Ancestors

Toot

Written by Cory Doctorow on 2024-10-08 at 23:15

Learning that today's massive Mastodon spam attack was carried out by conspiracy-addled Japanese middle-schoolers whose previous spam run was shut down when admins got in touch with their parents who confiscated their devices is definitely straight of the Shitty Timeline Little Brother.

=> More informations about this toot | More toots from pluralistic

Descendants

Written by Das on 2024-10-08 at 23:21

@pluralistic wow

=> More informations about this toot | More toots from SRDas@mastodon.online

Written by jcriecke on 2024-10-08 at 23:22

@pluralistic that is too ridiculous, no. that's a parks & rec plot.

=> More informations about this toot | More toots from jcriecke@urbanists.social

Written by 🌳 The Grove 🌳 on 2024-10-08 at 23:23

@pluralistic wait, conspiracy addled? V curious what the conspiracy is

=> More informations about this toot | More toots from thedandeliongrove@translunar.academy

Written by MichaΕ‚ "rysiek" WoΕΊniak Β· πŸ‡ΊπŸ‡¦ on 2024-10-08 at 23:26

@pluralistic I do think that fedi handled this one pretty well.

Doesn't seem like there was a lot of disruption.

Some fedizens (myself included) had to deal with a bunch of spam, but reporting worked, moderators did a fantastic job, and by and large most people don't seem to have even noticed?

=> More informations about this toot | More toots from rysiek@mstdn.social

Written by Ben Butler on 2024-10-09 at 00:55

@rysiek @pluralistic Didn't see any spam here. Thanks @stux!

=> More informations about this toot | More toots from benfrog@mstdn.social

Written by stux⚑ on 2024-10-09 at 00:56

@benfrog @rysiek @pluralistic There's been sooooo much :amaze:

Suspended hundreds of accs today

=> More informations about this toot | More toots from stux@mstdn.social

Written by Ben Butler on 2024-10-09 at 00:57

@stux @rysiek @pluralistic You''ve been doing a heck of a job. As a user I've seen zero disruption!

=> More informations about this toot | More toots from benfrog@mstdn.social

Written by Ted Garrison on 2024-10-09 at 01:10

@stux @benfrog @rysiek @pluralistic Awesome job then, as I haven't seen a bit!

=> More informations about this toot | More toots from Tedgarrison3@mstdn.social

Written by paul on 2024-10-09 at 04:35

@stux @benfrog @rysiek @pluralistic

=> View attached media

=> More informations about this toot | More toots from amiserabilist@beige.party

Written by David W. Jones on 2024-10-09 at 00:57

@rysiek

I saw no spam, didn't even know it happened, so GOOD JOB, #FediMods #FediModeration

@pluralistic @Szescstopni

=> More informations about this toot | More toots from dancingtreefrog@mastodon.social

Written by Szescstopni on 2024-10-09 at 01:00

@dancingtreefrog @rysiek @pluralistic Neither did I. I wonderif a centralized system would handle it any better.

=> More informations about this toot | More toots from Szescstopni@circumstances.run

Written by David W. Jones on 2024-10-09 at 02:17

@Szescstopni

I don't know. FediVerse has a lot of ways to manage connections and a lot of admins to handle them. Centralized (like the late Twitter/X) don't have nearly as many admins now, I suspect. Plus I think it profits from the spammers, so has no motivation to stop them...

@rysiek @pluralistic

=> More informations about this toot | More toots from dancingtreefrog@mastodon.social

Written by Aunty on 2024-10-09 at 01:24

@rysiek @pluralistic this is the first I'm hearing of it lol

=> More informations about this toot | More toots from AuntyRed@aus.social

Written by πŸŽ„ Tony Bark :pawified: on 2024-10-09 at 02:51

@rysiek @pluralistic I'm only hearing about this now. My instance is small. I imported a huge block list of bad or questionable actors to avoid future headaches. So that one might have already been preemptively blocked.

