michael, to random
@michael@thms.uk avatar

Woha, this is unexpected: in a future update mastodon will automatically turn off open registration if no mod has logged in for a week or longer:

https://github.com/mastodon/mastodon/pull/29318

This is great news, and should hopefully significantly cut down on abandoned servers being used to send spam!

(And this is in addition to also having open registrations off by default on new servers.)

Great news!

mods, to internet

We, the moderation and administration of tech.lgbt, are signing the Anti-Meta Fedi Pact in fellowship with our peer communities. (https://vantaa.black/pact)

There is over a decade of precedent that Facebook will not have users' best interests as their guiding principle but rather profit margins, if it joins the Fediverse.

We at tech.lgbt have long held the belief that corporation owned instances are a threat to the core of the Fediverse: freedom for users to be themselves and to be a part of their communities. The 2010s saw the loss of online freedom when the majority of the Web was consolidated into a few destinations, and Facebook entering here could lead us back to centralization. Furthermore, NDAs for server admins will constrain our sovereignty online by binding us legally from disrupting their business.

We are not products. We are people, and we do not welcome Facebook in this space.

menelion, to random
@menelion@dragonscave.space avatar

Re last: Please please please, don't use ! We blind people call it HateCaptcha, and it's for a reason. Their accessibility so-called innovative technology is simply broken and doesn't work reliably. You can't imagine how much time I spent fighting with this so-called accessibility cookie. Please don't use it, for goodness sake.

renchap, to mastodon
@renchap@oisaur.com avatar

After 8 months working on Mastodon, in particular on infrastructure for mastodon.social and mastodon.online, I have been able to articulate my vision for the future of Trust & Safery for Mastodon : https://renchap.com/blog/post/evolving_mastodon_trust_and_safety/

We need better tools to go along the growth of the Fediverse, and they need to enable multiple instances to work together on those topics and keep our loved network safe for everyone!

louis, to fediverse
@louis@emacs.ch avatar

I disagree with the current CEO of Mastodon about his stance on mid-sized instances. We don't want to be run in isolation, we are part of the Fediverse. "Normal users just want the default", he can repeat that as many times as he wants, it doesn't make it true because of that.

Diversity is the DNA of the Fediverse and Mastodon is just one part of the whole. Thousands of people spend their time and money to make it successful. Anyone who dismisses that and single-handedly tries to market the Fediverse as a Mastodon brand and use "crowding out" techniques to prevent users from even being encouraged to choose an instance from a diversity will ultimately fail.

I am super disappointed with the direction Mastodon Corporation is taking. If there is not enough headwind here soon, then sooner or later it will lead to a schism.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

, there’s a pretty serious security vulnerability due to be announced this week. Make sure you apply patches when released on Thursday.

If you’ve never patched, get the process down beforehand.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

My Mastodon server, cyberplace.social, has received a legal threat in an attempt to have a user's thread deleted. It is styled as a cease and desist.

I have published the email here:
https://github.com/GossiTheDog/Cyberplace/blob/main/LegalThreats/Cease%20and%20Desist%20Order%20-%20Felix%20Juhl

michael, (edited ) to random
@michael@thms.uk avatar

PSA: It looks like mastodon.social has implemented hCAPTCHA on their signups yesterday.

So, if you have limited / suspended mastodon.social because of the spam issue, you may wish to reconsider this.

This will also likely mean that spammers will move to different instances (already seeing them targeting mastodon.world).

You may wish to consider implementing hCAPTCHA yourself to protect your own instance, and here is the relevant PR:

https://github.com/mastodon/mastodon/pull/25019

The reason I'm suggesting this, is because if you are a small/medium instance with open registrations, and spammers find and abuse your instance, I imagine that other instances will limit/suspend your instance without hesitation, given how willing some were to limit/suspend the much larger mastodon.social.

But do note this comment on the PR:

“To give some context to people seeing this: this is an emergency feature backport from Glitch SOC to help mitigating an ongoing spam wave, this feature may not make it in a next release, or with significative changes.”

Edited to add: multiple people have rightly commented on the accessibility concerns with hCaptcha: hCaptcha is really really really bad for blind and visually impaired people.

