Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Well this is concerning.

Well this is concerning.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
19 Indlæg 18 Posters 13 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • leo@twit.socialL This user is from outside of this forum
    leo@twit.socialL This user is from outside of this forum
    leo@twit.social
    wrote sidst redigeret af
    #1

    Well this is concerning.

    I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

    Thanks to IFTAS SW-ISAC for noting and reporting the bots.

    viss@mastodon.socialV andrewh@twit.socialA ariarhythmic@ohai.socialA serge@babka.socialS god@tlv.coolG 14 Replies Last reply
    1
    0
    • leo@twit.socialL leo@twit.social

      Well this is concerning.

      I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

      Thanks to IFTAS SW-ISAC for noting and reporting the bots.

      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.social
      wrote sidst redigeret af
      #2

      @leo this is a pretty big deal. if youre running the stock mastodon code and not something like glitchsoc, this is worth submitting an issue to github about

      anticomposite@wikis.worldA 1 Reply Last reply
      0
      • leo@twit.socialL leo@twit.social

        Well this is concerning.

        I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

        Thanks to IFTAS SW-ISAC for noting and reporting the bots.

        andrewh@twit.socialA This user is from outside of this forum
        andrewh@twit.socialA This user is from outside of this forum
        andrewh@twit.social
        wrote sidst redigeret af
        #3

        @leo is that perhaps the period where your subscription had expired?

        1 Reply Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          @leo this is a pretty big deal. if youre running the stock mastodon code and not something like glitchsoc, this is worth submitting an issue to github about

          anticomposite@wikis.worldA This user is from outside of this forum
          anticomposite@wikis.worldA This user is from outside of this forum
          anticomposite@wikis.world
          wrote sidst redigeret af
          #4

          RE: https://mastodon.iftas.org/@iftas/116426965511875330

          @Viss @leo the current tactic seems to be getting a legit-looking account through review, then using invites (which bypass review) to create the spam accounts.

          viss@mastodon.socialV 1 Reply Last reply
          0
          • anticomposite@wikis.worldA anticomposite@wikis.world

            RE: https://mastodon.iftas.org/@iftas/116426965511875330

            @Viss @leo the current tactic seems to be getting a legit-looking account through review, then using invites (which bypass review) to create the spam accounts.

            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.social
            wrote sidst redigeret af
            #5

            @anticomposite @leo oh interesting - you think there are approved accounts already in there that are farming invites out to the bots?

            1 Reply Last reply
            0
            • leo@twit.socialL leo@twit.social

              Well this is concerning.

              I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

              Thanks to IFTAS SW-ISAC for noting and reporting the bots.

              ariarhythmic@ohai.socialA This user is from outside of this forum
              ariarhythmic@ohai.socialA This user is from outside of this forum
              ariarhythmic@ohai.social
              wrote sidst redigeret af
              #6

              @leo Are existing members allowed to create invites that bypass review?

              oli@olifant.socialO 1 Reply Last reply
              0
              • leo@twit.socialL leo@twit.social

                Well this is concerning.

                I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                serge@babka.socialS This user is from outside of this forum
                serge@babka.socialS This user is from outside of this forum
                serge@babka.social
                wrote sidst redigeret af
                #7

                @leo

                How did they circumvent your manual process?

                1 Reply Last reply
                0
                • leo@twit.socialL leo@twit.social

                  Well this is concerning.

                  I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                  Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                  god@tlv.coolG This user is from outside of this forum
                  god@tlv.coolG This user is from outside of this forum
                  god@tlv.cool
                  wrote sidst redigeret af
                  #8

                  @leo concerning is an understatement here, Leo.

                  1 Reply Last reply
                  0
                  • leo@twit.socialL leo@twit.social

                    Well this is concerning.

                    I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                    Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                    hamishtpb@mewblog.thepolarbear.co.ukH This user is from outside of this forum
                    hamishtpb@mewblog.thepolarbear.co.ukH This user is from outside of this forum
                    hamishtpb@mewblog.thepolarbear.co.uk
                    wrote sidst redigeret af
                    #9

                    @leo Can I confirm - this is on Mastodon's server software?

                    1 Reply Last reply
                    0
                    • leo@twit.socialL leo@twit.social

                      Well this is concerning.

                      I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                      Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                      scattapilla@jorts.horseS This user is from outside of this forum
                      scattapilla@jorts.horseS This user is from outside of this forum
                      scattapilla@jorts.horse
                      wrote sidst redigeret af
                      #10

                      @leo looking at the account in modtools should say the inviter name, just ban them too

                      1 Reply Last reply
                      0
                      • leo@twit.socialL leo@twit.social

                        Well this is concerning.

