Gargron,
@Gargron@mastodon.social avatar

There is an ongoing spam attack on the fediverse for the last couple of days. It's more widespread than before, as attackers are targeting smaller servers to create accounts. Before, usually only mastodon.social was targeted and our team could take care of it. For server administrators out there: If you don't need open registrations, switch over to approval mode. If you do, blocking disposable e-mail providers is a massive stopgap to the problem. Mastodon also supports hCaptcha.

collectifission,
@collectifission@greennuclear.online avatar

@Gargron hCaptcha is problematic. I'm sure you're aware of this github issue: https://github.com/mastodon/mastodon/issues/25023

It's becoming a harder sell that this is an "emergency feature implementation" 9 months after the issue was opened.

objectinspace,
@objectinspace@freeradical.zone avatar

@collectifission @Gargron +1 have seen multiple reports of blind people being locked out due to HCapcha. Respectfully, Throwing your disabled users under the bus when they're inconvenient is not being a good ally.

thomas,
@thomas@metalhead.club avatar

@Gargron I honor every line of code that your team and you produce to maintain Mastodon.

But what I really miss as an instance administrator is some sort of spam detection. We have tools and libraries for that, e.G. for simple naive bayes detection.

Maybe it will not be 100 percent precise, but it would help a lot of Mastodon could block / delay suspicious posts based on simple machine learning mechanisms (like we have them for email).

tramtrist,
@tramtrist@famichiki.jp avatar

@thomas @Gargron didn’t @dansup implement this in

thomas,
@thomas@metalhead.club avatar

@tramtrist yes, he did :)

@Gargron @dansup

HikerGeek,
@HikerGeek@mas.to avatar

@Gargron

Any thought on developing a federated anti-spam system? If one instance blocks an email or domain it propagates to the servers that choose to federate with its anti-spam so that email or domain can't be used on other servers.

Sibshops,
@Sibshops@mstdn.games avatar

@Gargron If you want to encourage servers to switch to manual approval. Maybe switch the order on joinmastodon.org to put the servers that require manual approval ahead of the open servers? By putting the open servers first it appears joinmastodon.org is endorsing open registrations.

fraying,
@fraying@xoxo.zone avatar

@Sibshops @Gargron
👆 THIS 👆

joenepraat,
@joenepraat@todon.nl avatar

@Gargron Still the problem is Mastodon. See https://github.com/mastodon/mastodon/discussions/29267.

Please see these issues (two of them are created by me and are related) as well:

Require blocking of disposable email providers and/or require a captcha provider when registrations are open

https://github.com/mastodon/mastodon/issues/29270

Set new registrations on new servers to manual approval by default

https://github.com/mastodon/mastodon/issues/29269

Ability to greylist new servers

https://github.com/mastodon/mastodon/issues/29266

Ability to use heuristic spam filtering tools

https://github.com/mastodon/mastodon/issues/29265

Instance-wide filtering

https://github.com/mastodon/mastodon/issues/29256

cc @renchap

ThaMunsta,
@ThaMunsta@nervesocket.com avatar

@Gargron it needs to be easier for moderators to find report and suspend accounts or instances that are compromised. It's hours of clicking to do it "properly" right now and I don't have a full time staff - it's just me doing clean up 🥲

sam,
@sam@urbanists.social avatar

@Gargron If you could like... idk... actually write software or something?? to make moderation easier??? that would help a fuckton. or approve the MRF??

downey,
@downey@floss.social avatar

@sam To be fair there are like 5+ years of ignored admin/moderation improvement requests in the queue 😅

ErikUden,
@ErikUden@mastodon.de avatar

@Gargron More methods to stop the ongoing attack:

https://mastodon.de/@ErikUden/111940301222380638

ipg,
@ipg@wetdry.world avatar

@Gargron will there be at least discussions on improving the moderation capabilities in Mastodon so server admins (both victims and passer-bys) can more easily manage these attacks?