=> More informations about this toot | More toots from tonytins@tonybark.com

Written by Misty on 2024-10-09 at 02:57

@rysiek Speaking as a server admin, I can say the moderation load has been highly disruptive. πŸ˜… I'm grateful most users don't have to notice, but for those who got hit it was intense - both for end users, and for moderators who had to clean up.

=> More informations about this toot | More toots from misty@digipres.club

Written by MichaΕ‚ "rysiek" WoΕΊniak Β· πŸ‡ΊπŸ‡¦ on 2024-10-09 at 10:07

@misty I imagine. I submitted a couple dozen spam reports myself. It's somewhat intense for me, I cannot imagine what moderation teams are dealing with.

=> More informations about this toot | More toots from rysiek@mstdn.social

Written by Oblomov on 2024-10-09 at 11:45

@rysiek @misty still, I feel like these spam waves would be almost trivial to contain with even the simplest of filters.

=> More informations about this toot | More toots from oblomov@sociale.network

Written by Colin the Mathmo on 2024-10-09 at 14:50

@oblomov True for a while, but not for long. Once you have simple filters the spammers find a way to get around them. And so it goes.

In this case my tech admin has a small script that dealt with it all.

So, yeah, it's whack-a-mole.

CC: @rysiek @misty

=> More informations about this toot | More toots from ColinTheMathmo@mathstodon.xyz

Written by Oblomov on 2024-10-09 at 15:32

@ColinTheMathmo of course, spam filters only raise the bar and can be circumvented, but at the moment that bar is basically underground, so even just a little bit would help ;-)

I'm honestly thinking about a small script myself as a user, but I don't know if it's possible to automate the reporting.

@rysiek @misty

=> More informations about this toot | More toots from oblomov@sociale.network

Written by Misty on 2024-10-09 at 15:36

@oblomov @rysiek Unfortunately, the builtin moderation tools don’t support anything like that.

=> More informations about this toot | More toots from misty@digipres.club

Written by Osma A on 2024-10-09 at 03:57

@rysiek

All I saw was a couple of toots wondering what's going on. @trumpet whatever you did it worked wonders, so thank you for your work!

=> More informations about this toot | More toots from osma@mas.to

Written by Oblomov on 2024-10-09 at 06:05

@rysiek @pluralistic well I'm still noticing ;-)

=> More informations about this toot | More toots from oblomov@sociale.network

Written by εΎ’ α›‹α›–α›α›αš© γ‚»γƒƒγƒˆ on 2024-10-08 at 23:30

@pluralistic@mamot.fr a detail maybe, but is it really an attack if creating an account is open to anyone without any reviewing process?

=> More informations about this toot | More toots from setto@s.basspistol.org

Written by :jan:‍:abreath:🌬️:dandelion: on 2024-10-09 at 00:17

@setto @pluralistic just because the devs think it's not their problem to solve doesn't mean it's a problem and not how it's supposed to be used

=> More informations about this toot | More toots from Crazypedia@pagan.plus

Written by calcifer :nes_fire: on 2024-10-09 at 00:22

@setto @pluralistic is it still malice for someone to destroy my garden if I don’t put up a fence?

=> More informations about this toot | More toots from calcifer@hackers.town

Written by Lord Kusuriya ​:tower:​ on 2024-10-09 at 00:36

@calcifer @setto @pluralistic if they had malice yes.

=> More informations about this toot | More toots from kusuriya@hackers.town

Written by calcifer :nes_fire: on 2024-10-09 at 00:38

@kusuriya @setto @pluralistic genau. So if someone conducts a spam attack, it’s still an attack if the intent was to spam everyone (instead of, say, an accident). It has nothing to do with what controls were in place.

=> More informations about this toot | More toots from calcifer@hackers.town

Written by Lord Kusuriya ​:tower:​ on 2024-10-09 at 00:39

@calcifer @setto @pluralistic thats always been my view. an attack is an attack if its intent was meant to be an attack.

