems like the hosts couldn't handle it wasn't some spooky organization.

    katrintheresa,
    @katrintheresa@cyberplace.social avatar
    aphistic,
    @aphistic@advent.social avatar

    @GossiTheDog Please tell me at some point on the show you said, “And don’t even get me STARTED on BGP!”

    ErosBlog,
    @ErosBlog@kinkyelephant.com avatar

    @GossiTheDog I think "Advanced Persistent Teenagers" are pretty much responsible for messing up that huge indoor Trump rally in Tulsa Oklahoma a few years ago -- the one where the stadium was embarrassingly empty because TikTok kids signed up for all the free tickets.

    tshirtman,
    @tshirtman@mas.to avatar

    @GossiTheDog i'm glad the internet was designed to survive nuclear warfare, i don't know how it could handle bored teenagers most of the time otherwise.

    spv,
    @spv@spv.sh avatar

    @GossiTheDog THAT is why DYN went down???????

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    If anybody wants an update on the Fediverse spam issue - the groups did a ceasefire 5 hours ago (3PM JST).

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    Also, yes, it was a beef over access to a Discord.

    Jonly,
    @Jonly@mastodon.social avatar

    @GossiTheDog still fail to see how the spam aided in that?

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    Mastodon change coming where new servers have open registration disabled by default: https://github.com/mastodon/mastodon/pull/29280

    Mastodon team have been all over behind the scenes btw.

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    Good news everybody, the Fediverse spammer is back! @ivory client filtering it all out for me.

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    Mastodon change incoming in next release, if no mod logs into a server for a week open registrations will close. Will probably take a few weeks but should solve the current spam issue largely. https://github.com/mastodon/mastodon/pull/29318

    jlo,
    @jlo@glib.social avatar

    @GossiTheDog Now I may be a known idiot but this would require a version update yes?

    If so, that would mean whatever % don’t update would still be a possible zombie IF Open Registration is still open on it?

    dracoling,

    @GossiTheDog While I love this change for future installations, updating to the new version with this patch requires interaction, which is exactly what's missing from the servers doing the spamming now!

    grrrr_shark,
    @grrrr_shark@supervolcano.angryshark.eu avatar

    @GossiTheDog of course, this depends on servers getting updated to the latest release in the first place...

    forteller,
    @forteller@tutoteket.no avatar

    @GossiTheDog @glynmoody Good change!

    panda,
    @panda@pandas.social avatar

    @GossiTheDog

    I thought most of the servers of the current spam wave run outdated software, so updates will not hit these servers any time soon or at all

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    deleted_by_author

  • Loading...
  • YesCT,
    @YesCT@mastodon.social avatar

    @GossiTheDog @panda I don't understand. How will the update effect already existing servers?

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    deleted_by_author

  • Loading...
  • YesCT,
    @YesCT@mastodon.social avatar

    @GossiTheDog @panda ah, ok. I think that's what panda was saying.

    patterfloof,
    @patterfloof@meow.social avatar

    @GossiTheDog silly question, but if mods haven't logged in for a week, how are those servers going to be upgraded to the version with this feature?

    aral,
    @aral@mastodon.ar.al avatar

    @patterfloof @GossiTheDog That is a very good question.

    patterfloof,
    @patterfloof@meow.social avatar

    @aral @GossiTheDog I guess there could be version numbers in the protocol & newer servers block feeds that aren't the right version

    but this is me, a programmer spitballing without info

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    deleted_by_author

  • Loading...
  • aral,
    @aral@mastodon.ar.al avatar

    @GossiTheDog @patterfloof Mastodon, however, could still very easily stop accepting traffic from Mastodon servers that are X versions behind. This would be good for the health of the network in general. And when/if those servers upgraded, it could start accepting traffic from them again.

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    deleted_by_author

  • Loading...
  • aral,
    @aral@mastodon.ar.al avatar

    @GossiTheDog @patterfloof Not my circus, not my monkeys. Sadly, I don’t have time in the day enough to contribute to every codebase on the planet. But I’ll keep the idea in mind as a possible feature that we could implement in Small Web apps to ensure we don’t run into the same problem. (Small Web apps auto update anyway but it’ll be a good check to have in case someone has disabled that for their server.)

    stux,
    @stux@mstdn.social avatar

    @GossiTheDog Yeah, that didn't go unoticed

    michael,
    @michael@thms.uk avatar

    @GossiTheDog can’t come soon enough!

    they should push that out as security fix and back port it. Though I appreciate that that might be a bit unusual…

    luc,
    @luc@chaos.social avatar

    @GossiTheDog what's a JST? Jordan? Japan? Java?
    tries to think really hard about other geographical regions' names starting with J

    This is why I like UTC/GMT offsets...