hexaheximal,
@hexaheximal@mastodon.social avatar

@ipg @Gargron there are! :)

@Jain made a feature request for MRF: https://github.com/mastodon/mastodon/issues/29252

nopewafl,

@Gargron An example of "It is your fault if you are be blocked by the fediverse if you do not secure you instance to avoid spam."

progressivecat,

@Gargron @GottaLaff Everything sounds good except, please, please, please no Hcaptcha. Hcaptcha is a pain for people who are blind.

loosenut,
@loosenut@genart.social avatar

@Gargron

Please send help 🙏

brights,
@brights@zhub.link avatar

This is really like:

  • We have a dude that is registering many accounts on abandoned old servers and is spamming all users. What we can do?!

  • We urge admins of OTHER, not abandoned servers, to close registrations! (or enable captcha, approval etc.)

  • What?! 🥴

@Gargron

mcdanlj,
@mcdanlj@social.makerforums.info avatar

@brights Speaking as the admin of a definitely not abandoned, previously-open-registration instance, not all of them have 24/7 admin coverage to handle spam reports. I had a flood while I was asleep, and I took care of them in the morning and changed to requiring approval with a reason. Then last night another similarly actively maintained server I know of was attacked in the same way and made the same change this morning. I'm sure there are others too; I'm just reporting what I know from my tiny corner of the fediverse.

So, why not start from an assumption that people aren't idiots? Turns out there are a lot of people here who actually know what they are doing.

Just because abandoned servers are highly visibly affected because no one is eventually cleaning up the mess doesn't mean that only abandoned servers are affected.

brights,
@brights@zhub.link avatar

@mcdanlj
> So, why not start from an assumption that people aren't idiots?

I didn't assume this, Gargron did. Because I closed the registration on my server about 24 hours ago, right after the wave started. I assumed that every "not stupid" admin on not abandoned server would do the same without a message from Gargron, right?

So, my assumption was - those servers, that are not switched to closed/approved/captcha enabled registration mode, are the source of the issue.

This was the first.

Second:
Closing registration or enabling captcha on not-abandoned servers WILL NOT solve the issue for the Fediverse because of those abandoned, but actively spamming servers.

The proposed "solution" is just a small mitigation at best :(

mcdanlj,
@mcdanlj@social.makerforums.info avatar

@brights You are the one calling it a solution. Everyone else seems to agree that it is a mitigation. You are reading a lot into what Gargron said that I don't think is there...

keyasen,

@Gargron Man. City-Brentford, the review: data, information, date, time, and television of the Head Association match
Watch Now: http://tinyurl.com/y5et47cw

kura,

@Gargron I am not hosting an open (mastodon) instance, but is there a public disposable e-mail provider list?

faylen,

@Gargron HCaptcha is a bad idea. I wish they'd use something different. It can block screen reader users when their cookie system fails to work the way it's supposed to.

louis,
@louis@emacs.ch avatar

@Gargron We've already had to limit over 50 domains and it looks like some instances are created only for the purpose of this attack. This exposes a vulnerability of Mastodon in that admins have no way to prevent incoming spam other than after the fact.

So if you know of any tool or option that would enable receiving instances to keep this in check, please let us know.

beatricejess,
@beatricejess@masto.bike avatar

@alter_unicorn
Plutôt que de bloquer les domaines, est ce qu'il serait possible de bloquer les fournisseurs de mails jetables ?

mate,
@mate@3615.computer avatar

@beatricejess @alter_unicorn

C'est quoi le problème des fournisseurs de mails jetables ? À l'époque (circa 2013) c'était le feu !!!

EDIT : Je viens de lire le toot original, je comprends mieux. Merci

project1enigma,
@project1enigma@wandering.shop avatar

@Gargron Captchas are still an accessibility nightmare. I'll die on this hill.

KevinMarks,
@KevinMarks@xoxo.zone avatar

@Gargron given that the spam is mainly the same images, could you hash them and use that as a rejection filter?