=> More informations about this toot | More toots from kusuriya@hackers.town

Written by εΎ’ α›‹α›–α›α›αš© γ‚»γƒƒγƒˆ on 2024-10-09 at 07:00

@kusuriya@hackers.town @calcifer@hackers.town @pluralistic@mamot.fr

Fair points. I guess what i'm trying to convey is that i think enormous freebeer-for-all instances are a danger. Because at that scale, moderation becomes a full time large-team job and can only be applied post mortem.

=> More informations about this toot | More toots from setto@s.basspistol.org

Written by Lord Kusuriya ​:tower:​ on 2024-10-09 at 15:01

@setto @pluralistic @calcifer To some degree moderation can only be reactionary. We probably as a group of communities need to take pages from the books of operations engineers or cybersecurity groups. It would probably look something like you will always have an incident response team that is acting against threats we know, A larger team acting against threats we know exist but we don't know who they are yet, and a team that is looking for threats that we haven't even thought about.

Once we manage what we know, what we know we don't know, and what we don't know we don't know only then can we build proactive defense to help lighten the burden of reactionary defense.

But I'm rambling

=> More informations about this toot | More toots from kusuriya@hackers.town

Written by εΎ’ α›‹α›–α›α›αš© γ‚»γƒƒγƒˆ on 2024-10-09 at 15:54

@kusuriya@hackers.town

I think you make sense. And i agree in many ways. Especially in terms of conflict resolution. But preventing spam attacks on fedi i actually pretty easy: put in place a vetting protocole for new registrants.

To quote myself from another part of this thread, it's a tough one. On one hand it is nice that the network is accessible to the masses and remains an affordable alternative. On the other hand, i find myself wishing the appeal of the network would be more centered around cooperation and mutual aid in running services, and less around being a quick fix for the corporate social media catastrophe.

@pluralistic@mamot.fr @calcifer@hackers.town

=> More informations about this toot | More toots from setto@s.basspistol.org

Written by Lord Kusuriya ​:tower:​ on 2024-10-09 at 16:02

@setto @pluralistic @calcifer Yes and that sort of falls into the known unknowns bucket. We could probably do the same thing that old style community forums did. You have a probationary period, that probationary period stops you from posting to other instances until your local community gets to know you. Maybe if you have 0 posts or interactions within the probationary period your account gets auto-binned, and maybe the promotion process is non automated.

There is a lot that could be done in the space if we stop thinking about the fedi being the replacement to social media and think of it more as groups of communities coming together.

=> More informations about this toot | More toots from kusuriya@hackers.town

Written by εΎ’ α›‹α›–α›α›αš© γ‚»γƒƒγƒˆ on 2024-10-09 at 16:05

@kusuriya@hackers.town

​:metathis:​

thanks for giving me the benefit of the doubt and bouncing ideas with me. I realize my initial response to OP wasn't conveying my idea very well, but i received some pretty visceral reactions, which your eloquence is slowly making me forget ​:cyber_heart_sparkle_purple:​

@pluralistic@mamot.fr @calcifer@hackers.town

=> More informations about this toot | More toots from setto@s.basspistol.org

Written by Lord Kusuriya ​:tower:​ on 2024-10-09 at 16:11

@setto @pluralistic @calcifer Thank you. I always fear people forget that on the other end of the screen is a person, and I always try to remember that because it clues me into things like maybe this isn't their first language. Maybe they don't have words for what they are trying to communicate yet. Maybe they just have a really vague idea and are hoping someone with another part of their vague idea will bring crayons over and help color it in.

Using that has always kept me centered and helped me find new ideas.

Its also a great way to find sneaky nazi shit heels and ban their recruiting instances.

=> More informations about this toot | More toots from kusuriya@hackers.town

Written by Jack Linke πŸ¦„ on 2024-10-09 at 01:09

@setto @pluralistic Great. The "well, technically... 🧐" folks have arrived πŸ™„

=> More informations about this toot | More toots from jack@social.jacklinke.com

Written by Davey on 2024-10-09 at 08:38

@jack @setto @pluralistic

Great. The Great. people have arrived πŸ˜‰

Setto has a good point though, .social's practice of not using registration approval is an open door for this stuff.

