It's Just Me

@me@mysmallinstance.homelinux.org

It's just me, posting from this brand new instance. No faces or physical descriptions here. This account will remain an abstraction of ideas and thoughts, something ethereal, devoid of physicality. I'm the one you'll read here, you'll hear here.

I'll be trying to bring some positivity and hope to the Fediverse.

To you who are reading this bio, thank you for stopping by, and have a nice day!

Profile Image by Marnhe Du Plooy on Unsplash
Banner Image by Johannes Plenio on Unsplash
18 ★ 2 ↺
Φου boosted

It's Just Me »
@me@mysmallinstance.homelinux.org

Flooded by spam. But this will continue to be my small, cozy instance, full of positive feelings 🙂

...
It's Just Me boosted

Spoofy »
@spoofy@mastodon.com.pl

@me Nothing can stop positive energy! 😍

Keep it up! 💪

If you need help, let me know and I'll be happy to help!

...
It's Just Me boosted

Łukasz Wójcik 👨‍💻 📷 »
@lukem@hachyderm.io

@me take it as a confirmation your instance is indeed federated and recognized as a legitimate actor in the ecosystem 😄

...
technicat boosted

Alexander Reisach »
@Scriddie@mathstodon.xyz

@lukem @me I receive spam, therfore I am.

It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

Sun is Setting on a Silent Sunday

A serene rural landscape at sunset. The sun is low on the horizon, casting a vibrant orange glow across the sky. Silhouettes of trees with bare branches stand out starkly against the bright background, some reflected in the still waters of a small pond in the foreground. The water mirrors the warm colors of the sky and the tangled web of branches overhead. 
The atmosphere is peaceful and slightly misty, which adds a dreamy quality to the scene.
...
It's Just Me boosted

Eugen Rochko »
@Gargron@mastodon.social

There is an ongoing spam attack on the fediverse for the last couple of days. It's more widespread than before, as attackers are targeting smaller servers to create accounts. Before, usually only mastodon.social was targeted and our team could take care of it. For server administrators out there: If you don't need open registrations, switch over to approval mode. If you do, blocking disposable e-mail providers is a massive stopgap to the problem. Mastodon also supports hCaptcha.

...
Older...

Sarah A »
@ke7zum@mastodon.cc

@Gargron Yep, my instance is set to approvals and I did only see one. they are getting ignored.

Emma »
@ipg@wetdry.world

@Gargron will there be at least discussions on improving the moderation capabilities in Mastodon so server admins (both victims and passer-bys) can more easily manage these attacks?

...
Older...

Cedara 📖🍵🤍 »
@Cedara@social.tchncs.de

@ipg @gargron Yes, please, users and admins need finer tools to block spam, especially if those smaller instances don't seem to administrate well enough and still run on old versions.

kim wulff »
@kimwulff@krigskunst.social

@Gargron @anderspuck Tænker du har styr på det.

...

Anders Puck Nielsen »
@anderspuck@krigskunst.social

@kimwulff Det vil jeg mene. Men hvis du begynder at se underlige opslag på den lokale tidslinje, må du meget gerne sige til. Der er nogle af dem som anmoder om en konto, hvor det er svært at gennemskue hvem de er.

...

kim wulff »
@kimwulff@krigskunst.social

@anderspuck Det skal jeg gøre. Har støt på nogle fra andre server , som ikke er ret rene i kanten hvis man lige går i dybden, men du skal få det at vide hvis jeg opdager noget.

...

Anders Puck Nielsen »
@anderspuck@krigskunst.social

@kimwulff Ja, dem på de andre servere behøver du ikke at rapportere til mig. Så bliver jeg lagt ned af arbejde. 😅

...

kim wulff »
@kimwulff@krigskunst.social

@anderspuck Nej nej det gør jeg heller ikke 😅😅😎😎😎😇 vi kan jo ikke ha at stats ansatte bliver over bebyrdet 😎😎😎😇😇😂😂😂😂😂 ok godt ord igen.

Joe Brockmeier »
@jzb@mastodon.social

@Gargron any idea where it’s coming from, or why now?

...

Greenpete (No Flag) »
@greenpete@lor.sh

@jzb I've read here, that it's one person in Japan.

...
PetterOfCats boosted

artisanrox »
@artisanrox@mstdn.social

@Gargron

you know you're on to the right ideas when jerks try to ruin it.

...

jz.tusk »
@jztusk@mastodon.social

@artisanrox @Gargron

Yup. I feel sorry for (and greatly appreciate) all the admins who have to spend their time fighting this, but trolls and spam are a sign that what you've created is becoming important.

Sexybiggetje🐖 »
@martijn@ieji.de

@Gargron whilst being good advice, blocking disposable e-mail providers is not a great solution. Privacy focussed users often use those, and they are a legitimate userbase. Can't wait to see what else the fediverse comes up to remedy this problem, there are some pretty smart people on here! :)

...

ZeroEcks »
@ZeroEcks@cuties.cloud

@martijn you could probably just ask an admin to let you in manually or just run your own ;)

...

Sexybiggetje🐖 »
@martijn@ieji.de

@ZeroEcks I believe in a low barrier of entry to the fediverse. Both are 'too hard' for many users. I agree, but my dad isn't that tech savvy :)

...

ZeroEcks »
@ZeroEcks@cuties.cloud

@martijn does your dad use anonymous mail services tho. The problem is that if you don't make people vouch for themselves to some degree, you will just get overrun with spammers eventually, the barrier to entry for email is super high because of this (which is then why we use email as the barrier to entry for everything else lol)

...

Sexybiggetje🐖 »
@martijn@ieji.de

@ZeroEcks you pose a valid point.

Stephan »
@stvo@darmstadt.social

@martijn @Gargron you can get a privacy friendly mail from most of the regular providers. Mastodon is using mailcontact to recover acounts and inform about activity and moderation.

