Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Well this is concerning.

Well this is concerning.

Scheduled Pinned Locked Moved Uncategorized
22 Posts 21 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • leo@twit.socialL leo@twit.social

    Well this is concerning.

    I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

    Thanks to IFTAS SW-ISAC for noting and reporting the bots.

    andrewh@twit.socialA This user is from outside of this forum
    andrewh@twit.socialA This user is from outside of this forum
    andrewh@twit.social
    wrote last edited by
    #3

    @leo is that perhaps the period where your subscription had expired?

    1 Reply Last reply
    0
    • viss@mastodon.socialV viss@mastodon.social

      @leo this is a pretty big deal. if youre running the stock mastodon code and not something like glitchsoc, this is worth submitting an issue to github about

      anticomposite@wikis.worldA This user is from outside of this forum
      anticomposite@wikis.worldA This user is from outside of this forum
      anticomposite@wikis.world
      wrote last edited by
      #4

      RE: https://mastodon.iftas.org/@iftas/116426965511875330

      @Viss @leo the current tactic seems to be getting a legit-looking account through review, then using invites (which bypass review) to create the spam accounts.

      viss@mastodon.socialV 1 Reply Last reply
      0
      • anticomposite@wikis.worldA anticomposite@wikis.world

        RE: https://mastodon.iftas.org/@iftas/116426965511875330

        @Viss @leo the current tactic seems to be getting a legit-looking account through review, then using invites (which bypass review) to create the spam accounts.

        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.social
        wrote last edited by
        #5

        @anticomposite @leo oh interesting - you think there are approved accounts already in there that are farming invites out to the bots?

        1 Reply Last reply
        0
        • leo@twit.socialL leo@twit.social

          Well this is concerning.

          I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

          Thanks to IFTAS SW-ISAC for noting and reporting the bots.

          ariarhythmic@ohai.socialA This user is from outside of this forum
          ariarhythmic@ohai.socialA This user is from outside of this forum
          ariarhythmic@ohai.social
          wrote last edited by
          #6

          @leo Are existing members allowed to create invites that bypass review?

          oli@olifant.socialO 1 Reply Last reply
          0
          • leo@twit.socialL leo@twit.social

            Well this is concerning.

            I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

            Thanks to IFTAS SW-ISAC for noting and reporting the bots.

            serge@babka.socialS This user is from outside of this forum
            serge@babka.socialS This user is from outside of this forum
            serge@babka.social
            wrote last edited by
            #7

            @leo

            How did they circumvent your manual process?

            1 Reply Last reply
            0
            • leo@twit.socialL leo@twit.social

              Well this is concerning.

              I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

              Thanks to IFTAS SW-ISAC for noting and reporting the bots.

              god@tlv.coolG This user is from outside of this forum
              god@tlv.coolG This user is from outside of this forum
              god@tlv.cool
              wrote last edited by
              #8

              @leo concerning is an understatement here, Leo.

              1 Reply Last reply
              0
              • R relay@relay.mycrowd.ca shared this topic
                R relay@relay.publicsquare.global shared this topic
              • leo@twit.socialL leo@twit.social

                Well this is concerning.

                I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                hamishtpb@mewblog.thepolarbear.co.ukH This user is from outside of this forum
                hamishtpb@mewblog.thepolarbear.co.ukH This user is from outside of this forum
                hamishtpb@mewblog.thepolarbear.co.uk
                wrote last edited by
                #9

                @leo Can I confirm - this is on Mastodon's server software?

                1 Reply Last reply
                0
                • leo@twit.socialL leo@twit.social

                  Well this is concerning.

                  I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                  Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                  scattapilla@jorts.horseS This user is from outside of this forum
                  scattapilla@jorts.horseS This user is from outside of this forum
                  scattapilla@jorts.horse
                  wrote last edited by
                  #10

                  @leo looking at the account in modtools should say the inviter name, just ban them too

                  1 Reply Last reply
                  0
                  • leo@twit.socialL leo@twit.social

                    Well this is concerning.

                    I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                    Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                    oregon_pacifist@retro-gaiden.comO This user is from outside of this forum
                    oregon_pacifist@retro-gaiden.comO This user is from outside of this forum
                    oregon_pacifist@retro-gaiden.com
                    wrote last edited by
                    #11

                    @leo yeah, there was a wave of bots that joined my instance. Enabling Captcha didn’t slow them down at all. The only thing that helped was requiring new accounts to write a reason to join. Haven’t seen a bot since.

                    1 Reply Last reply
                    0
                    • leo@twit.socialL leo@twit.social

                      Well this is concerning.

                      I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                      Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                      brothercasas@twit.socialB This user is from outside of this forum
                      brothercasas@twit.socialB This user is from outside of this forum
                      brothercasas@twit.social
                      wrote last edited by
                      #12

                      @leo thanks for keeping this server safe. 👍

                      1 Reply Last reply
                      0
                      • leo@twit.socialL leo@twit.social

                        Well this is concerning.

