Please report any account that claims that you need to verify your #Mastodon account to continue using it. It is a scam. Don't click the links. Real staff accounts either have a special role badge on their profile or are verified through the joinmastodon.org domain.

reshared this

in reply to Mastodon.social Staff

in reply to Martin Dougiamas

@martin so the spam waves we're seeing are quite advanced and adaptive, it's not like the script kiddie spam from last year.

With this spam wave, I'm still analyzing the data, but:
- we've seen at least 13 different domains used for the phishing site
- we've seen them using CWs when spamming publicly
- we've seen them use multiple different scripts (what's written), including multiple languages

Regexp and publicly available lists of data are not something that would particularly help, as as soon as you publish & block keywords or domains, the attack changes.

If a server admin is not vigilant, then they should not have open registration (ex. Mastodon.social), but there's servers out there that are several versions out of date, so they don't get any of the new mitigation features or warnings (there's a big warning about open registration in the admin panel since 4.3.x)

in reply to Emelia πŸ‘ΈπŸ»

@staff

would limiting rate of posts for new accounts help?

so you make a new account, you only get 3 posts on your first day for example

but... they'll just register and go dormant for a period of time

no, you could still do it:

rate limit number of first few posts, no matter account age

so... they post innocuous garbage to get past that hurdle

but that's still useful

put up these kinds of barriers to make spamming hard, while not interfering with regular users

This entry was edited (4 months ago)
in reply to Mastodon.social Staff

@cainmark
Thank you for that information! I'm on mastodon.social, but I'm usually on a third-party app, #Fedilab, which doesn't show badges, so domain verification is still important.
On that, why not verify through mastodon.social and mastodon.online instead of joinmastodon.org?

#Mastodon #MastodonSocial #MastodonOnline

in reply to Mastodon.social Staff

this scam is taking advantage of an information vacuum (why doesn’t every mastodon user know you don’t have to verify your account to keep using it?), digital deference(it’s on a computer so I must do what it says). Instead of assuming why people are responding to these messages, ask them in order to understand their assumptions and situation.
Also indicates a gap in providing admin level messages, similar to old school forum discussion boards or SMS from mobile phone provider.
This entry was edited (4 months ago)
Unknown parent

mastodon - Link to source

Piiieps & Brummm

Yes, I agree. Praise to the admins!

Yesterday I saw my first post of the sort as a comment on a post I was reading. When I saw it, the commented post was less than 5 minutes old. I _tried_ to report it, but the account was already suspended by the time and a reload showed, that the spam was deleted.

Really outstanding work by all the admins!

@staff

Edits: typos

This entry was edited (4 months ago)
⇧