The sewage runs downstream and 80-90% of report handling for other servers is spam from name+numbers accounts at .social

It's a pain in the face and we all have to suffer from their decision.

=> More informations about this toot | More toots from davey_cakes@mastodon.ie

Written by εΎ’ α›‹α›–α›α›αš© γ‚»γƒƒγƒˆ on 2024-10-09 at 08:45

@davey_cakes@mastodon.ie

thanks! if only it was confined to .social It's a tough nut: on one hand it is nice that the network is accessible to the masses and remains an affordable alternative. On the other hand, i wish the appeal of the network would be more centered around cooperation and mutual aid in running services, and less around being a quick fix for the corporate social media catastrophe.

@jack@social.jacklinke.com @pluralistic@mamot.fr

=> More informations about this toot | More toots from setto@s.basspistol.org

Written by :jan:‍:abreath:🌬️:dandelion: on 2024-10-08 at 23:36

@pluralistic hold on I have to check my bingo card for this one

=> More informations about this toot | More toots from Crazypedia@pagan.plus

Written by Mx Verda on 2024-10-08 at 23:37

@pluralistic well shit. Now I feel kinda bad for posting https://www.youtube.com/watch?v=u_4adkAymrg in response a few times.

But also, that explains why I could almost read it without much effort (kids use fewer kanji, which are like letters, words, or phonemes β€” parts of words with meaning when combined? Idk, I’m not a linguist, just a long covid addled dweeboid with insomnia)

=> More informations about this toot | More toots from MxVerda@lgbtqia.space

Written by Preston Is Not My Real Name on 2024-10-08 at 23:37

@pluralistic wow I had no idea there was even an attack. Somehow, your explanation leaves me with more questions than if I knew nothing at all

=> More informations about this toot | More toots from prestontumber@mastodon.social

Written by Alain Dellepiane :eit: :pm: on 2024-10-09 at 00:11

@pluralistic Icing on the cake: these attacks are carried through Discord scripting. Because Discord is so self-absorbed they don't even check if their scripts are bothering the world at large.

=> More informations about this toot | More toots from aran@localization.cafe

Written by Florian Berger (privat) on 2024-10-09 at 06:03

@aran

What.

I don't know anything about that. I can run scripts on Discord, and they will happily do HTTP requests to other servers?

=> More informations about this toot | More toots from flberger@nerdculture.de

Written by Alain Dellepiane :eit: :pm: on 2024-10-09 at 06:16

@flberger https://techcrunch.com/2024/02/21/discord-took-no-action-against-server-that-coordinated-costly-mastodon-spam-attacks/

=> View attached media

=> More informations about this toot | More toots from aran@localization.cafe

Written by shadowwwind on 2024-10-09 at 07:58

@aran @flberger no discord is not hosting scripts. The article sound like they used discord bots to interface with their server.

Or maybe they abused a badly designed Discord bot but that would be the bot owners fault

=> More informations about this toot | More toots from shadowwwind@fosstodon.org

Written by Alain Dellepiane :eit: :pm: on 2024-10-09 at 08:23

@shadowwwind @flberger

The article states clearly how they didn't need any external server and the attack was launched directly from Discord.

Techcrunch seems a fairly reliable source too, but I'm not technical enough to argue either way. I hate Discord regardless πŸ˜†

=> More informations about this toot | More toots from aran@localization.cafe

Written by shadowwwind on 2024-10-09 at 08:25

@aran @flberger I have used the discord api, it does host scripts for you.

It probably means, that somebody, set up a server, connected to the discord bot and people that don't know how to code use it to start spam waves.

=> More informations about this toot | More toots from shadowwwind@fosstodon.org

Written by Alain Dellepiane :eit: :pm: on 2024-10-09 at 08:30

@shadowwwind @flberger

Admittedly, understanding the passage in full is made complicated by the terminology overlap between script and bot and (most importantly) between a "server" as a stand-alone computer on the network and "server" as in an instance of Discord itself.