Throwaway mail is not a good use for a mastodonaccount and in case of account recovery even a security problem (which is in the end a contradiction with privacy goals)

yoshi, the dinosaur from mario »
@cybertailor@wetdry.world

@martijn @Gargron addy and firefox relay are better alternative to temporary email

john lehet »
@johnlehet@mas.to

@Gargron I’m glad to say I *never* see span on mas.to. Thanks @trumpet !

Grey Goo »
@greygoo@corteximplant.com

...

🇳𝗮ꜟ𝖼𝘩 »
@Naich@fosstodon.org

@greygoo @Gargron
Nope, that was someone doing testing and it escaping into the wild. ani.work/@hanbitgaram/11195202

...

4censord »
@4censord@unfug.social

@greygoo @Gargron nop, not really. That is single server that had create 30 million actors (users) for test purposes, but they didn't actually do anything. It wasn't supposed to federate, but was an accident.
If that was the source of the spam, one could just have blocked this single server.

The spam wave is some script kiddy going around and searching for servers with open registrations, and registering accounts there using disposable emails. These accounts then start tagging people with spam.

Barkeeper Tom »
@thomas@metalhead.club

@Gargron I honor every line of code that your team and you produce to maintain Mastodon.

But what I really miss as an instance administrator is some sort of spam detection. We have tools and libraries for that, e.G. for simple naive bayes detection.

Maybe it will not be 100 percent precise, but it would help a lot of Mastodon could block / delay suspicious posts based on simple machine learning mechanisms (like we have them for email).

...

fuomag9 »
@fuomag9@lime.fuo.fi

@thomas @Gargron I agree, we have the tools built on year of experience with emails that would absolutely work here as well

Retro Librarian »
@LibrarianRA@worldkey.io

@Gargron my account is getting tagged in about 20-30 a day. If this keeps up , I have little choice then to leave . I’m reporting more spam than engaging with followers . It’s exhausting 😮‍💨

...

David Tanner 🏴󠁧󠁢󠁷󠁬󠁳󠁿 »
@DavidTanner@toot.wales

@LibrarianRA @Gargron It’s bizarre as I haven’t seen a single spam. I assume @jaz is working overtime keeping toot.wales spam free 🤷‍♂️

...

jaz 🏴󠁧󠁢󠁷󠁬󠁳󠁿 »
@jaz@toot.wales

@DavidTanner @LibrarianRA it's all our fantastic @teamtoot staff and a lot of experience managing a busy service. Please do (if using Mastodon) go to your notifications preferences eg toot.wales/settings/preference and review "Other Notification Settings" to minimise spam notifications and messages.

moggie »
@EverydayMoggie@sfba.social

Try turning on these settings. The spam always has direct mentions, so it should help some.

@LibrarianRA @Gargron

Screenshot showing options turned on:
OTHER NOTIFICATIONS SETTINGS
Block notifications from non-followers
Block notifications from people you don't follow
Block direct messages from people you don't follow
...

Retro Librarian »
@LibrarianRA@worldkey.io

@EverydayMoggie @LibrarianRA @Gargron Thank you , but most of these won’t work for my page. Turning some of them off won’t allow me to interact with the over 3.k followers of this page. It also doesn’t stop the spam. I hope they can do something soon . I’ve had another 10 in the last hour . 🫠

JimmyChezPants »
@jpaskaruk@growers.social

@Gargron

Back in BBS days, most Sysops required a phone call before we enabled access to more than the "Introductions" board.

This created a human connection between user and Sysop that created a fairly congenial environment, even when very strong disagreements were the order of the day.

The VC need to hoover up accounts which they can monetize is what incentivizes open registration. Nobody else needs "all the accounts" so turning on approval is just a good idea for everyone.

...

Condalmo. »
@condalmo@mstdn.social

@jpaskaruk @Gargron I miss those days

...

JimmyChezPants »
@jpaskaruk@growers.social

@condalmo @Gargron

You n me both.

Good news though, LoRaWAN gets you about 300bps, I am told, so my current plan is to start up a community meshtastic network with its first BBS hosted at my place.

I just need to get a job first so I can buy some radios.

AvvieLanche »
@Avvielanche@mstdn.social

@Gargron well that sucks because I use Protonmail and DDG's email masker because fuck google. I hope this doesn't mean that only massive, centralized corporate mail servers are acceptable

...

Kevin Marks »
@KevinMarks@xoxo.zone

@Gargron given that the spam is mainly the same images, could you hash them and use that as a rejection filter?

...

4censord »
@4censord@unfug.social

@KevinMarks @Gargron Assuming they use the exact same image, possibly. But if they even so much as slightly change the image (e.g., convert to another format, change some colour mapping etc) then it won't work with traditional hashing.
There exist hashing methods that work on visual similarity, but those are more complicated, and significantly harder to get right.
Also, more vulnerable to false positives, and worse catch rate.

...

Braw 🏳‍🌈 »
@brawaru@mstdn.social

@4censord the images are indeed always different in hash because each instance also has its own image quality settings, as far as I understand. however the images that I have tested have about 99.9% visual match, so would easily be qualified as the same, and thus as spam

@KevinMarks @Gargron

fuomag9 »
@fuomag9@lime.fuo.fi

@KevinMarks @Gargron almost useless, just a single pixel can be changed and the hash will have a different value

BeAware boosted

Sam »
@sam@urbanists.social

@Gargron If you could like... idk... actually write software or something?? to make moderation easier??? that would help a fuckton. or approve the MRF??

...
BeAware boosted

Michael Downey 🇺🇳 »
@downey@floss.social

@sam To be fair there are like 5+ years of ignored admin/moderation improvement requests in the queue 😅

Jess »
@beatricejess@masto.bike

@alter_unicorn
Plutôt que de bloquer les domaines, est ce qu'il serait possible de bloquer les fournisseurs de mails jetables ?

...

Mathieu-Flâneur »
@mate@3615.computer

@beatricejess @alter_unicorn

C'est quoi le problème des fournisseurs de mails jetables ? À l'époque (circa 2013) c'était le feu !!!