                        I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                        Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                        roryh@twit.socialR This user is from outside of this forum
                        roryh@twit.socialR This user is from outside of this forum
                        roryh@twit.social
                        wrote last edited by
                        #13

                        @leo thanks for putting in the effort to keep this instance clean!

                        1 Reply Last reply
                        0
                        • leo@twit.socialL leo@twit.social

                          Well this is concerning.

                          I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                          Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                          bob@beamship.mpaq.orgB This user is from outside of this forum
                          bob@beamship.mpaq.orgB This user is from outside of this forum
                          bob@beamship.mpaq.org
                          wrote last edited by
                          #14

                          @leo yep, mastodon 4.5.9 ...

                          Link Preview Image
                          1 Reply Last reply
                          0
                          • leo@twit.socialL leo@twit.social

                            Well this is concerning.

                            I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                            Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                            beet1123@twit.socialB This user is from outside of this forum
                            beet1123@twit.socialB This user is from outside of this forum
                            beet1123@twit.social
                            wrote last edited by
                            #15

                            @leo ims i had to give a reason to join

                            1 Reply Last reply
                            0
                            • ariarhythmic@ohai.socialA ariarhythmic@ohai.social

                              @leo Are existing members allowed to create invites that bypass review?

                              oli@olifant.socialO This user is from outside of this forum
                              oli@olifant.socialO This user is from outside of this forum
                              oli@olifant.social
                              wrote last edited by
                              #16

                              @ariarhythmic @leo This is how it's being done by the 'Portal Kombat' crew. They use existing accounts and use server invites to bypass registration checks.

                              1 Reply Last reply
                              0
                              • iveyline@mastodon.nzI This user is from outside of this forum
                                iveyline@mastodon.nzI This user is from outside of this forum
                                iveyline@mastodon.nz
                                wrote last edited by
                                #17

                                @curiously @leo Yes, thanks a million. It is really appreciated.

                                1 Reply Last reply
                                0
                                • leo@twit.socialL leo@twit.social

                                  Well this is concerning.

                                  I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                                  Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                                  nihilistic_capybara@layer8.spaceN This user is from outside of this forum
                                  nihilistic_capybara@layer8.spaceN This user is from outside of this forum
                                  nihilistic_capybara@layer8.space
                                  wrote last edited by
                                  #18

                                  @leo aren't traditional capchas kind of a solved problem in machine learning?

                                  1 Reply Last reply
                                  0
                                  • leo@twit.socialL leo@twit.social

                                    Well this is concerning.

                                    I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                                    Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                                    evan@cosocial.caE This user is from outside of this forum
                                    evan@cosocial.caE This user is from outside of this forum
                                    evan@cosocial.ca
                                    wrote last edited by
                                    #19

                                    @leo thanks for keeping vigilant, Leo!

                                    1 Reply Last reply
                                    0
                                    • leo@twit.socialL leo@twit.social

                                      Well this is concerning.

                                      I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                                      Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                                      abeorch@friendica.ginestes.esA This user is from outside of this forum
                                      abeorch@friendica.ginestes.esA This user is from outside of this forum
                                      abeorch@friendica.ginestes.es
                                      wrote last edited by
                                      #20
                                      @leo Didnt someone identify something about invite links circumventing manual approval?
                                      1 Reply Last reply
                                      0
                                      • leo@twit.socialL leo@twit.social

                                        Well this is concerning.

                                        I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                                        Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                                        tartley@fosstodon.orgT This user is from outside of this forum
                                        tartley@fosstodon.orgT This user is from outside of this forum
                                        tartley@fosstodon.org
                                        wrote last edited by
                                        #21

                                        @leo for 14 of them, couldn't the owners have just registered/captched them manually?

                                        1 Reply Last reply
                                        0
                                        • leo@twit.socialL leo@twit.social

                                          Well this is concerning.

                                          I just suspended 14 Russian LLM generated bot accounts that were created around April 17 on my Mastodon instance, twit.social. Somehow they circumvented manual registration approval. I've turned on Captchas (much as I hate them) for new member requests in the hopes that will stop the bots. They must have discovered a registration bypass bug.

                                          Thanks to IFTAS SW-ISAC for noting and reporting the bots.

                                          wtfismyip@gnu.glW This user is from outside of this forum
                                          wtfismyip@gnu.glW This user is from outside of this forum
                                          wtfismyip@gnu.gl
                                          wrote last edited by
                                          #22

                                          @leo I enabled server-status to investigate some other issue, but noticed there were a bunch of requests against my Mastodon instance.

                                          Link Preview Image
                                          1 Reply Last reply
                                          1
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups