jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
These are the voyag... uh, things I post about.
Admin email
jrollans@gmail.com
Admin account
@jrollans@jrollans.com

Search results for tag #mastoadmin

[?]nullagent » 🌐
@nullagent@partyon.xyz

Kind.Social has proven it's a willfully unsafe space

The moderator is excusing OPEN brigading organized by an OPEN account on their site.

This ring leader is ENCOURAGING harassment and it's continuing to occur.

I'm getting a FLOOD of harassing DMs and tags all day.

This is unsafe, unprofessional and admins like Kind.Social should NOT be allowed to enable abuse.

partyon.xyz/@nullagent/1171856

    [?]Rimuru » 🌐
    @Tempest@burningboard.net

    Post 2 of 2

    Furthermore, the ActivityPub protocol and Mastodon's API have evolved substantially between version 3.5 and version 4.7, meaning an older core can easily lead to federation issues, broken interactions with users on modern instances, and missing features like improved moderation tools. While Glitch Edition offers great quality-of-life tweaks, running a heavily customized and severely outdated fork only increases technical debt, making eventual upgrades exponentially harder.

    This, however, is why I maintain security_risk_domains.csv

    github.com/Fediverse-Express/F

      [?]Rimuru » 🌐
      @Tempest@burningboard.net

      766 Fediverse accounts identified as participating in spam and scam activity — along with accounts that actively promote, defend, or amplify them.

      You'd be surprised by how much cleaner and more user-friendly your site's local live feed is once you weed those out. 🥳

      github.com/Fediverse-Express/F

        [?]Rimuru » 🌐
        @Tempest@burningboard.net

        766 Fediverse accounts identified as participating in spam and scam activity — along with accounts that actively promote, defend, or amplify them.

        You'd be surprised by how much cleaner and more user-friendly your site's local live feed is once you weed those out. 🥳

        github.com/Fediverse-Express/F

          AodeRelay boosted

          [?]Rimuru » 🌐
          @Tempest@burningboard.net

          Post 2 of 2

          kind.social has 831 active users (at the time of this post). Looking at their local timeline, they seem to be PRO LGBTQ+, PRO trans, PRO women's rights, and I even (with some effort) found a PRO Black Lives Matter post on their site from way back.

          The whole "hate" argument is nonsense. It is a false flag as far as I can tell. But don't take my word for it — see for yourself by viewing their public timeline: kind.social/public/local

          By contrast, @ nullagent @partyon.xyz, who is listed as the owner of partyon.xyz, has 6 active users. It is a small, niche site with an agenda. I'd share their public timeline, but they have conveniently turned theirs off.

          I would encourage people to explore and investigate anyone who uses the FediBlock hashtag. Do not just blindly take people for their word.

          I speak from experience.

            [?]Rimuru » 🌐
            @Tempest@burningboard.net

            Scammer wrongfully claims "racism" and ignores that my profile is filled with me supporting both the people of Palestine and Israel.

            Motivation?

            Scammer wants to paint false flag to deflect away from the fact that I am not a racist, but they are indeed a scammer.

            Suggest you use my anti spam / anti scam list which includes accounts that actively promote, defend, or amplify them. Scam groups often have "white knight" (hero) dummy accounts and my list takes that into account.

            github.com/Fediverse-Express/F

              fedicat boosted

              [?]Admin of Listodon » 🌐
              @admin@listodon.com

              Listodon has been updated to v4.7.1

              No issues, tho my routine notes have me doing a bundle install, yarn install --immutable, and RAILS_ENV=production bundle exec rails assets:precompile on every upgrade.

              It seems that this simply required a bundle install this time...it seemed to work just fine, at least I see the updated version number when restarted.

                [?]GLITCH-SOC Release Watcher » 🤖 🌐
                @glitch_soc_release_watcher@mastodon.kodesumber.com

                v4.5.17

                Changelog Security Update dependencies Fix password authentication bypass in 2FA auth for LDAP/PAM/SSO accounts (GHSA-vx32-x96w-qq65) Fix Denial of Service when processing pathological JSON-LD activities (GHSA-vgm8-frgh-rh2v) Fix disabled staff...

                github.com/glitch-soc/mastodon

                  [?]GLITCH-SOC Release Watcher » 🤖 🌐
                  @glitch_soc_release_watcher@mastodon.kodesumber.com

                  v4.4.24

                  NoteWhile we continue to support Mastodon 4.4 and release patches for it, please note that Mastodon 4.6 is available with new features, changes and fixes. We encourage administrators to update to the latest 4.6 version when they...

                  github.com/glitch-soc/mastodon

                    [?]GLITCH-SOC Release Watcher » 🤖 🌐
                    @glitch_soc_release_watcher@mastodon.kodesumber.com

                    v4.6.7

                    Upgrade overview This release contains upgrade notes that deviate from the norm: ℹ️ Requires assets recompilation For more information, view the complete release notes and scroll down to the upgrade instructions section. Changelog Security Update...