EDIT : Je viens de lire le toot original, je comprends mieux. Merci

...

Jess »
@beatricejess@masto.bike

@mate @alter_unicorn
Bon, ça n'a pas l'air d'être non plus une super solution, vu que des gens l'utilisent aussi, pas que des spammeurs.

Michael Bishop ☕ »
@MichaelBishop@mastodon.world

@Gargron

I haven't received any yet. 🤞

Galactic Stone 🇺🇦 »
@galacticstone@mastodon.social

@Gargron - is any of this related to Meta's Threads?

That company's lax attitude towards moderation could become a beacon for spammers to set up accounts there and then propagate their spam to the rest of the fediverse.

I am not an admin, so I don't know what goes on with the server side of things, and I am probably over-simplifying.

...

Jcrabapple »
@jcrabapple@dmv.community

@galacticstone no the spammers are taking advantage of fediverse servers with open registrations.

joene 🇵🇸 🕊️ »
@joenepraat@todon.nl

@Gargron Still the problem is Mastodon. See github.com/mastodon/mastodon/d.

Please see these issues (two of them are created by me and are related) as well:

*Require blocking of disposable email providers and/or require a captcha provider when registrations are open*

github.com/mastodon/mastodon/i

*Set new registrations on new servers to manual approval by default*

github.com/mastodon/mastodon/i

*Ability to greylist new servers*

github.com/mastodon/mastodon/i

*Ability to use heuristic spam filtering tools*

github.com/mastodon/mastodon/i

*Instance-wide filtering*

github.com/mastodon/mastodon/i

cc @renchap

Herman 🇪🇺🇺🇦🇾🇪 »
@Herman@mastodon.world

@Gargron Thanks for keeping us safe from these digital hooligans.

Ian Bog'Ste »
@b0gste@mstdn.social

@Gargron @stux maybe this could be useful?

Allan Chow »
@grumpasaurus@fosstodon.org

@Gargron how many are just servers people set up and forgot about

Drew Mochak boosted

Collectifission »
@collectifission@greennuclear.online

@Gargron hCaptcha is problematic. I'm sure you're aware of this github issue: github.com/mastodon/mastodon/i

It's becoming a harder sell that this is an "emergency feature implementation" 9 months after the issue was opened.

...

Drew Mochak »
@objectinspace@freeradical.zone

@collectifission @Gargron +1 have seen multiple reports of blind people being locked out due to HCapcha. Respectfully, Throwing your disabled users under the bus when they're inconvenient is not being a good ally.

Callalily »
@Callalily@a2mi.social

@Gargron I've been getting a lot of spam since Thursday or Friday. I keep reporting & blocking.

...

Jeri Dansky »
@jeridansky@sfba.social

@Callalily Have you tried this (a suggestion from the admins on my site):
You may want to consider temporarily blocking direct messages from people you don’t follow. To do that, go to Preferences ➡️ Notifications ➡️ Block direct messages.

...

Callalily »
@Callalily@a2mi.social

@jeridansky
I'm on my phone & that's not an option in my preferences or notifications. I was able to change in to only my followers.

Louis »
@louis@emacs.ch

@Gargron We've already had to limit over 50 domains and it looks like some instances are created only for the purpose of this attack. This exposes a vulnerability of Mastodon in that admins have no way to prevent incoming spam other than after the fact.

So if you know of any tool or option that would enable receiving instances to keep this in check, please let us know.

Sibshops »
@Sibshops@mstdn.games

@Gargron If you want to encourage servers to switch to manual approval. Maybe switch the order on joinmastodon.org to put the servers that require manual approval ahead of the open servers? By putting the open servers first it appears joinmastodon.org is endorsing open registrations.

Screenshot of joinmastodon.org page showing open registration servers before manual approval servers.
...
BeAware boosted

james is ??? »
@james@strangeobject.space

@Gargron hey Eugen, thanks for this statement. I noticed that the team are or were aware of accessibility issues with hCaptcha and other captcha services. (github.com/mastodon/mastodon/i)

Was this remedied, or do you have any further insight into what the accessibility issues are? They weren't listed in the comment.

Whilst I appreciate that combating this spam wave is necessary for general happy and continued use of the platform, I want to avoid making mastodon inaccessible to those with access needs.

Cheers!

...

Renaud Chaput »
@renchap@oisaur.com

@james @Gargron we have this in mind, but did not got the time to improve it yet.

...

Julian Lam »
@devnull@crag.social

@james we recently were in touch with some consultants and hCaptcha was one of the points raised.

According to them hCaptcha's accessible method for confirming human use is to have them enter an email to which a magic link is sent, and a cookie is sent (like a magic login link). That's not so good from a data privacy perspective.

...

Darrell Hilliker 👨‍🦯♾️📡 »
@darrell73@mastodon.online

@devnull @james That's right. This is yet another example of how it isn't first and won't be the last time disabled people are expected to give up our own privacy and security for the comfort and convenience of nondisabled people.

techsinger »
@techsinger@mastodon.social

@devnull @james If I may add to this, let's set aside privacy for a minute, the evidence over the past few years has made it abundantly clear, nobody cares about the privacy of the disabled, and I include disabled people when I say nobody. The problem with HCaptcha isn't just privacy, it's that the cookie simply doesn't work. I recently went through four browsers over two days until I could finally get passed the block on one site.

BeAware boosted

Mike Johnston »
@ThaMunsta@mastodon.nervesocket.com

@Gargron it needs to be easier for moderators to find report and suspend accounts or instances that are compromised. It's hours of clicking to do it "properly" right now and I don't have a full time staff - it's just me doing clean up 🥲

nemo™ 🇺🇦 »
@nemo@mas.to

@Gargron I was like 😅 😓 🤦

The Brights »
@brights@zhub.link

This is really like:

- We have a dude that is registering many accounts on abandoned old servers and is spamming all users. What we can do?!

- We urge admins of OTHER, not abandoned servers, to close registrations! (or enable captcha, approval etc.)

