Post (mostly) for instance admins: spam / sleeper account registrations
Our server, with approved registrations (i.e. mods only accept new people after checking their "reasons to join") is still constantly getting spam account requests. (spam, for lack of a better word... maybe 'sleeper accounts'?)
These are not obviously immediate to the untrained eye, but it's been happening for months now and there are some clear patterns. Here's a list of what I've learned so far in case that's useful to other mods. Any additional advice welcome!
How to spot a sleeper account request (beyond the obvious):
- Always from a disposable email domain.
- Otherwise, a lot of them are from "proton.me" domain or "onionmail.org"
- request reads as if it was an account description, not an account request e.g. "writer, queer, loves cats, profile pic of a lake in front of a mountain, posts a lot about bread, here to share ideas and engage positively with the community, my DMs are open" - yeah it sounds like your average Fedi person, but that's probably because they scrape profiles from Fedi in the first place.
- The account request will not directly name your server or meaningfully answer the account request text
- The name of the account and of their email will have nothing to do with each other, e.g, username "colixal" and email "inyfupvtr@proton.me"
- the email usually looks random (see above), probably because they're all randomly-generated.
Solutions / mitigation (for Admins):
- Switch on approved registrations on your server! @FediTips has instructions for this.
- Tell in your server's account request description that you do not accept registration from disposable emails and you want specific reasons for choosing your server.
- How to spot a disposable email domain: you can check this list, but I don't think it's up to date. you can also search for the domain with quotes "domain.xyz" online and it will usually show up as being disposable.
- Once you know a domain is disposable, you can block registrations from it (User Preferences menu>Moderation> Blocked email domains > add new)
- in doubt, email the "person" to ask them more specific info. 50% of the time the email will bounce back, and 40% you will get no answer. That's your cue to reject those (and possibly add their domain to the block list, although you don't want to block non-disposable ones of course)
- requesting a donation, even minimal (say 10p per account) would probably completely block those.
- It is possible that we've already accepted a few of the sleeper accounts. We should all probably go back and check everything out (yes, that's easier when you have a small server).
- Any other suggestions / tips? Let us know!
Of course, some of these measures are bound to also prevent some genuine people from joining. In this case I think it's worth it, and also, if you can't be bothered writing 3 lines of text to explain why you chose a server then maybe you wouldn't be contributing to Fedi much anyway.
Quantification
We are a very small server (150 active accounts) and are getting about 1-3 such requests per day when our usual rate of genuine requests is about 1-2 per month (well, except when @jonny makes a post that pierces the thin veil with the real world). I can't imagine how many of those must be infiltrating large, open instances like mastodon.social... Have any of you people on other servers noticed it? Please let us know in answers. And if anyone personally knows one of the mastodon.social mods it would be interesting to hear from their point of view.
Possible goals and consequences
- wasting our time
- making it harder for genuine people to join
- sudden spamming
- use all the server's storage to block the server
- propaganda
- harassment (possibly in private posts so they can't be reported)
- anything else? In any case, no good can come out of it.
Other posts noticing this
quoting @johannab:
https://cosocial.ca/@johannab/116856878972351914
quoting @dsalo:
https://digipres.club/@dsalo/117039864558262328
quoting @tante:
https://tldr.nettime.org/@tante/116845372717559528
quoting @jerry who mentioned making a script to auto-block the disposable domains - I don't know if this exists now?
https://infosec.exchange/@jerry/116805164892680867
and
https://infosec.exchange/@jerry/116846097736300539
quoting @futurebirds@sauropods.win:
https://sauropods.win/@futurebird/117161690843829586
PS: If you answer please un-tag all these nice people to avoid spamming them!
#MastoAdmin #MastoAdminTip #FediAdmin #AcountRequests #SleeperAccounts #SpamAccounts