jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
RE: https://mastodon.social/@Mastodon/117083691112770390
Extremely disappointed about this.
Some months ago, I had to delete a #Mastodon instance, because it had "Mastodon" in it's domain name and I didn't receive any response from their legal department on my request for MONTHS. Therefore, I had to delete it, all money and time wasted.
If I hadn't delete it and kept it running (illegally), it would have been legal now, because suddenly all servers that existed before 2026-05-13 receive a permission automatically.
Today we're sharing additional guidelines about our Trade Mark Policy based on community feedback that we received.
The new guidelines, and more background about these changes, are available on our blog:
https://blog.joinmastodon.org/2026/08/sharing-guidelines-about-mastodons-trade-mark-policy/#Mastodon #Fediverse #SocialWeb #FediDev #MastoDev #FediAdmin #MastoAdmin
pros of having your fedi handle as an email: its cool
cons of having your fedi handle as an email:
GLITCH-SOC Release Watcher » 🤖 🌐
@glitch_soc_release_watcher@mastodon.kodesumber.com
v4.4.23
NoteWhile we continue to support Mastodon 4.4 and release patches for it, please note that Mastodon 4.6 is available with new features, changes and fixes. We encourage administrators to update to the latest 4.6 version when they...
Just FYI: The server you mentioned is part of the Garden Fence blocklist maintained by @gardenfence at https://github.com/gardenfence/blocklist. Highly recommended.
The blocklist is a useful tool for server admins, so you can recommend it to your instance's administrator if you want.
Mastodon Release Watcher » 🤖 🌐
@mstdn_release_watcher@mastodon.kodesumber.com
v4.5.16
Changelog Changed Change mastodon:setup task warning about trademark to match masto but ignore subdomains (#40143 by @ClearlyClaire) Fixed Fix connection errors when processing fediverse:creator preventing creation of preview cards (#40135 by...
We just released Mastodon 4.6.6, 4.5.16 and 4.4.23.
They contain minor bug fixes and we advise server administrators to update when they can.
Full release notes and update instructions are available on the GitHub releases page. https://github.com/mastodon/mastodon/releases
Shitty people with shitty opinions being inconvenienced by the results of their own inactions.
Cry me a river, you little baby.
So. Streaming on the instance was broken for a couple days because your instance admin failed to realize that yes, sometimes software that will happily sit still and do nothing for nearly 3 years still wakes up and decides it needs an update. If you want technical details I can share them, but the short version is if your client hits the streaming API, it can now officially do that again. #MastoAdmin
Today we're sharing additional guidelines about our Trade Mark Policy based on community feedback that we received.
The new guidelines, and more background about these changes, are available on our blog:
https://blog.joinmastodon.org/2026/08/sharing-guidelines-about-mastodons-trade-mark-policy/
#Mastodon #Fediverse #SocialWeb #FediDev #MastoDev #FediAdmin #MastoAdmin
Hey friends, it's me again
We have more news to share today, though I must admit, this news is a little less fun.
Recently, the @Mastodon team received a fair number of questions about our trade mark policy. We realised we could add some guidelines to help make the Policy more clear, so over the last few months, we did just that! I'll post a "plain English" version of the guidelines as a comment.
You can read more background about the changes we made, and see the guidelines themselves, in this blog post:
https://blog.joinmastodon.org/2026/08/sharing-guidelines-about-mastodons-trade-mark-policy/
And the trade mark policy page is updated too:
https://joinmastodon.org/trademark
📬 Trunk & Tidbits for July 2026 is now out!
Our monthly blog post series is there to showcase what we worked on last month.
In this edition, we welcome @jhbabon and highlight the many backend changes that were merged and will be part of our upcoming 4.7 release. Those include support for FEP-8b32, FEP 8967 and new algorithms, including ML-DSA-44 for post-quantum signatures.
RE: https://mastodon.social/@MastodonEngineering/117071692327950548
Just updated. So far so good.
#MastoAdmin #Fediverse #Mastodon
We released the first beta for Mastodon 4.7 today. It contains very few user-facing changes, but contains significant reworks of the backend code to improve security and support new protocol features.
This update includes substantial database migrations that might take up to a couple of hours on very large servers, but will not cause downtime if the upgrade instructions are followed.
Release notes and upgrade instructions are available here: https://github.com/mastodon/mastodon/releases/tag/v4.7.0-beta.1
We released the first beta for Mastodon 4.7 today. It contains very few user-facing changes, but contains significant reworks of the backend code to improve security and support new protocol features.
This update includes substantial database migrations that might take up to a couple of hours on very large servers, but will not cause downtime if the upgrade instructions are followed.
Release notes and upgrade instructions are available here: https://github.com/mastodon/mastodon/releases/tag/v4.7.0-beta.1
Mastodon Release Watcher » 🤖 🌐
@mstdn_release_watcher@mastodon.kodesumber.com
v4.7.0-beta.1
WarningThis is a pre-release! This has not been as widely tested as regular releases, although it is still tested on mastodon.social and some other servers. If you update to this release, you will not be able to safely downgrade to the existing...
https://github.com/mastodon/mastodon/releases/tag/v4.7.0-beta.1
Auf dem #Fedicamp habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:
Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?
FakeNews-Kampagne #PortalKombat und ähnliche: https://about.iftas.org/library/suspected-portal-kombat-accounts/
Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools tootctl möglich.
Mit Standard-Tools wie host und whois können Linux-Nutzende die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool ist wtfis, wenn man die API-Keys einiger Webdienste hinterlegt: https://github.com/pirxthepilot/wtfis
Viele der Bots oder Klickarbeiter:innen nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.
Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.
Sehr sinnvoll erscheint es uns, die Über-Seite oder den Text über dem Antragsformular anzupassen, um Antragstellende aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.
Für Matrix-Nutzende hat die @FediverseFoundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: https://git.fediverse.foundation/ff_pub/fedi-signup-bot
Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:
Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: https://mastodonpy.readthedocs.io
#PortalKombat #PutinTrolle #TrumpTrolle #AntiSpam #AntiFakeNews #Spam #FakeNews #disinformation #MastoAdmin #FediAdmin #Registrierungen #Fedicamp2006 #Fedicamp2006Tag3
FYI, nefarious ppl are sending out NameCheap domain expiration emails to an email address I use exclusively for the Fediverse Observer registration and editing of my instance on that site.... They look legit except for the links where they ultimately go to. Be careful #NameCheap #domains #infosec
How they got that email address is beyond me
RE: https://fedifreu.de/@chpietsch/117050639754423573
Liebe Mastodon-Admins,
wenn ihr nicht Teil einer rechtsextremen (oder von Putin/Trump gesteuerten) Propadandamaschine werden wollt, dann tut was gegen die #Sleeper-Accounts, die sich evt. massenhaft auf euren Instanzen einnisten.
Was ihr tun könnte, habe ich mit Teilnehmenden des laufenden #Fedicamp zusammengetragen.
Aktuelles Beispiel für diese FakeNews-Kampagnen: https://newsie.social/@dieKadda/117058626402342451
#PortalKombat #PutinTroll #TrumpTroll #SleeperAccounts #FakeNews #SpamRegistrations #RegistrationSpam #MastoAdmin #FediAdmin
AodeRelay boostedAuf dem #Fedicamp habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:
Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?
Anlass
FakeNews-Kampagne #PortalKombat und ähnliche: https://about.iftas.org/library/suspected-portal-kombat-accounts/
Vorsorgemaßnahmen
- Schaltet Registrierungen von offen auf halboffen um, falls ihr das nicht schon getan habt. Und verlangt eine Begründung! Ihr findet das unter Einstellungen > Administration > Serverregeln > Registrierungen
- Schreibt auf eure About-Seite, was in einer guten Begründung drinstehen sollte.
- Sollte euch doch mal ein Spammer/Sleeper durchrutschen, dann wäre es fatal, wenn er Einladungen erzeugen dürfte. Leider ist das der Default. Ändert das bitte in Einstellungen > Administration > Rollen > Standard. Die allermeisten User nutzen diese Funktion eh nicht. Mods und Admins können dann weiterhin Einladungslinks generieren.
Abwehrstrategie E-Mail-Domain
Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools
tootctlmöglich.
- Suche in ca. 70.000 Wegwerf-Domains: https://disposable.github.io/disposable-email-domains/lookup
- Repo dazu: https://github.com/disposable/disposable
- Bei so einer langen Liste steigt die Gefahr des Overblockings.
- Bewährte Teilmenge der obigen Liste mit ca. 7.000 Wegwerf-Domains: https://github.com/disposable-email-domains/disposable-email-domains
- Update: Von @gunchleoc bekam ich ein kurzes Shellscript, das diese Blocklist in eine Mastodon-Instanz importiert: https://codeberg.org/datenfreude/emailblock – am besten jede Nacht per Cronjob.
Abwehrstrategie IP-Adresse
Mit Standard-Tools wie
hostundwhoiskönnen Linux-Nutzende die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool istwtfis, wenn man die API-Keys einiger Webdienste hinterlegt: https://github.com/pirxthepilot/wtfisViele der Bots oder Klickarbeiter:innen nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.
Abwehrstrategie Begründung
Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.
Sehr sinnvoll erscheint es uns, die Über-Seite oder den Text über dem Antragsformular anzupassen, um Antragstellende aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.
Eine Lösung für Matrix-Fans
Für Matrix-Nutzende hat die @FediverseFoundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: https://git.fediverse.foundation/ff_pub/fedi-signup-bot
Allgemeine Anti-DDoS-Maßnahmen
Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:
- Proof of Work, z.B. Anubis
- IP-Sperrlisten, z.B. https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker
- UserAgent-Sperrlisten
- Tarpitting/Teergrubing/Fallen
Ideen für Fallen
Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: https://mastodonpy.readthedocs.io
#PortalKombat #PutinTrolle #TrumpTrolle #AntiSpam #AntiFakeNews #Spam #FakeNews #disinformation #MastoAdmin #FediAdmin #Registrierungen #Fedicamp2006 #Fedicamp2006Tag3
GLITCH-SOC Release Watcher » 🤖 🌐
@glitch_soc_release_watcher@mastodon.kodesumber.com
v4.6.5
Upgrade overview This release contains upgrade notes that deviate from the norm: ℹ️ Requires assets recompilation For more information, view the complete release notes and scroll down to the upgrade instructions section. Changelog Fixed Fix...
For those #Mastoadmin 's that use the Universeodon relay, we've been seeing some issues it seems overnight. I've made some changes to our infrastructure to try to cope with what looks like a huge amount of traffic now. You may need to disable and re-enable the relay if it isn't working on your server.
We just released Mastodon 4.6.5. It contains one important bug fix and we recommend every instance running 4.6 to update.
We are also releasing Mastodon v4.5.15 and v4.4.22 with minor bugfixes
Full release notes and update instructions are available on the GitHub releases page.