- What?! 🥴

@Gargron

...

Michael K Johnson »
@mcdanlj@social.makerforums.info

@brights Speaking as the admin of a definitely not abandoned, previously-open-registration instance, not all of them have 24/7 admin coverage to handle spam reports. I had a flood while I was asleep, and I took care of them in the morning and changed to requiring approval with a reason. Then last night another similarly actively maintained server I know of was attacked in the same way and made the same change this morning. I'm sure there are others too; I'm just reporting what I know from my tiny corner of the fediverse.

So, why not start from an assumption that people aren't idiots? Turns out there are a lot of people here who actually know what they are doing.

Just because abandoned servers are highly visibly affected because no one is eventually cleaning up the mess doesn't mean that only abandoned servers are affected.

...

The Brights »
@brights@zhub.link

@mcdanlj
> So, why not start from an assumption that people aren't idiots?

I didn't assume this, Gargron did. Because I closed the registration on my server about 24 hours ago, right after the wave started. I assumed that every "not stupid" admin on not abandoned server would do the same without a message from Gargron, right?

So, my assumption was - those servers, that are not switched to closed/approved/captcha enabled registration mode, are the source of the issue.

This was the first.

Second:
Closing registration or enabling captcha on not-abandoned servers WILL NOT solve the issue for the Fediverse because of those abandoned, but actively spamming servers.

The proposed "solution" is just a small mitigation at best :(

...

Michael K Johnson »
@mcdanlj@social.makerforums.info

@brights You are the one calling it a solution. Everyone else seems to agree that it is a mitigation. You are reading a lot into what Gargron said that I don't think is there...

Hiker Geek 🌲💻🌲 »
@HikerGeek@mas.to

@Gargron

Any thought on developing a federated anti-spam system? If one instance blocks an email or domain it propagates to the servers that choose to federate with its anti-spam so that email or domain can't be used on other servers.

kristophr »
@kristophr@the-gathering.space

@Gargron This it me and our server - I tried to shut it down and think I'm successful - but do worry what happens to our small server and getting defederated because of this.

Drew Mochak boosted

Andre Louis »
@FreakyFwoof@universeodon.com

@Gargron is a barrier for many blind/visually impaired users, for some of the reasons outlined in my recent post here: universeodon.com/@FreakyFwoof/

It's Just Me boosted

Frehi »
@frehi@fosstodon.org

3 ★ 0 ↺

It's Just Me »
@me@mysmallinstance.homelinux.org

So much spam in the last two days...

...
It's Just Me boosted

Pablo »
@p@universeodon.com

@me Exactly! I've blocked a bunch, but I noticed no difference.

...
1 ★ 0 ↺

It's Just Me »
@me@mysmallinstance.homelinux.org

It's a flood!

It's Just Me boosted

boggin »
@boggin@hachyderm.io

First time ever: on a web article I was reading, I hit the X at the top-right corner not realizing it was the Twitter logo

...

Courtney Cantrell »
@courtcan@mastodon.social

@boggin I've done that a couple of times now and it is SUPER ANNOYING AND POOPY.

It's Just Me boosted

Jerry Bell »
@jerry@infosec.exchange

This is by far the worst spam campaign I’ve seen in my 7 years here on the fediverse

...
Older...

Josh »
@Josh@infosec.exchange

@jerry Screenshots?

...

Jerry Bell »
@jerry@infosec.exchange

@Josh its just lot of posts from what brand new user accounts on hundreds of different mastodon instances with a few random users tagged and an image that contains the link to a discord server.

Rémy Grünblatt 🍃 »
@RGrunblatt@social.sciences.re

@jerry Honestly here I have not seen a single report… Are the targeted instances limited ?

...

Jerry Bell »
@jerry@infosec.exchange

@RGrunblatt I have been limiting them. I’ve had perhaps 250 reports or so today across perhaps 100 different instances

...

Rémy Grünblatt 🍃 »
@RGrunblatt@social.sciences.re

@jerry Do you have maybe some part of the spam messages I could search for on my server ? Because I find it weird that none of the users of my server made some report about being spammed…

...

Jerry Bell »
@jerry@infosec.exchange

@RGrunblatt the spams are targeted - they are tagging 5-10 accounts in each spam message. I don’t know what sort of algorithm is driving who gets included, but I’m guessing your instance hasn’t had any of its members tagged in the spam runs

...
Skip Lacaze boosted

Raccoon at TechHub »
@Raccoon@techhub.social

@jerry @RGrunblatt
It's being done by some person or group using the moniker "Black Cat", tagging things with the hashtag . The thing that made the attack tedious to deal with was the fact that they were signing up for a bunch of accounts, posting only one or a few messages on an account before moving on to make the next one, meaning it wasn't as simple as blocking a single account, moderators would have to go through the entire list and block every account that was doing it.

It wasn't like, network destroying, but it was annoying, and I don't envy the moderation teams that had to deal with it, regardless of who they were.

----

Edit: since the post is being boosted, PSA, don't click the links they are spamming, remember to use the report button, and remain calm. It's just a spam attack, and moderation is on it. Happy posting.

...

Raccoon at TechHub »
@Raccoon@techhub.social

@jerry @RGrunblatt
The scale of the attack was thousands of posts spread across hundreds of accounts spread across about a hundred servers. If it weren't for decentralized moderation, we might have been overwhelmed by that, but as it stood, individual servers only had to ban a handful of accounts each.

----

Edit: since the post is being boosted, PSA, don't click the links they are spamming, remember to use the report button, and remain calm. It's just a spam attack, and moderation is on it. Happy posting.

Screenshot of the kuroneko hashtag. 1.7 k posts, 375 participants
...

GunChleoc »
@gunchleoc@mastodon.scot

@Raccoon @jerry @RGrunblatt Here's a thread with instructions on how to get rid of them: mastodon.de/@ErikUden/11194030

Jerry Bell »
@jerry@infosec.exchange

@Raccoon the last ~200 I’ve dealt with have been different - they have no hashtags - just an image with a handful of accounts tagged - nothing else to key on @RGrunblatt

...