                        I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                        Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                        curiously@mastodon.auC This user is from outside of this forum
                        curiously@mastodon.auC This user is from outside of this forum
                        curiously@mastodon.au
                        wrote sidst redigeret af
                        #11

                        @leo hey thanks for your work in finding and removing these bots. Much appreciated the horde of admins across the Fediverse do an awesome job keeping this a safe place that's people first. Thank you.

                        iveyline@mastodon.nzI 1 Reply Last reply
                        0
                        • leo@twit.socialL leo@twit.social

                          Well this is concerning.

                          I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                          Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                          oregon_pacifist@retro-gaiden.comO This user is from outside of this forum
                          oregon_pacifist@retro-gaiden.comO This user is from outside of this forum
                          oregon_pacifist@retro-gaiden.com
                          wrote sidst redigeret af
                          #12

                          @leo yeah, there was a wave of bots that joined my instance. Enabling Captcha didn’t slow them down at all. The only thing that helped was requiring new accounts to write a reason to join. Haven’t seen a bot since.

                          1 Reply Last reply
                          0
                          • leo@twit.socialL leo@twit.social

                            Well this is concerning.

                            I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                            Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                            brothercasas@twit.socialB This user is from outside of this forum
                            brothercasas@twit.socialB This user is from outside of this forum
                            brothercasas@twit.social
                            wrote sidst redigeret af
                            #13

                            @leo thanks for keeping this server safe. 👍

                            1 Reply Last reply
                            0
                            • leo@twit.socialL leo@twit.social

                              Well this is concerning.

                              I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                              Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                              roryh@twit.socialR This user is from outside of this forum
                              roryh@twit.socialR This user is from outside of this forum
                              roryh@twit.social
                              wrote sidst redigeret af
                              #14

                              @leo thanks for putting in the effort to keep this instance clean!

                              1 Reply Last reply
                              0
                              • leo@twit.socialL leo@twit.social

                                Well this is concerning.

                                I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                                Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                                beet1123@twit.socialB This user is from outside of this forum
                                beet1123@twit.socialB This user is from outside of this forum
                                beet1123@twit.social
                                wrote sidst redigeret af
                                #15

                                @leo ims i had to give a reason to join

                                1 Reply Last reply
                                0
                                • ariarhythmic@ohai.socialA ariarhythmic@ohai.social

                                  @leo Are existing members allowed to create invites that bypass review?

                                  oli@olifant.socialO This user is from outside of this forum
                                  oli@olifant.socialO This user is from outside of this forum
                                  oli@olifant.social
                                  wrote sidst redigeret af
                                  #16

                                  @ariarhythmic @leo This is how it's being done by the 'Portal Kombat' crew. They use existing accounts and use server invites to bypass registration checks.

                                  1 Reply Last reply
                                  0
                                  • curiously@mastodon.auC curiously@mastodon.au

                                    @leo hey thanks for your work in finding and removing these bots. Much appreciated the horde of admins across the Fediverse do an awesome job keeping this a safe place that's people first. Thank you.

                                    iveyline@mastodon.nzI This user is from outside of this forum
                                    iveyline@mastodon.nzI This user is from outside of this forum
                                    iveyline@mastodon.nz
                                    wrote sidst redigeret af
                                    #17

                                    @curiously @leo Yes, thanks a million. It is really appreciated.

                                    1 Reply Last reply
                                    0
                                    • leo@twit.socialL leo@twit.social

                                      Well this is concerning.

                                      I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                                      Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                                      nihilistic_capybara@layer8.spaceN This user is from outside of this forum
                                      nihilistic_capybara@layer8.spaceN This user is from outside of this forum
                                      nihilistic_capybara@layer8.space
                                      wrote sidst redigeret af
                                      #18

                                      @leo aren't traditional capchas kind of a solved problem in machine learning?

                                      1 Reply Last reply
                                      0
                                      • leo@twit.socialL leo@twit.social

                                        Well this is concerning.

                                        I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                                        Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                                        evan@cosocial.caE This user is from outside of this forum
                                        evan@cosocial.caE This user is from outside of this forum
                                        evan@cosocial.ca
                                        wrote sidst redigeret af
                                        #19

                                        @leo thanks for keeping vigilant, Leo!

                                        1 Reply Last reply
                                        0
                                        • tanyakaroli@expressional.socialT tanyakaroli@expressional.social shared this topic
                                        Svar
                                        • Svar som emne
                                        Login for at svare
                                        • Ældste til nyeste
                                        • Nyeste til ældste
                                        • Most Votes


                                        • Log ind

                                        • Har du ikke en konto? Tilmeld

                                        • Login or register to search.
                                        Powered by NodeBB Contributors
                                        Graciously hosted by data.coop
                                        • First post
                                          Last post
                                        0
                                        • Hjem
                                        • Seneste
                                        • Etiketter
                                        • Populære
                                        • Verden
                                        • Bruger
                                        • Grupper