Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Emelia 👸🏻
@thisismissem@hachyderm.io  ·  activity timestamp 3 months ago

Mastodon Moderators: If you've had this verification scam/spam happening from accounts on your server, would you mind sharing with me privately the IP address and other details of the account?

I'm trying to compile information on this attack (we don't have any of this data from Hachyderm, because we've approval based registrations due to LLM spam)

I've been able to pull together information on the different domains and text of the spam messages being used, but not much in the way of account details.

(Yes, this data is PII, and I promise to handle it responsibly)

#moderation#trustandsafety

  • Copy link
  • Flag this post
  • Block
Daniel Cid
@dcid@noc.social replied  ·  activity timestamp 3 months ago
@thisismissem None of ours as well (we require registration approval).

Would be nice to have a central repo to share those things, so we can help contain those spam botnets.

  • Copy link
  • Flag this comment
  • Block
Emelia 👸🏻
@thisismissem@hachyderm.io replied  ·  activity timestamp 3 months ago
@dcid eventually that's what my FIRES project can handle: https://fires.fedimod.org

Although I may also develop an evidence collection system for Mastodon, which would make gathering data across instances much easier.

  • Copy link
  • Flag this comment
  • Block
Daniel Cid
@dcid@noc.social replied  ·  activity timestamp 3 months ago
@thisismissem very nice, if we can help let us know.
  • Copy link
  • Flag this comment
  • Block
RodolfoRG
@rodolforg@mastodon.online replied  ·  activity timestamp 3 months ago
@thisismissem I wonder if anything could be done like checking profile photo and name containing mastodon icon/word to prevent it
  • Copy link
  • Flag this comment
  • Block
Varx
@varx@defcon.social replied  ·  activity timestamp 2 months ago
@rodolforg @thisismissem I wonder if some sort of client proof-of-work cryptographic stamp for private post mentions could help make it unprofitable for mass spam?
  • Copy link
  • Flag this comment
  • Block
Emelia 👸🏻
@thisismissem@hachyderm.io replied  ·  activity timestamp 3 months ago
@rodolforg not particularly. We do have some heuristics we look for and use, but these spam attacks are fairly sophisticated.
  • Copy link
  • Flag this comment
  • Block
Matt ⁂ 🇳🇴 🇺🇦
@matt@oslo.town replied  ·  activity timestamp 3 months ago

@thisismissem Fortunately no accounts created on my server (yet), but I am making sure that when I see and find these spam accounts, I am creating a report for each one and forwarding it to other servers, rather than just suspend the account on mine through the admin panel.

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.13 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login