Zekovski »
@Zekovski@pouet.chapril.org

@RGrunblatt @jerry
I think if your instance requires approved registration, you won't see it in your local feed, and people won't share them in your main feed.
At least that's how I explain to myself I haven't seen one either.

shadowwwind boosted

Fabrice Roux »
@fabrice@infosec.exchange

@jerry *Homer from the back of the room* Worst spam campaign so far. 😬

jenbanim »
@jenbanim@mastodo.neoliber.al

@jerry spending my Friday evening just hanging out in the "other servers" feed banning spam accounts as they pop up

There are worse hobbies I suppose

You might be interested in following the mod tools discussion promoted by this here:

github.com/mastodon/mastodon/i

Dr. Sbaitso »
@drsbaitso@infosec.exchange

@jerry If it helps, I've seen way more discussion about how terrible this spam wave is than any actual spam 🤷🏻‍♂️

...

weilawei »
@weilawei@mastodon.online

@drsbaitso

I think that's a good sign that the admins are really on top of things. I like it.

@jerry

...

Jerry Bell »
@jerry@infosec.exchange

@weilawei @drsbaitso I’ve spend the last two hours handling spam reports and wading through recently created new accounts on remote servers looking for and proactively suspending new spam accounts and limiting their domains

...

weilawei »
@weilawei@mastodon.online

@jerry is a modern day hero right here.

Communication is absolutely vital to every other thing we do, and you're keeping watch. Thank you.

@drsbaitso

Dr. Sbaitso »
@drsbaitso@infosec.exchange

@jerry @weilawei Wow. To be clearer, I meant what I said in the sense that the work is absolutely working on the user side.

Raccoon at TechHub »
@Raccoon@techhub.social

@weilawei @drsbaitso @jerry
To be fair, we had the advanced warning that the first servers that were really hit were misskey instances which a lot of us had already blocked. Cunnyborea, for instance, seems to have been the source of the bulk of it, and they are constantly showing up on FediBlock.

...

Jerry Bell »
@jerry@infosec.exchange

@Raccoon I would estimate there are at least 100 instances involved now, and all the recent ones (perhaps the last 90) have all been mastodon instances. @weilawei @drsbaitso

...

Raccoon at TechHub »
@Raccoon@techhub.social

@jerry @weilawei @drsbaitso
Yeah I figured they would hit us eventually, that's why I'm keeping an eye out.

Shelenn Ayres »
@shelenn@nerdica.net

@jerry I have to wonder if this coincides with the recent merger approval and the timing of rulings against Trump - it makes sense an army of DWAC or Truth.social bots and/or trumpers have a renewed mission... theguardian.com/us-news/2024/f…

Raccoon at TechHub »
@Raccoon@techhub.social

@jerry
Here's an interesting question, has anyone tried going to that Discord server they keep linking? I mean, obviously you'd want to do it on Linux using a throwaway account, but other than that they call themselves kuroneko/black cat, I don't really know anything about them.

I'm really curious as to what the motivation for this is: it doesn't seem to be ideological because they seem to be attacking at random, and I don't see a reason for anyone who isn't like, Elon musk, or some government entity, to attempt to harm Fediverse as a whole...

...

Incognitim » 🤖
@Incognitim@mastodon.social

@Raccoon @jerry
Apparently they're just a bunch of kids in Japan doing it for lulz or something. At least that's what
Cappy Ishihara
cappy@fedi.fyralabs.com
thinks.

...

Raccoon at TechHub »
@Raccoon@techhub.social

@Incognitim @jerry
That would lean the Asian text and the initial focus on Misskey instances...

So has anyone managed to maybe talk to them about this? If it is just some kids in Japan, maybe they could be pointed in a more positive direction: clearly they are not without skill or dedication.

...

Incognitim » 🤖
@Incognitim@mastodon.social

@Raccoon @jerry
I honestly have no idea, this is all secondhand from Cappy's (who I don't know) posts from like 12 hours ago.
I believe they also said that Misskey was pursuing legal action, but if it's just some youngsters trolling then everyone might just have to wait for them to get bored and find another outlet for their cybergression 😅

INK »
@mata_aimasho@the9thcircle.club

@Raccoon@techhub.social @jerry@infosec.exchange I haven't visited, but apparently they also offer "VOICEVOX" and "VOICEROID" bots on that Discord (think VOCALOID, except made for talking instead of synthesized singing).

To be quite honest I guess I do see that being viable as a Discord bot.

Plus I assume that does appeal to Japanese users, and the main target indeed seems to be users following Japanese accounts. (I might be wrong.)

They might also be avoiding admins, but not mods (fuck).

By the way: I don't suppose Linux is that much safer unless it's a VM that's virtually disconnected from your home router. (But who knows. Maybe they're not that dangerous anyway.)

...

Raccoon at TechHub »
@Raccoon@techhub.social

@mata_aimasho @jerry
I suggest Linux because it's easier to secure against common attack vectors, like someone trying to trick the browser into running code that messes with the system itself. Windows has gotten pretty good about not doing that, but people are still finding vulnerabilities that Linux just doesn't have.

That said, I don't think they'd like, be able to see your IP address or something from just going on their discord server and talking to them.

Angus Marshall »
@marshalla99@thx.gg

@jerry "Worst" as in "not done very well" or as in "having the greatest effect" ?

...

dango🍡 »
@dango_@mas.to

@jerry does mastodon (or any ap impl) have automated spam filtering? Leaving it all to users and admins to report and clean up seems kinda...

...

Jerry Bell »
@jerry@infosec.exchange

@dango_ no. It’s a manual effort

Elusive Man boosted

Jerry Bell »
@jerry@infosec.exchange

I am amending my statement above. I believe that all of the prior spam incidents over the past 7 years combined don’t amount to what has happened in the past 24 hours

...
Older...

