Please report any account that claims that you need to verify your #Mastodon account to continue using it. It is a scam. Don't click the links. Real staff accounts either have a special role badge on their profile or are verified through the joinmastodon.org domain.
reshared this
Mastodon.social Staff
in reply to Mastodon.social Staff • • •reshared this
Debbie Goldsmith ๐ณ๏ธโง๏ธโพ๏ธ๐บ๐ฆ, Mastodon, stuxโก, António Manuel Dias, Rokosun and Franz Graf reshared this.
Pam C
in reply to Mastodon.social Staff • • •Petra van Cronenburg
in reply to Pam C • • •Pam C
in reply to Petra van Cronenburg • • •Stefan
in reply to Mastodon.social Staff • • •stuxโก
in reply to Stefan • • •@stefan Oh thats a nice one!
Or maaaybe some sort of REGEX filter on signup? Since they seem to use a pattern maybe
Martin Dougiamas
in reply to Mastodon.social Staff • • •Emelia ๐ธ๐ป
in reply to Martin Dougiamas • • •Martin Dougiamas
in reply to Emelia ๐ธ๐ป • • •Emelia ๐ธ๐ป
in reply to Martin Dougiamas • • •@martin so the spam waves we're seeing are quite advanced and adaptive, it's not like the script kiddie spam from last year.
With this spam wave, I'm still analyzing the data, but:
- we've seen at least 13 different domains used for the phishing site
- we've seen them using CWs when spamming publicly
- we've seen them use multiple different scripts (what's written), including multiple languages
Regexp and publicly available lists of data are not something that would particularly help, as as soon as you publish & block keywords or domains, the attack changes.
If a server admin is not vigilant, then they should not have open registration (ex. Mastodon.social), but there's servers out there that are several versions out of date, so they don't get any of the new mitigation features or warnings (there's a big warning about open registration in the admin panel since 4.3.x)
Ben Royce ๐บ๐ฆ ๐ธ๐ฉ
in reply to Emelia ๐ธ๐ป • • •@staff
would limiting rate of posts for new accounts help?
so you make a new account, you only get 3 posts on your first day for example
but... they'll just register and go dormant for a period of time
no, you could still do it:
rate limit number of first few posts, no matter account age
so... they post innocuous garbage to get past that hurdle
but that's still useful
put up these kinds of barriers to make spamming hard, while not interfering with regular users
Gabriel H. Nunes
in reply to Mastodon.social Staff • • •Your account isn't yet verified in any way, though.
#Mastodon #MastodonSocial #MastodonOnline
Cainmark Does Not Comply ๐ฒ
in reply to Gabriel H. Nunes • • •Good catch.
Mastodon.social Staff
in reply to Cainmark Does Not Comply ๐ฒ • • •Gabriel H. Nunes
in reply to Mastodon.social Staff • • •@cainmark
Thank you for that information! I'm on mastodon.social, but I'm usually on a third-party app, #Fedilab, which doesn't show badges, so domain verification is still important.
On that, why not verify through mastodon.social and mastodon.online instead of joinmastodon.org?
#Mastodon #MastodonSocial #MastodonOnline
Fedilab Apps
in reply to Gabriel H. Nunes • • •At least, when opening the profil remotely, you should see the badge with Fedilab. So there is an issue on our end. Bookmarked for a fix.
@staff @cainmark