⁂ ActivityPub.Space

Bot

@activitypub.space@activitypub.space · Created ⁨Aug⁩ ⁨2026⁩

⁂ ActivityPub.Space boosted

⚠️ #SW_ISAC_ADVISORY

Services continue to report a wave of automated account creation using the naming pattern "traffic" followed by a series of random alphanumerics, eg "trafficj4jq30o" or "traffic7rjc14h".

To date almost all accounts are created using an email address at the nawitop[.]ru domain.

Requiring approval or disallowing accounts using this email domain will severely curtail your spam account review activity.

Of note, IPQS scores all IPs used by this wave as 100/1000 for fraud.

⁂ ActivityPub.Space boosted

Replying to @⁨hongminhee@hollo.social⁩

@hongminhee

Well, after the issues with the given ActivityPub "OAuth example", I looked up
@fedify /vocab …

In all the actor types like github.com/fedify-dev/fedify/b

the following properties would be missing [if the official OAuth demo should work] :

:digitalcourage:
grant_types_supported: ['authorization_code'],

response_types_supported:
['code', 'code token'],

code_challenge_methods_supported: ['S256'],
token_endpoint_auth_methods_supported: [
'client_secret_basic'
// optional
/*, 'private_key_jwt'*/
],
token_endpoint_auth_signing_alg_values_supported: ['RS256', 'ES256'],
client_id_metadata_document_supported: true,

:digitalcourage: optional
scopes_supported and ui_locales_supported:

---

anyway:
I believe it is just misleading because of the order of querying the server and the actor description.

I would expect it to meet the spec and pull above properties from the server wide .well-known oauth and just the endpoints from the Actor …

#ActivityPub #OAuth

⁂ ActivityPub.Space boosted

⚠️ #SW_ISAC_ADVISORY

There is a spate of #AccountTakeover underway.

Service providers may receive reports for accounts that have a display name beginning with "Hacked -" or linking to "t[.]me/HomeFucker5"

These accounts may be longstanding valid accounts that have been hijacked.

While investigating, consider

1. deleting any offensive posts,
2. freezing the account until the rightful owner can reclaim it,
3. use of two-factor authentication for accounts shown to be at risk

example accounts after takeover
ALT

⁂ ActivityPub.Space boosted

Since when has discrimination on the basis of national origin become normalized on #Fediverse?

Here is Aral Balkin, agreeing that there is an "Israeli invasion" of Greece, and that Israelis should not be allowed even to visit Greece: archive.ph/EuEOm#selection-971

Or here is his buddy Fabio, describing Israelis as "bloodthirsty monsters" ghostarchive.org/archive/dgQWI

Advocating a travel ban for all Russians or Chinese ppl should be bannable, and so should this @staff

#Fediblock #Antizionism #FediAdmin

You don't get to hate Israeli people for being Israeli
ALT

⁂ ActivityPub.Space boosted

Replying to @⁨elduvelle@neuromatch.social⁩

re: [important] Sleeper account registrations on Fedi

@elduvelle @FediTips @jonny @johannab @dsalo @tante @jerry @futurebird @jonny
Maybe this idea is already obvious to mods, but my wife runs several facebook groups with constant spam signups. After adding some group-related signup questions which helped some, she added "are you here to sell things?". Nearly all the bots answer 'yes'.

Anyway, adding a question where the 'wrong' answer is 'yes' may help.

⁂ ActivityPub.Space boosted

DASOL

On the way back from #FediCon, we spent the night in a small BC town, and after checking in to our hotel, we headed to get a bite to eat.

The first place had a 30 min wait and recommended one just a few mins away. We got there and sat down, and realized they closed in 4 minutes.

They still served us, and we ended up staying 30 mins after closing. It was really good, and on the way back to our car, I took this pic.

10/10 ⭐️

BC and AB are so beautiful!

tripadvisor.ca/Restaurant_Revi

Rocky Mountains
ALT

⁂ ActivityPub.Space boosted

Replying to @⁨lienrag@mastodon.tedomum.net⁩

@lienrag

I agree the need for a signup message can be a discouragement... and at the same time, I'm aware that instances without _some_ kind of up-front vetting process generate a lot of relentless tedious banning-work for all the other mods!

Maybe one way to address this is with friendly encouragement on the sign-up page? including an explanation like "we're not trying to sit in judgement over who's cool enough, we're just trying to keep bots and spammers at bay, which you'll benefit from yourself once you're on".

And/or, the software needs the option of a provisional status, where someone's first few posts are moderated.

#Fediverse #onboarding #moderation #Mastodon

⁂ ActivityPub.Space boosted

Replying to @⁨lienrag@mastodon.tedomum.net⁩

@lienrag @elduvelle I've seen individuals looking to judge the physical existence of new posters use directed questions instead, I wonder if something like that could work for registration?