                    github.com/glitch-soc/mastodon

                      [?]GLITCH-SOC Release Watcher » 🤖 🌐
                      @glitch_soc_release_watcher@mastodon.kodesumber.com

                      v4.7.1

                      Changelog Security Fix password authentication bypass in 2FA auth for LDAP/PAM/SSO accounts (GHSA-vx32-x96w-qq65) Fix Denial of Service when processing pathological JSON-LD activities (GHSA-vgm8-frgh-rh2v) Fix disabled staff accounts still having...

                      github.com/glitch-soc/mastodon

                        wakest ⁂ boosted

                        [?]Mastodon Engineering » 🌐
                        @MastodonEngineering@mastodon.social

                        We just released Mastodon v4.7.1, v4.6.7, v4.5.17 and v4.4.24.

                        These include important security fixes.

                        We encourage server administrators to update as soon as possible, especially if you are using LDAP, PAM or an external SSO for user authentication.

                        Full release notes and update instructions are available on the GitHub releases page.

                        github.com/mastodon/mastodon/r

                          [?]Daniel Colquitt » 🌐
                          @daniel@colquitt.xyz

                          Is docker.elastic.co down for everyone else, or is it just me?

                            [?]Daniel Colquitt » 🌐
                            @daniel@colquitt.xyz

                            Nvermind... it's back.

                              [?]Chris Alemany🇺🇦🇨🇦🇪🇸 [He/Him] » 🌐
                              @chris@mstdn.chrisalemany.ca

                              Here’s a question.

                              Why would the scheduler process be up around 1000 seconds for average completion time when all others are under 5 seconds?

                              Is it something to be concerned about?

                              Sidekia
Sidekiq
local
Dashboard Busy Queues
Retries
Scheduled Dead Metrics Profiles Recurring Jobs
* Global Bond Sell-Off Puts Investors on Edge - ...
Name
ActivityPub: :ProcessingWorker
DistributionWorker
Scheduler: :Trends:: RefreshScheduler
FetchReplyWorker
ActivityPub: : SynchronizeFeaturedCollectionWorker
FeedInsertWorker
• LinkCrawlworker
• ThreadResolveWorker
• AccountRefreshworker
ActivityPub:: SynchronizeFeaturedCollectionsCollectionWorker
• VerifyAccountLinksWorker
Sidekiq v8.1.6
redis://service.chrisalemany.ca:6380
13:27:47 UTC docs
Success Failure Total Execution Time (Seconds)
Average Execution Time (Seconds)
1,800
1,728
19
3
465
301
1,231
1,797
200
133
250
152
English
1
3
16
5,596.32
2,966.35
2,910.15
1,985.14
1,693.89
1,576.52
1,538.09
1,090.92
779.42
578.17
382.23
3.11
1.72
970.05
4.27
5.63
1.28
0.86
5.45
5.86
2.31
2.51

                              Alt...Sidekia Sidekiq local Dashboard Busy Queues Retries Scheduled Dead Metrics Profiles Recurring Jobs * Global Bond Sell-Off Puts Investors on Edge - ... Name ActivityPub: :ProcessingWorker DistributionWorker Scheduler: :Trends:: RefreshScheduler FetchReplyWorker ActivityPub: : SynchronizeFeaturedCollectionWorker FeedInsertWorker • LinkCrawlworker • ThreadResolveWorker • AccountRefreshworker ActivityPub:: SynchronizeFeaturedCollectionsCollectionWorker • VerifyAccountLinksWorker Sidekiq v8.1.6 redis://service.chrisalemany.ca:6380 13:27:47 UTC docs Success Failure Total Execution Time (Seconds) Average Execution Time (Seconds) 1,800 1,728 19 3 465 301 1,231 1,797 200 133 250 152 English 1 3 16 5,596.32 2,966.35 2,910.15 1,985.14 1,693.89 1,576.52 1,538.09 1,090.92 779.42 578.17 382.23 3.11 1.72 970.05 4.27 5.63 1.28 0.86 5.45 5.86 2.31 2.51

                                [?]Mastodon Release Watcher » 🤖 🌐
                                @mstdn_release_watcher@mastodon.kodesumber.com

                                v4.7.1

                                Changelog Security Fix password authentication bypass in 2FA auth for LDAP/PAM/SSO accounts (GHSA-vx32-x96w-qq65) Fix Denial of Service when processing pathological JSON-LD activities (GHSA-vgm8-frgh-rh2v) Fix disabled staff accounts still having...

