Skip to main content


I can see the current spam attack taking out a lot of hobbyist instances for good. I've seen mentions of it already

Reputational damage and defedations lead to people giving up as it is, for less than this, but with potential to be impacted by increased costs because of it is insult to injury, and that could be pretty hefty if they only log in occasionally.

I've always been a champion for the little guys on here, I think we need more tiny communities, so it's really sad to see all this

Unknown parent

tiddy roosevelt

@goatsarah Oof, yeah 🙁

I meant to ask, is it alright to follow you? I think I lost the connection in the move and it's been hung on request since

Unknown parent

tiddy roosevelt
@KFuentesGeorge Yeah I've wondered whether having discovery options enabled is going to be a factor in this, or posting mostly public. I've not even got the basic discovery options on and post almost exclusively unlisted and I've had nothing
in reply to tiddy roosevelt

having a tiny community is still a community.

You have to keep on top of it, and have notifications turned on, and if you aren't around a lot you shouldn't have open signups.

I'm terminally online and even my instance is strictly people-I-know-only.

Unknown parent

tiddy roosevelt
@goatsarah Ahh seems to have worked this time around
in reply to tiddy roosevelt

If you're wondering the kind of scale of this, we've just seen someone ask how to ban 12000 spam accounts from their server.

Twelve thousand.

in reply to Brynndylow, they/them

@FrazzledBrynn You can just imagine what that would do to a place like this.

But think if we only had the bandwidth that we did in 2018.

Absolutely fucked.

in reply to tiddy roosevelt

I'm glad you're a great maintainer of glitterkitten, I feel bad for everyone being caught by surprise

I've only seen screenshots of spam... spam? so far

in reply to tiddy roosevelt

I'm manually blocking accounts as they show up as spam from other instances on my single-account instance, but it's a losing game. I'll persist, if not through sheer determination, then through scripts and automation. But that's not an option for most 🙁
This entry was edited (9 months ago)
in reply to tiddy roosevelt

Maybe this tool helps them at least with the accs on their own server?

urbanists.social/@sam/11194900…

#citadel #SpamBotAssassin #Spamwave #Spambot


Introducing Citadel! Citadel is a tool for Mastodon admins that makes it quick and easy to find + suspend spammers in one click!

Eventually Citadel will have more tools, but I wanted to get this out ASAP to help server admins.

It's a client-side app, no server. Everything's all in your browser.

Give it a shot: citadel.samw.dev

View source: github.com/samwightt/citadel

(also note that after you log in you will ned to reload the page)

#MastoAdmin #FediBlock #FediBlockMeta #Admin #Spam


in reply to tiddy roosevelt

Wow... Fire ought to do the trick. :blobfoxrage: Seriously though, open signups are a real liability for instances it seems.
in reply to tiddy roosevelt

@Lazarou
Thinking aloud...
All the users are rand hex that I have encountered, might be possible to use Python's isxdigit then search and destroy users with only hex chars.

It's dirty though, and could remove legit users, but 12k... Damn.

in reply to tiddy roosevelt

It would be hard to get people to accept it, now that we've become so used to everything on the internet being TOTALLY free, but just a tiny sign up charge, say 10 cents, would fix that kind of thing. It's not a meaningful charge for somebody really interested in trying out a Mastodon account.
in reply to tiddy roosevelt

Do you think this is musk? He is very capable of this and it is the type of action he would take?
in reply to tiddy roosevelt

I think one thing we've seen is a large number of instances unknown to others, with open registration being used as launch pads for malicious activity.

I'm starting to suggest a blocklist based on:
- not up to date software
- open registration without approvals
- low MAU count

I think those would help in the short-term, but longer term we really need to come to terms with how purely open federation is not the answer & leads to pain.

Unknown parent

@Sarah Brown @tiddy roosevelt I get this occasionally. Even though it’s set to auto accept I still have to poke it manually.
in reply to tiddy roosevelt

@KFuentesGeorge I’m actually discoverable/searchable but also posting mainly unlisted, it might be the key? (No spam)
in reply to tiddy roosevelt

I've been on the Fediverse a long time -- I remember mentioning to others that this kind of thing was going to be a problem, I think, *seven* years ago.

I run a small instance, but I've never had open registrations -- it's for family members and some automated bots I program.

It's strange -- Mastodon is made with a "small servers are better!" mindset, but then a lot of the internal administration is designed around *large* instances.

in reply to Administrator

For an interesting story, read about the actor Wil Wheaton's first experience with Mastodon, years ago. He was one of the first very large Twitter users to abandon Twitter and move to Mastodon.

He was eventually forced off of a server by a very interesting harassment method -- attackers continuously made automated complaints against his account with the server admins.

in reply to tiddy roosevelt

yeah, this is really bad for small instances.

We need to come up with broader safety nets and support systems for them.

Unknown parent

BenjiButo :mastodance:

@neil
Gonna read the docs and see I can start one on my cluster. I heard it uses a lot of memory, that true?

@babe

Unknown parent

BenjiButo :mastodance:
@neil
Oh that's not a lot. What about hard disk space? Or can I limit caching?
@babe
in reply to tiddy roosevelt

Will the users of the tiny instances who give up just disappear or will they move to the tiny instances that survive?
Unknown parent

Bruce Heerssen
@monochrome
It's a problem. One person, or even a small team, can't manually verify 12,000 registrations. So for small instances, this is effectively a denial of service attack on new signups.
in reply to tiddy roosevelt

No ressources, so we went for applications and approval and I'm still glad we did, especially after the recent wave. That way, I could even joke about it when the wave hit. No big deal.

¯\_(ツ)_/¯

in reply to tiddy roosevelt

I took it as an opportunity to further develop my Automod, catches the spam within seconds of posting and bans the users.