Viss »
@Viss@mastodon.social

@jerry ive been abroad at a con making defender upset. what have i missed? :D

...

Jerry Bell »
@jerry@infosec.exchange

@Viss a lot of spam. The wild part is that if you aren’t targeted by it, you would never know it happened.

...

Viss »
@Viss@mastodon.social

@jerry is it all one subject of spam? like is it all porn bots? or phishing/malware?

...

Jerry Bell »
@jerry@infosec.exchange

@Viss it’s literally images of a can of spam with a discord link on the can. There are a few other permutations. But most are images with a link to a discord server

...

HM02 »
@hm02@misskey.social

@jerry@infosec.exchange Do you think the actors are actually Japanese or is that a disguise?

...

Jerry Bell »
@jerry@infosec.exchange

@hm02 I really don’t know. None have signed up up my instance, so I don’t have a lot of insight beyond the posts themselves, which gives no real insight

wen »
@goldeee13@mas.to

@jerry @Viss they’ve been top trends on Trending Tags

Screenshot of Trending Tags

Dan 🔓 »
@sycophantic@infosec.exchange

@jerry @Viss yeah I didn't see any porn. I want my porn!

John Kristoff »
@jtk@infosec.exchange

@jerry @Viss Some may see them if they are following any of the tags. Some bots reporting trending topics saw a great deal of pollution in their stats the past couple of days too.

...

Jerry Bell »
@jerry@infosec.exchange

@jtk @Viss 99% of the spam has no hashtags. There were some other runs (not sure of the same actor) that did. But this action happening now are quite minimalist posts

Jernej Simončič � »
@jernej__s@infosec.exchange

@jerry Thank you for whatever you're doing, because I haven't seen a spam message on here in months (cue my feed being filled with spam in the next few minutes).

BeAware boosted

Tim Chambers »
@tchambers@indieweb.social

@jerry Wow. That’s a thing.

TheKilt »
@thekilt@infosec.exchange

@jerry thanks, we appreciate all your hard work keeping this place running, and running smooth!

rallias »
@rallias@hax.social

@jerry I had one registration on my instance, fortunately I caught it before they fired off their load.

I guess it's justify your reg season on HAX.

Simon »
@simontsui@infosec.exchange

@jerry I'm not sure if you've seen this trending toot: mstdn.ca/@jd/11194753011457715

But from initial impressions, it seems to be a Japanese Discord bot drama escalating into "doxxing people and harassing real world businesses."

As for limiting the creation of spam accounts, adding an hcaptcha on signup was suggested by @stux mstdn.social/@stux/11194741886

...

Jerry Bell »
@jerry@infosec.exchange

@simontsui @stux I have it under so no spammers can join Infosec.exchange - it’s the 20000 other instances that are my problem now

...

Fritz Adalis »
@FritzAdalis@infosec.exchange

@jerry @simontsui @stux
We have 60k infosec professionals and > 15k MAU, can't we just hack our way out of it?

...

Jerry Bell »
@jerry@infosec.exchange

@FritzAdalis @simontsui @stux I needed the laugh 😂😂😂

Simon Zerafa »
@simonzerafa@infosec.exchange

@jerry

It has been somewhat persistent 😟

Jason »
@ShibaBotJason@social.linux.pizza

@jerry

@selea must be working overtime because I haven't seen it on our instance. Thanks @selea !!

...

𝚜𝚎𝚕𝚎𝚊 »
@selea@social.linux.pizza

@ShibaBotJason

Yeah I am constantly suspending shit accounts

@jerry

...

GunChleoc »
@gunchleoc@mastodon.scot

@selea Have you seen this? mastodon.de/@ErikUden/11194030

Includes instructions on blocking their e-mail domains so that they can't sign up.

...

𝚜𝚎𝚕𝚎𝚊 »
@selea@social.linux.pizza

@gunchleoc

Yeah, saw it yesterday. But it initialy had bad instructions, such as suspend domains involved in the domain even if it is a well known instance.

...

GunChleoc »
@gunchleoc@mastodon.scot

@selea Yes, they updated that bit.

I found the e-mail domain blocking helpful, and the server list.

Hayo Bethlehem »
@hayo@infosec.exchange

@jerry
Too be fair, on x noone would be doing anything to stop it. I'm amazed by the willpower of the adminheroes of the Fediverse.

Renaud Chaput »
@renchap@oisaur.com

@jerry and this is caused by japanese kiddies…

fedops 💙💛 »
@fedops@fosstodon.org

@jerry I never understood why open registrations seemed like a good idea.

cremevax 👩🏻‍💻 🏳️‍🌈​ »
@cremevax@infosec.exchange

@jerry thanks. I greatly appreciate all the work you and the other admins are doing. ✨

Paul_IPv6 »
@paul_ipv6@infosec.exchange

@jerry

this just boggles my mind...

...

Jerry Bell »
@jerry@infosec.exchange

@paul_ipv6 yeah, same.

...

Paul_IPv6 »
@paul_ipv6@infosec.exchange

@jerry

most crackers/spammers are pretty dumb and lazy. it's why we can keep up.

but every so often, i see someone really effective, who's obviously done some work and done something clever. can't help but wonder how someone like that couldn't financially clean up even more with legit work, considering how lame most commercial products are and how dumb so many millionaires are.

...

Karl Baron »
@kalleboo@bitbang.social

@paul_ipv6 @jerry The fediverse has zero spam protection, I'm more amazed it made it this far before becoming a target

Steve Dinn »
@steve@social.dinn.ca

@jerry I thank you and the other conscientious admins for the fact that I, on my tiny instance, have seen absolutely none of it.

kel »
@kel@mastodon.online

@jerry

This actually makes me feel better, I got upset this morning because of the intensity of it.

Thank you for posting.

14 ★ 3 ↺

It's Just Me »
@me@mysmallinstance.homelinux.org

Ok, enough with the haiku. It's Friday, the weekend calls for relaxation and a bit of self-care (which I've neglected in these past weeks) and some good time here on social media.
I wish you, reading this, a fantastic weekend filled with the things you most enjoy doing!

