#fedimod

12 posts · Last used 15d

Boosted by @fedicat@pc.cafe
Quick heads-up for other Mastodon admins: this registration spam wave isn't over yet. On lsbt.me, we first saw a flood of API registrations using Python/aiohttp. The telltale signs were usernames following the pattern bp plus 16 hex characters, and the sign-up reason was always "Automated protocol deliverability probe". A narrow block on that user agent stopped the first wave. Today, however, five new registrations came in with the same usernames and the same sign-up reason. This time the bot simply identified itself as Chrome 126. That's exactly why a user agent is only useful as a short-term filter. It's a header the client can set to anything. The requests go to POST /api/v1/accounts. This endpoint lets client apps create a new local account directly in the app. No app needs it for OAuth connections to existing accounts. #FediSuite doesn't use it either. It registers itself via /api/v1/apps, obtains consent via /oauth/authorize, and then works with a user token. Regular sign-up through the Mastodon website is also handled separately via POST /auth. So I've completely disabled API account creation on lsbt.me. Web sign-up, OAuth, and existing clients keep working as before. Anyone who wants a new account just signs up once on the web as usual and can then use any client. If you'd also rather not offer this optional native sign-up path, you can add the following to your Nginx server block, before the general location / block. The example assumes the @proxy location that many Mastodon Nginx configs already include: location = /api/v1/accounts { limit_except GET { deny all; } try_files $uri @proxy; } This returns a 403 only for POST /api/v1/accounts. The read-only GET endpoint remains reachable. As always, run nginx -t afterwards and only reload once the test passes. #Mastodon #Fediverse #MastoAdmin #FediAdmin #FediMod #FediBlock #Moderation #Registration #Spam #Nginx #SelfHosting #SysAdmin #ActivityPub
0
1
6
0
Modmins, it might be time to review ur accounts panel. Some of the more reg serial spammers and bigots are on school holiday or something. We smooshed a few more of the "just five" accounts from Linux is Best, cleared some fediblock spammers. Seems some boys just can't stand being ignored. Also reached out to some instances to ask them their plan for handing the recent spam from their ends. We still think the best plan is not allowing automatic reg. #FediMod #FediModerator #FediAdmin
10
3
13
0
For instances struggling with icky people trying to sign up... our extra step during sign-ups is working as intended. As we suspected, filling out the application is enough of a barrier that trolls and spammers are mostly weeded out. Does it reduce possible sign ups? Probs. Does it create more work? A little. But it means that we have a better idea of who ends up on the Speakeasy. We def recommend giving it a try. #FediMod #FediModerators
10
0
6
0

The Speakeasy uses a two-step process to approve applications, bc "just" turning on approvals doesn"t give us enough info to decide if the person applying is legit. We sort of had a hypo that two step apps would help us catch spam and trolls and so far... it is working!

Stats:

  • 2 scam troll accounts using throwaway email
  • 1 spam account
  • 1 approved
  • 2 pending reply

Eventually, we will fail and let someone in who doesnt vibe. That's just facts. But mostly, requiring enough to get a feel for ppl is working well.

We're of course going to revise as we go, but... for admins and mods who are frustrated with the limits of Masto sign up options... u might want to consider two step sign ups too!

Let us know if u want to chat abt, we're here to help.

#FediMod #FediModeration #FediAdmin

4
2
4
0
Let's see what platforms are responding to this year's Social Web survey, the annual questionnaire to see how #FediAdmin and #FediMod folks are doing: #Mastodon 54 #Matrix 17 #PeerTube 15 #WordPress 10 #Pixelfed 9 #ATProto platform 8 #Lemmy 8 #Pleroma 8 #Bookwyrm 6 #GoToSocial 5 #Bonfire 4 #Gancio 4 #Sharkey 4 #Writefreely 4 #Akkoma 3 #Friendica 3 #Ghost 3 #Mobilizon 3 #Nostr platform 3 #Funkwhale 2 #Hometown 2 #Misskey 2 #NodeBB 2 #Hubzilla 1
2
2
31
0
Let's see what platforms are responding to this year's Social Web survey, the annual questionnaire to see how #FediAdmin and #FediMod folks are doing: Mastodon 54 Matrix 17 PeerTube 15 WordPress 10 Pixelfed 9 ATProto platform 8 Lemmy 8 Pleroma 8 Bookwyrm 6 GoToSocial 5 Bonfire 4 Gancio 4 Sharkey 4 Writefreely 4 Akkoma 3 Friendica 3 Ghost 3 Mobilizon 3 Nostr platform 3 Funkwhale 2 Hometown 2 Misskey 2 NodeBB 2 Hubzilla 1
0
1
28
0
We're reviewing the below comment and follow-ups from the admin of burnout.cafe. We're probably going to open discussion within the Speakeasy on how to proceed (the instance users on burnout aren't at fault), but we strongly condemn the premise that "gay pornography" needs to be singled out for removal. Our thoughts: The admin(at)burnout(dot)cafe call for a ban of "gay pornography.". We believe this to be a homophobic position as it singles out the LGBTQIA+ (Rainbow Panopoly) community for a behavior that is implied to be "less problematic" if heterosexuals do it. To be crystal, sex is natural and healthy and we will not shame our members or anyone on the fedi for enjoying or sharing it. We esp will not be singling out particular sexualities for censure. The comments from the admin compare gay pornography to execution and gore videos. We believe the comparison of consensual sex to non-consensual violence and graphic injury super offensive; it suggests that non-het sex is somehow wrong. -- So we are not misunderstood, we do not believe that blocking porn allowing instances on a SEXUALITY NEUTRAL basis is homophobic. But to single out the LBBTQIA+ community specifically is, in our opinion, because it targets us not because we post sex, but because we're not hetero. #FediMod #FediModeration #FediBlock #LGBTQIA @admin@burnout.cafe https://burnout.cafe/@admin/116857804772538444
13
4
4
0
You've seen all posts