Please have a look at this excellent reply for more details:

https://dragonscave.space/@Mayana/110383119877022255

mookie, (edited ) to fediverse

Can we please stop throwing around the threat of defederation?

Defederation shouldn't happen unless an instance is a cesspool full of terrible behavior with an admin unwilling to deal with it.

Annoyances like spam can be dealt with by admins without scorching the Earth and going nuclear.

Lets not turn the , where instances are supposed to be part of a larger collection, into islands of instances that have cut themselves off from others because of annoyances.

jaz, to trustandsafety
@jaz@mastodon.iftas.org avatar

Please see our latest blog post "Targeted Misgendering and Deadnaming in the Fediverse"

After conversations with GLAAD, we are providing sample language to combat these specific harms, and a pledge to gather and demonstrate support for the community.

Blog post: https://about.iftas.org/2024/01/30/targeted-misgendering-and-deadnaming-in-the-fediverse/

Server Pledge: https://cryptpad.fr/form/#/2/form/view/2Mz2UVcnDmRVjiSwTHJbwTXKUHMXkKz6sx1kc6Vosr4/

@moderation

renchap, (edited ) to mastodon
@renchap@oisaur.com avatar

We just published our first Trunk & Tidbits post! This will hopefuly be a monthly update where we showcase what we worked on last month, and what's coming next.

I hope this will bring more visibility to all the efforts and love that put on Mastodon

https://blog.joinmastodon.org/2024/05/trunk-tidbits-april-2024/

downey, (edited ) to opensource
@downey@floss.social avatar

⚠️ Hey FYI there is a Mastodon security update apparently coming 6 July.

EDIT: Interestingly, the same day launches. Hmm... 🤔

The reason you probably didn't know about it, is because it was only announced* behind a proprietary centralized paywalled garden. (Not Twitter, but the same effect.)

Be ready.

  • This is not a recommended way to run an community.
Gazimoff, to random
@Gazimoff@gamepad.club avatar

If you run a Mastodon server, especially if it's small and only lightly moderated, I would STRONGLY suggest enabling 'Approval required for sign up'. It means that your server is MUCH less likely to become the next source of spam in this wave we're seeing.

markwyner, to mastodon
@markwyner@mas.to avatar

Some words about Mastodon moderation:

  1. It’s hard. No decision is easy and there’s lots of gray area even with explicit rules.
  2. We’ll sometimes debate for a long time on a single post. We do our best to make the right call.
  3. Even so, we sometimes make mistakes. We’re willing to accept appeals when that happens.
  4. We get a lot of things right. You can’t even imagine some of the traumatic things we see.

1/5

sam, to random
@sam@urbanists.social avatar

Introducing Citadel! Citadel makes it quick and easy to suspend spammers and send reports to their admins - in one click!

Eventually Citadel will have more tools, but I wanted to get this out ASAP to help server admins.

Give it a shot: https://citadel.samw.dev

(also note that after you log in you will ned to reload the page)

video/mp4

renchap, to random
@renchap@oisaur.com avatar

Hugops to every other having to deal with this spam wave. We have been fighting is on mastodon.social for days, and were forced to close registrations yesterday until we could emergency-deploy countermeasures.
Unfortunately, this made them realise they are other servers in the Fediverse to target.
If any admin needs help fighting this, please ping me either on the server admin discord, or directly here, and I will gladly help.

paul, to random
@paul@oldfriends.live avatar

Users and friends, filtering hashtag 診断メーカー works to keep the current wave of spam out of your timeline, mentions, etc, as this example shows.

Over 4.4K in the last 24-hours. I know many admins have been combating it all night to keep it out of your timeline.

Might not be a bad idea to set the filter up while 's combat the problems.

If you're not curious, hide completely instead of just a warning as shown in the red circle..

timeline showing spam behind a hidden
timeline with a hidden post exposed

r000t, to random
@r000t@fosstodon.org avatar

YOUR MASTODON SECURITY UPDATES (probably) AREN'T (quite) DONE YET

There were changes to the default nginx conf. This obviously doesn't get updated when Mastodon does.