...

OddFellow ✓ »
@jm101@mstdn.party

@me

Have a great weekend 💯😎👋👍

...
It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

...

Rob Chapman ✍🏼🐧 »
@robchapman@ohai.social

@stefano Those phones are particularly satisfying, because you can slam the handset down on someone objectionable on the other end of the line.
or, in this case, chuck the whole thing out the window.

...

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

@robchapman maybe that's what happened here.

cuddle »
@cuddle@mastodon.bsd.cafe

@stefano I've rarely seen these phones, some people still do have them... but very rare.

0 ★ 0 ↺

It's Just Me »
@me@mysmallinstance.homelinux.org

Ok, enough with the haiku. It's Friday, the weekend calls for relaxation and a bit of self-care (which I've neglected in these past weeks) and some good time here on social media.
I wish you, reading this, a fantastic weekend filled with the things you most enjoy doing!

6 ★ 1 ↺
Ian Davis boosted

It's Just Me »
@me@mysmallinstance.homelinux.org

Friday's soft whisper,
Week's weight lifts, spirits soaring,
Weekend's embrace nears.

It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

"Hang".

This photo is from 2012. It perfectly captured my life and my mood, at that time.

This photograph features a single, dark pull handle suspended on a thin line, centered against a backdrop of dense fog that blankets a neighborhood scene. The silhouette of the handle is crisp and prominent, offering a sharp contrast to the soft, obscured forms of houses and a rooftop that fade into the misty grey. The image evokes a sense of stillness and solitude, with the handle hanging motionless, an element of everyday utility transformed into a focal point of contemplative simplicity amidst the enveloping haze. Hang in space, hang in time.
...

Zeki Çatav 🤔 ☕ 🕯️🎶 »
@catavz@mastodon.social

@stefano It looks like " weather stone"😉

No description
It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

Ferrara is celebrating Valentine's day

This photo captures a majestic red brick castle bathed in romantic red lighting, in celebration of Valentine's Day, set against a deep twilight blue sky. The castle's historical features, including a central tower and crenellated parapets, are accentuated by the vibrant lighting. A cobblestone courtyard extends in the foreground, enhancing the castle's grandeur and the special occasion's ambiance.
It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

Memories of a stroll in Ferrara city center, one year ago today.
Love was in the air.

A vibrant evening scene in a bustling city square adorned with festive lights. Heart-shaped illuminations create a romantic atmosphere, hanging from lamp posts and strung across the open space, glowing warmly against the twilight sky. Historic buildings line the square, their traditional architecture and lit windows adding to the ambience. People, bundled in winter attire, stroll through the area, some pausing to admire the decorations, while the soft glow of street lamps casts a cozy light over the entire scene.
It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

...
8 ★ 0 ↺

It's Just Me »
@me@mysmallinstance.homelinux.org

A new Haiku for a new week!

Monday morning light,
Fresh start, possibilities,
Embrace the new week.

It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

Memories of a walk in nature, 11 years ago, in search of a Silent Sunday, a bit of peace in a tumultuous and turbulent period of my life that would soon come to an end, although I didn't know it yet.

This photo holds a profound significance, known only to me.

This is a serene photo capturing a group of common reeds, illuminated by the soft, warm glow of the setting sun. The reeds are in sharp focus in the foreground, while the background is a gently blurred landscape featuring a tranquil waterway, flanked by grassy banks that lead to a line of tall, slender trees in the distance. The trees' bare branches suggest it is  winter. The low angle of the sun creates a peaceful ambiance and casts a golden hue over the scene, highlighting the feathery plumes of the reeds and giving the entire image a quiet, timeless quality.
...
Older...
It's Just Me boosted

Stu 🏴󠁧󠁢󠁷󠁬󠁳󠁿🏳️‍🌈🖖 »
@welshstu@toot.wales

How does such a little cat produce so much poop? I’ve never done so much scooping.

A black cat sitting on a beige carpet.
...
Older...
It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

"Ok, it's Caturday. Why are you taking a photo of me? I'm a Tiger!" 😆

A majestic ginger cat sits confidently on a brick ledge, mouth wide open in a mighty yawn, resembling a fierce tiger in its powerful stance and expression.
...
9 ★ 2 ↺
Deester boosted

It's Just Me »
@me@mysmallinstance.homelinux.org

Saturday's gentle breeze,
Positivity at ease,
Relax, heart at peace.

...
It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

...
It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

In 2007, I used to invite friends over to my place. Often, I would hear them burst into laughter when using the toilet.
This is a photo of my flush from 2007.

A close-up view of a shiny, metallic toilet flush button on a white surface, with a small rectangular sticker above it displaying the colorful Windows XP logo and the text "Designed for Microsoft Windows XP."
...
12 ★ 4 ↺
sara boosted

It's Just Me »
@me@mysmallinstance.homelinux.org

Friday's gentle hum,
Week's burdens set adrift, free,
Weekend dreams take flight.

8 ★ 3 ↺
Stevo boosted

It's Just Me »
@me@mysmallinstance.homelinux.org

Thursday's hues,
Colors dance through daylight,
Sun sets in night.

...
It's Just Me boosted

justdisa »
@justdisa@mas.to

@me

So cool that you've made
A miniature instance--
Mastodon haiku.

It's Just Me boosted

Hobbits Wife »
@hobbitswife@mastodon.me.uk

Littlest cat has finally discovered the radiator. Only took her 4 years ….

Tabby cat on a radiator
...
It's Just Me boosted

bytter »
@bytter@fosstodon.org

How to be secure of your employment?
Write a code so bad that nobody will want to maintain it, and thus pretend that you understand this code.
Do not work with Open Source positions

It's Just Me boosted

JB »
@JB@toot.community

Just plain fun. Inspired by a tutorial by katiewhiteartist on Instagram, but she does it better. Colors: Cobalt Blue, Spring Green, Sap Green, Paynes Grey. Brushes: quill, rigger.