Still, the title "Discord took no action against server that coordinated costly Mastodon spam attacks" should leave no ambiguity about the main issue at play πŸ˜„

=> More informations about this toot | More toots from aran@localization.cafe

Written by shadowwwind on 2024-10-09 at 08:47

@aran @flberger some discord bots allow you to create customer commands and use http requests, they might abuse something like that. But that is not possible for Discord to control

=> More informations about this toot | More toots from shadowwwind@fosstodon.org

Written by Alain Dellepiane :eit: :pm: on 2024-10-09 at 08:49

@shadowwwind @flberger

Ok. It still sounds like a failure of moderation to me. Especially after they have been told about it.

=> More informations about this toot | More toots from aran@localization.cafe

Written by shadowwwind on 2024-10-09 at 08:47

@aran @flberger considering there are servers where discord users try to bait minors into sending nudes, I understand it's not their top priority

=> More informations about this toot | More toots from shadowwwind@fosstodon.org

Written by Alain Dellepiane :eit: :pm: on 2024-10-09 at 08:54

@shadowwwind @flberger

That's an interesting form of Whataboutism you got there πŸ˜„

"You think that's bad for Discord standards? YOU GOT NO IDEA"

=> More informations about this toot | More toots from aran@localization.cafe

Written by matthewfarrer on 2024-10-09 at 00:15

@pluralistic Shittle Brother?

=> More informations about this toot | More toots from matthewfarrer@mastodon.social

Written by Just Bob πŸ‡ΊπŸ‡²β™’πŸ§πŸͺ– on 2024-10-09 at 00:17

@pluralistic

I'm not saying that it isn't happening but I find it incredible that Beamship apparently is to small to bother with. We have less than 50 user. Very manageable and personal with such a small system.

Of course, I'm the only one that gets reported πŸ˜‚

=> More informations about this toot | More toots from bob@beamship.mpaq.org

Written by faraiwe on 2024-10-09 at 00:55

@pluralistic πŸ˜‚

=> More informations about this toot | More toots from faraiwe@beige.party

Written by Holiday's Over, πŸ‘€ Patty. on 2024-10-09 at 00:59

@pluralistic They will not get off scott-free. They have brought embarrassment and shame to their families, and now have a significant misdeed on their permanent school records which, in highly competitive high school admission (and even more competitive university admission) may well tank their future lives.

Japan is a judgemental accountability culture.

=> More informations about this toot | More toots from pattykimura@beige.party

Written by Orca 🌻 | πŸŽ€ | πŸͺ | πŸ΄πŸ³οΈβ€βš§οΈ on 2024-10-09 at 01:47

@pluralistic@mamot.fr Conspiracy? iirc they're a massive cyberbullying gang that doxxes people?

=> More informations about this toot | More toots from Orca@nya.one

Written by Jason Dyer on 2024-10-09 at 02:44

@pluralistic why are we talking about this past tense? My last spam message was 43 minutes ago, still rolling in regularly

=> More informations about this toot | More toots from jdyer@mastodon.gamedev.place

Written by Tushar Chauhan on 2024-10-09 at 02:48

@pluralistic Aha. That explains all the kanji I'm seeing in the most popular tags for the day.

=> More informations about this toot | More toots from tchauhan@mastodon.mit.edu

Written by Deborah Yoon Zacharias on 2024-10-09 at 03:14

@pluralistic I didn't notice anything, but the story blows my mind.

=> More informations about this toot | More toots from deborahyz@sfba.social

Written by Gnorzaps on 2024-10-09 at 03:23

@pluralistic Kind of disappointed now that I missed out on the fun.

=> More informations about this toot | More toots from zappy@techhub.social

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113274343620089198
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
746.42603 milliseconds
Gemini-to-HTML Time
25.632162 milliseconds

This content has been proxied by September (3851b).