Just add these lines to your nginx configs. Reload nginx. You're done.

https://github.com/mastodon/mastodon/commit/fed9cbfd2ba8db8bffb03f554c24d83b6f8aa059

renchap, (edited ) to random
@renchap@oisaur.com avatar

Question for Mastodon Admins: are you using the REDIS_NAMESPACE configuration variable?
If yes, can you reply and explain why you are using it?

We will need to drop support for it, as Sidekiq no longer supports it, and I want to be certain we understand every usage to prepare a migration guide.

dominik, to random German

Ihr wollt wissen, was so ungefähr rechtlich zu beachten ist, wenn man in Deutschland eine Mastodon Instanz betreibt?

Hierfür hab ich für eine Vorlesung eine Seminararbeit geschrieben mit 16 Seiten und etwa 35.000 Zeichen, die ich hier nun veröffentliche.

Keine Garantie auf 100%ige Richtigkeit, bin schließlich auch nur ein Informatik Bachelor Student, habe aber auf jeden Fall mein Bestes gegeben. 🙂
Einfach wars definitiv nicht. 😕

Link (eigene Cloud): https://seafile.do-m-inik.at/d/b307f5ebf5784c1ab7a7/

rolle, to fediverse
@rolle@mementomori.social avatar

During my one year activity on the I've now seen at least four instance admins quitting from being an admin or shutting down their server. Half of these cases were admins being dickheads and the rest of them were mostly about users being dickheads leading admin getting burned out.

Both outcomes are unfortunate, but the latter makes me sad. Why do we have to harass and doxx an admin here for such pseudetical reasons like extensive open text search feature? I don't get humans sometimes.

I repeat: We are not free from toxicity on the Fediverse. Be kind. Make a chance.

ordnung, (edited ) to random
@ordnung@chaos.social avatar

If you have used a mail account that is registered via outlook.com or another service provided by Microsoft to register on chaos.social, you won't receive mails anymore because they blocked us or the whole network of our provider (again). We will not fix it this time, change your mail provider to someone less annoying.

EDIT: PLEASE! Stop writing us that you hate MS, this was an info to our users not the start of a discussion.

cappy, to infosec
@cappy@fedi.fyralabs.com avatar

im getting really tired... -w-

summary of today:

someone on a Japanese hacker forum decided it was a good idea to spam the entire Fediverse because they wanted to cancel a minor that DDoSed a Discord bot which apparently made them lost millions (what?)

A Discord bot. I can't make this shit up man.

The real culprit seems to be someone who goes by mumei in the ctkpaarr.org forums, whose first post was literally a threat to ap12, that if they don't delete their "Kuroneko Server" Discord bot, they will spam every blog, forum and SNS and cancel him.

This shit is ridiculous.

The ap12 account from mastodon-japan was actually fake, and this dude impersonated a minor to get all of the Fediverse (us) to bully him.

The forum admins didn't even stop this. Why? lulz apparently.

kc, to random
@kc@chaos.social avatar

The Mastodon development team currently suggest enabling in order to combat the current spam wave in the fediverse.

However, hCaptcha discriminates genuine users with disabilities from accessing your instance. So if people and inclusion are important to you, please just don't. Consider closing your public registrations instead, for the time being.

Additional info is on the thread 🧵

leigh, (edited ) to random
@leigh@ottawa.place avatar

Currently sleeping the sleep of the righteous, @andrew was up way too late building tools to fend off the current wave of fedi spam, playing whack-a-mole with bad accounts, and getting fedi friends up and running with their own blocklists.

I’d like to convene a discussion this week or next to do a mini retro on this attack and some work around fedi spam fighting tools. If you’re interested in the discussion, @ me your email or send one to spamretro at hypatia dot ca and I’ll loop you in on it 🙏

Would love to have a proper UR/UX person on the call, I’m a mere amateur at that part 😅

Edit to add for reach 🚀

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • rosin
  • modclub
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • khanakhh
  • osvaldo12
  • tacticalgear
  • Youngstown
  • everett
  • slotface
  • kavyap
  • anitta
  • thenastyranch
  • mdbf
  • tester
  • GTA5RPClips
  • provamag3
  • Leos
  • Durango
  • ethstaker
  • cisconetworking
  • normalnudes
  • megavids
  • cubers
  • lostlight
  • All magazines