This is a watercolor doodle. There’s a green sky, very wet and dripping. Three black trees rise out of a river bank.
...
1 ★ 0 ↺

It's Just Me »
@me@mysmallinstance.homelinux.org

A pure dream. Congrats!

...
It's Just Me boosted

Cindy 🏳️‍🌈 »
@RIDDLES@c.im

@RIDDLES
1920s Sweetheart Toaster.

No description
...
8 ★ 0 ↺

It's Just Me »
@me@mysmallinstance.homelinux.org

Here we are again, halfway through the week. Does time seem to fly by faster for you too as days go by?

...
It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

...
12 ★ 1 ↺

It's Just Me »
@me@mysmallinstance.homelinux.org

My Sunday in an Haiku:

Winter's calm embrace,
A warm beverage by the window,
Peaceful Sundays at home.

To you that are reading this message, happy Sunday!

It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

8 ★ 2 ↺
Choukichouk boosted

It's Just Me »
@me@mysmallinstance.homelinux.org

Saturday's embrace,
Week's burdens start to loosen,
Weekend's sweetest grace.


It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

...
It's Just Me boosted

🪷 प्रियंका | Priyanka 🪷 »
@altlife@me.dm

1 ★ 0 ↺

It's Just Me »
@me@mysmallinstance.homelinux.org

Closer to the weekend day by day! And I don't have any plans for the weekend. Hey, why am I waiting for the weekend then? 😃😅🤣

...
It's Just Me boosted

Tanja »
@hrglbrmpf@mstdn.social

@me Because drifting through a day without a plan can be a really good thing (to me, at least 😄 )

...
It's Just Me boosted

𝚜𝚎𝚕𝚎𝚊 »
@selea@social.linux.pizza

It happened

No descriptionNo description
...
Older...
It's Just Me boosted

Evan Prodromou »
@evan@cosocial.ca

I am so grateful to be part of the fediverse with you.

...
Older...
It's Just Me boosted

a miserable pile of coffee »
@AgathaSorceress@fv.technogothic.net

bluetooth audio is great because instead of the horrible inconvenience of plugging in an audio cable into the audio hole, I get to just put the earbuds into my ears, open the bluetooth device list on my desktop, not see them there, pull out my phone, check if it's connected, find out that it's not, realize that it probably automatically paired to my laptop that's laying in the other corner of the room, then google "WF-1000XM4 pairing mode", find a page that tells me what I need to press for how long to switch it into pairing mode, and only then I can start using them

...
Older...
16 ★ 6 ↺
Luis García boosted

It's Just Me »
@me@mysmallinstance.homelinux.org

Since social networks are filled with negativity, I want to share some good news with everyone: it's Wednesday, and we're already halfway through the week. That means the next weekend is closer than the time that has passed since the last one.

It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

It's Just Me boosted

🪷 प्रियंका | Priyanka 🪷 »
@altlife@me.dm

...
It's Just Me boosted

Ryan Rampersad »
@ryanmr@mastodon.cloud

The hardest part of switching to a new phone: installing the screen protector and being happy with the results.

added the zagg screen protector to the new s24u and it already has smudges all over
...
It's Just Me boosted

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

Winter, cold, fog.
But the light already gives us a faint and distant prelude of spring.

A tranquil sunset scene is depicted, where the sun descends towards the horizon, emitting a soft, golden light that bathes the landscape. The sky, a canvas of subtle oranges and blues, is reflected in the still waters of a pond. Silhouetted against this luminous backdrop are the intricate, interwoven branches of leafless trees, mirrored with striking clarity in the water below. The calm surface of the pond doubles the beauty of the scene, creating a symmetrical display of natural splendor. In the distance, faint outlines of buildings hint at the proximity of rural civilization, quietly coexisting with the natural world. The overall mood is one of serene beauty, marking the day's gentle transition into night.
13 ★ 2 ↺
YMItalking boosted

It's Just Me »
@me@mysmallinstance.homelinux.org

Many people are sad on Monday morning because the weekend is over. I am happy because a new week is starting, which will surely bring new exciting experiences.
Have a great week to you who are reading!

It's Just Me boosted

The Real Grunfink »
@grunfink@comam.es

I'm glad to announce the release of version 2.46 of , the simple, minimalistic instance server written in C. It includes the following changes:

Added support for Peertube videos.

Mastodon API: Tweaks to support the Subway Tooter app (contributed by pswilde), added support for editing posts, fixed an error related to the edit date of a post, fixed some crashes.

Added a handshake emoji next to a user name if it's a mutual relation (follower and followed), because friendship is bliss.

Tweaked some retry timeout values for better behaviour in larger instances (thanks to me@mysmallinstance.homelinux.org for their help).

https://comam.es/what-is-snac

If you find useful, please consider buying grunfink a coffee: https://ko-fi.com/grunfink

This release has been inspired by the album Duality by .


...
Older...
It's Just Me boosted

Mishell Baker gladly »
@mishellbaker@wandering.shop

It's perfectly fine to think of your life as a narrative, that everything in it has meaning. You just have to consider that perhaps you are not always the center of the narrative, and that the meaning of any given event in your life might be more for someone else than for you.

It's easier to find a sense of satisfaction with the course of your life when you include impact on others as a measure of success and meaning.

It's Just Me boosted

Rodrigo Pio »
@rrapio@fosstodon.org

@reginaryerson @me I have the impression this is true regardless of the seniority, I'm afraid. I discuss these issues with friends from 30 to 50 and they seem unaware or, at best, unconcerned about this fact.

I think the best we can do is to equip the next generation. I try to address this issue with my 7yo, for example. This should definitively be a topic for educators and tutors.

It's Just Me boosted

alice »
@lexd0g@wetdry.world

shoutout people doing independent unobtrusive privacy friendly advertisements i will disable my adblocker on your site

It's Just Me boosted

Sheril Kirshenbaum »
@Sheril@mastodon.social

...

History

Back to top - More...