    peturdainn,
    @peturdainn@mastodon.social avatar

    @GossiTheDog Oh I remember that one!
    (mostly because I was using Dyn at the time)

    patterfloof,
    @patterfloof@meow.social avatar

    @GossiTheDog we went from "this system can survive a nuclear attack knocking out many nodes" to "what if we added single points of failure that every site uses"

    brinnbelyea,

    @GossiTheDog A great way to get ahold of classified military technical information is start a dispute about a system like a plane, tank, ship, or missile being over or under modeled in an online video game. The dispute rages until someone gets the real data and posts it. James Bond is now on the dole because his work has been outsourced to raging gamers.

    notroot,

    @GossiTheDog Yup! I got an alarm this morning from my hosting provider that my drive was at 80% used and climbing.

    It was the spam.

    Defederated and blocked for a while. Cleared the file cache. Still above 80%. Deleted my one relay and disabled caching... now it's down to 1% used.

    80%? That's 80GB!!! (I have a 100GB drive)

    dmaonR,
    @dmaonR@mastodon.online avatar

    @GossiTheDog Do you think something like spam-assasin could be converted to filter fedi feeds? or is something tailored to mastodon required?

    thisismissem,
    @thisismissem@hachyderm.io avatar

    @GossiTheDog as far as I know doing plugins in rails applications is particularly difficult..

    ted,
    @ted@an.errant.cloud avatar

    @thisismissem @GossiTheDog Yeah. I mean, i've done internally owned/controlled plugins via Rails engines in the past, but it's not a meaningful security boundary and thus not really... a plugin system.

    tcely,
    @tcely@fosstodon.org avatar
    stefan,
    @stefan@gardenstate.social avatar

    @GossiTheDog 100% agree on plugins. It's sad that core devs have to be a gate keeper for every idea people want when plugins can really outsource the combo of features that are most wanted.

    renchap,
    @renchap@oisaur.com avatar

    @GossiTheDog here are my plans to tackle this, hopefully we will be able to start on it soon: https://renchap.com/blog/post/evolving_mastodon_trust_and_safety/

    szbalint,
    @szbalint@x0r.be avatar

    @renchap

    The pluggable/modular idea is a very nice design, that will be quite helpful.

    However please whatever you do, include an account reputation/lifecycle part in the telemetry. Long-term nothing else will work: ip/email even phonenr are too low level and easily obtainable by bad actors

    gsuberland,
    @gsuberland@chaos.social avatar

    @GossiTheDog unfortunately hCaptcha is garbage for accessibility, despite being touted as the most accessible captcha, and the email-based workarounds they try to use for screenreader folks are apparently just completely broken at the moment so it fully breaks masto sign-up for blind and vision impaired folks.

    jonny,
    @jonny@neuromatch.social avatar

    @GossiTheDog a plugin system for mastodon would be the best thing that ever happened to it, and unfortunately given its design the least possible thing i could imagine happening to it

    wolf480pl,
    @wolf480pl@mstdn.io avatar

    @GossiTheDog captchas might work for this spam bot, but I wouldn't count on them for the long term.

    Outside of fedi, I've seen captcha-solving spambots years ago. Also they took their time, slowly registering sleeper accounts over the span of a year, before using them to send any spam.

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    deleted_by_author

  • Loading...
  • wolf480pl,
    @wolf480pl@mstdn.io avatar

    @GossiTheDog yeah what I'm saying is, my concern are the bots that we might see in a year or two.

    JonnyT,
    @JonnyT@mastodon.me.uk avatar

    @GossiTheDog CAPTCHA is offensively inaccessible, including the supposedly accessible hCAPTCHA. So, no, you should not enable it. You'd be automatically excluding many blind people from joining your instance.

    paul,
    @paul@oldfriends.live avatar

    @GossiTheDog

    Muting 診断メーカー will help the end user from being bombarded.

    There's about a dozen or so more tags but that seems to be the one with the thickest slice of spam on the bread.

    https://oldfriends.live/@paul/111948023571665927

    sysop408,
    @sysop408@sfba.social avatar

    @GossiTheDog either the people behind this have a sense of humor or someone is doing this with the help of an "AI assistant" and instructed it to send spam.

    grumpasaurus,
    @grumpasaurus@fosstodon.org avatar

    @GossiTheDog how many of these instances are instances people set up but then forgot about them

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • kavyap
  • ngwrru68w68
  • osvaldo12
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • thenastyranch
  • Youngstown
  • khanakhh
  • everett
  • slotface
  • tacticalgear
  • rosin
  • normalnudes
  • megavids
  • Leos
  • GTA5RPClips
  • ethstaker
  • InstantRegret
  • cubers
  • modclub
  • Durango
  • provamag3
  • cisconetworking
  • tester
  • anitta
  • JUstTest
  • lostlight
  • All magazines