4censord,
@4censord@unfug.social avatar

@KevinMarks @Gargron Assuming they use the exact same image, possibly. But if they even so much as slightly change the image (e.g., convert to another format, change some colour mapping etc) then it won't work with traditional hashing.
There exist hashing methods that work on visual similarity, but those are more complicated, and significantly harder to get right.
Also, more vulnerable to false positives, and worse catch rate.

brawaru,
@brawaru@mstdn.social avatar

@4censord the images are indeed always different in hash because each instance also has its own image quality settings, as far as I understand. however the images that I have tested have about 99.9% visual match, so would easily be qualified as the same, and thus as spam

@KevinMarks @Gargron

galacticstone,
@galacticstone@mastodon.social avatar

deleted_by_author

  • Loading...
  • Gargron,
    @Gargron@mastodon.social avatar

    @galacticstone No, not at all related.

    LibrarianRA,
    @LibrarianRA@worldkey.io avatar

    @Gargron my account is getting tagged in about 20-30 a day. If this keeps up , I have little choice then to leave . I’m reporting more spam than engaging with followers . It’s exhausting 😮‍💨

    EverydayMoggie,
    @EverydayMoggie@sfba.social avatar

    Try turning on these settings. The spam always has direct mentions, so it should help some.

    @LibrarianRA @Gargron

    LibrarianRA,
    @LibrarianRA@worldkey.io avatar

    @EverydayMoggie @LibrarianRA @Gargron Thank you , but most of these won’t work for my page. Turning some of them off won’t allow me to interact with the over 3.k followers of this page. It also doesn’t stop the spam. I hope they can do something soon . I’ve had another 10 in the last hour . 🫠

    DavidTanner,
    @DavidTanner@toot.wales avatar

    @LibrarianRA @Gargron It’s bizarre as I haven’t seen a single spam. I assume @jaz is working overtime keeping toot.wales spam free 🤷‍♂️

    jaz,
    @jaz@toot.wales avatar

    @DavidTanner @LibrarianRA it's all our fantastic @teamtoot staff and a lot of experience managing a busy service. Please do (if using Mastodon) go to your notifications preferences eg https://toot.wales/settings/preferences/notifications and review "Other Notification Settings" to minimise spam notifications and messages.

    bullshitter,

    @Gargron Oh Yeah..
    If they are attacking surely there's some good going on here.

    shved,
    @shved@mastodon.social avatar

    @Gargron Does duckduckgo email masking count as disposable email?

    Avvielanche,
    @Avvielanche@mstdn.social avatar

    @Gargron well that sucks because I use Protonmail and DDG's email masker because fuck google. I hope this doesn't mean that only massive, centralized corporate mail servers are acceptable

    condalmo,
    @condalmo@mstdn.social avatar

    @Avvielanche @Gargron Yes, don't block Proton

    @protonmail

    protonmail,
    @protonmail@mastodon.social avatar

    @condalmo Hi! Can you give us some more details? Have you experienced issues with Proton Mail being blocked while trying to use your email to register to some website or similar?

    condalmo,
    @condalmo@mstdn.social avatar

    @protonmail No, not recently at least. I just wanted to mention it so that admins trying to corral the spam flood don't block Proton addresses

    protonmail,
    @protonmail@mastodon.social avatar

    @condalmo Thanks!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • kavyap
  • thenastyranch
  • mdbf
  • DreamBathrooms
  • everett
  • magazineikmin
  • GTA5RPClips
  • Youngstown
  • cisconetworking
  • ethstaker
  • slotface
  • ngwrru68w68
  • rosin
  • cubers
  • JUstTest
  • InstantRegret
  • Durango
  • osvaldo12
  • modclub
  • tester
  • Leos
  • khanakhh
  • normalnudes
  • tacticalgear
  • megavids
  • anitta
  • provamag3
  • lostlight
  • All magazines