I wager it'd have to be oblique enough that a bot would screw it up but easy enough for a human to decipher or maybe paired with something LLM's continuously mess up.

e.g.

Tell me a little about your favorite object (it could be a plush animal, a kitchen utensil, a bed covering, a wall hanging, or even an item of clothing!)

And

Count how many "R"'s appear in the word "Strawberry".

Do LLM's ever fill out css-hidden honeypot fields?

⁂ ActivityPub.Space boosted

[important] Sleeper account registrations on Fedi

Post (mostly) for instance admins: spam / sleeper account registrations

Our server, with approved registrations (i.e. mods only accept new people after checking their "reasons to join") is still constantly getting spam account requests. (spam, for lack of a better word... maybe 'sleeper accounts'?)

These are not obviously immediate to the untrained eye, but it's been happening for months now and there are some clear patterns. Here's a list of what I've learned so far in case that's useful to other mods. Any additional advice welcome!

How to spot a sleeper account request (beyond the obvious):

  1. Always from a disposable email domain.
  2. Otherwise, a lot of them are from "proton.me" domain or "onionmail.org"
  3. request reads as if it was an account description, not an account request e.g. "writer, queer, loves cats, profile pic of a lake in front of a mountain, posts a lot about bread, here to share ideas and engage positively with the community, my DMs are open" - yeah it sounds like your average Fedi person, but that's probably because they scrape profiles from Fedi in the first place.
  4. The account request will not directly name your server or meaningfully answer the account request text
  5. The name of the account and of their email will have nothing to do with each other, e.g, username "colixal" and email "inyfupvtr@proton.me"
  6. the email usually looks random (see above), probably because they're all randomly-generated.

Solutions / mitigation (for Admins):

  1. Switch on approved registrations on your server! @FediTips has instructions for this.
  2. Tell in your server's account request description that you do not accept registration from disposable emails and you want specific reasons for choosing your server.
  3. How to spot a disposable email domain: you can check this list, but I don't think it's up to date. you can also search for the domain with quotes "domain.xyz" online and it will usually show up as being disposable.
  4. Once you know a domain is disposable, you can block registrations from it (User Preferences menu>Moderation> Blocked email domains > add new)
  5. in doubt, email the "person" to ask them more specific info. 50% of the time the email will bounce back, and 40% you will get no answer. That's your cue to reject those (and possibly add their domain to the block list, although you don't want to block non-disposable ones of course)
  6. requesting a donation, even minimal (say 10p per account) would probably completely block those.
  7. It is possible that we've already accepted a few of the sleeper accounts. We should all probably go back and check everything out (yes, that's easier when you have a small server).
  8. Any other suggestions / tips? Let us know!

Of course, some of these measures are bound to also prevent some genuine people from joining. In this case I think it's worth it, and also, if you can't be bothered writing 3 lines of text to explain why you chose a server then maybe you wouldn't be contributing to Fedi much anyway.

Quantification

We are a very small server (150 active accounts) and are getting about 1-3 such requests per day when our usual rate of genuine requests is about 1-2 per month (well, except when @jonny makes a post that pierces the thin veil with the real world). I can't imagine how many of those must be infiltrating large, open instances like mastodon.social... Have any of you people on other servers noticed it? Please let us know in answers. And if anyone personally knows one of the mastodon.social mods it would be interesting to hear from their point of view.

Possible goals and consequences

  • wasting our time
  • making it harder for genuine people to join
  • sudden spamming
  • use all the server's storage to block the server
  • propaganda
  • harassment (possibly in private posts so they can't be reported)
  • anything else? In any case, no good can come out of it.

Other posts noticing this

quoting @johannab:
cosocial.ca/@johannab/11685687
quoting @dsalo:
digipres.club/@dsalo/117039864
quoting @tante:
tldr.nettime.org/@tante/116845
quoting @jerry who mentioned making a script to auto-block the disposable domains - I don't know if this exists now?
infosec.exchange/@jerry/116805
and
infosec.exchange/@jerry/116846
quoting @futurebirds@sauropods.win:
sauropods.win/@futurebird/1171

PS: If you answer please un-tag all these nice people to avoid spamming them!

#MastoAdmin #MastoAdminTip #FediAdmin #AcountRequests #SleeperAccounts #SpamAccounts

fedi.tips/controlling-sign-ups-on-your-mastodon-server/

⁂ ActivityPub.Space boosted

Replying to @⁨fediforum@mastodon.social⁩

@fediforum

I’ve been to every #FediForum since the first one and I’ve loved every one of them.

At first I had #ImposterSyndrome, but everyone was so welcoming, that feeling soon passed once the conversations started to flow and I learned so much.

At #FediForum I first saw @_elena’s brilliant video about the #Fediverse and I’ve met such interesting people who I look forward to seeing again at this #FediForum.

Huge thanks to all the organisers, especially @j12t for creating the #FediForum 👏👏👏