                                github.com/mastodon/mastodon/r

                                  [?]Ian Littman » 🌐
                                  @ian@phpc.social

                                  phpc.social is now running Mastodon 4.7.1, released about 25 minutes ago.

                                    AodeRelay boosted

                                    [?]Yehor :dartlang: 🇺🇦 » 🌐
                                    @yehor@mastodon.glitchy.social

                                    AodeRelay boosted

                                    [?]Mastodon Releases » 🤖 🌐
                                    @mastodon_releases@mastodon.social

                                    AodeRelay boosted

                                    [?]Grow Your Own Services 🌱 » 🌐
                                    @homegrown@social.growyourown.services

                                    Hey Mastodon admins, could anyone give some advice about custom CSS?

                                    There's a piece of custom CSS at gist.github.com/FiXato/3de505b which is supposed to remind people to add alt texts to their images, but it seems to no longer work?

                                    If this is broken, can anyone suggest a better source of custom CSS for reminding people?

                                      [?]nullagent » 🌐
                                      @nullagent@partyon.xyz

                                      Is it common practice for someone to get a restraining order THEN send the restrained person constant direct communications? Oh and egg on their followers constantly too!?

                                      Fedi. Can we please agree this type of harassment isn't something our platforms should enable.

                                      Reports about this type of conduct is serious. It needs to be taken seriously by mods.

                                      IF you get a report about ppl violating restraining orders THEY sought, please take them seriously.

                                        [?]nullagent » 🌐
                                        @nullagent@partyon.xyz

                                        I'm sick and tired of the abuse kind.social is ACTIVELY enabling.

                                        At least mastodon.social is too big to likely keep up with sock puppets.

                                        But for crying out loud @Texan_Reverend@kind.social

                                        Can you please reign in the racists on your platform. You've been hosting a persistent harasser for over a year. You dismiss ALL complaints against them.

                                        Do you even warn them?

                                        People need to consider defederating Kind.Social.

                                          [?]nullagent » 🌐
                                          @nullagent@partyon.xyz

                                          Ok I've limited kind.social.

                                          Judging by the numbers we'll likely be doing a full block of kind.social sometime today.

                                          Two notes on Mastodon in current form:

                                          1. There's still ppl I care about on an instance with a shit mod

                                          2. The tools suck for exploring these connections.

                                            [?]nullagent » 🌐
                                            @nullagent@partyon.xyz

                                            Oh fun, another hour, another sock puppet from @Mastodon that's harassing me.

                                            This harassment is being coordinated on kind.social in the OPEN by the accout I've had to report over the past year and the flimsy signup rules on mastodon.social enables their flying monkeys to keep going.

                                            THIS is how Black people get run off of fedi. This "community" is insanely bad at keeping racist out oh my god.

                                              [?]nullagent » 🌐
                                              @nullagent@partyon.xyz

                                              How do you report a public post from an account that you or they have blocked?

                                              Offending content is essentially unreportable if the server is blocked by the user even when the content is public and on servers you otherwise federate with.

                                              This seems like a MASSIVE admin oversight in Mastodon.

                                              @FediTips @mastodonmigration

                                                [?]Walter Selent 🇨🇦 » 🌐
                                                @walter@selent.ca

                                                How to get past a Mastodon server's rate_limit error.

                                                I setup this Mastodon server as a combined upgrade and move to a new VPS provider. Rather than exporting everyone I followed and then bulk importing them I took the opportunity to review who I was following to see if I still wanted to view their posts. I wrote a script that gave me a list of profile URLs of who I was following and openned each of their profile URLs to review.

                                                I clicked on user profiles and/or blog server if they mentioned one. Some were interesting so I bookmarked for future follow up. Typical internet surfing behaviour going down some rabbit holes finding new users to follow and for various reasons unfollowing others I used to follow.

                                                I occasionally got a rate_limit error message from Mastodon about doing too many follows and need to wait a few minutes. When that happenned I would be unable to add new followers until the specified time. I spent the time looking more deeply at potential followers profiles until I was able to add followers again. A bit frustrating but manageable. Then I hit another rate_limit error saying I had to wait until 4:00 PM tomorrow. (which happens to be midnight UTC for my timezone). I was annoyed because I still had a few hundred followers to review. I was in the zone and wanted to get this completed.

                                                Looks like there's a hardcoded limit from Mastodon of 400 follows that can be done in a single day (based on UTC timezone). Since I admin my own Mastodon server and have full CLI access I found out a way to get past this rate_limit blockage and will share a little recipe on how to to that.

                                                If you run the following command as userid mastodon you will see what rate_limit associated keys are in redis on your Mastodon server:

                                                redis-cli --scan --pattern 'rate_limit*'

                                                which in my case emitted the following result:

                                                "rate_limit:116094709108426294:follows:20504"

                                                I checked the value type for this redis key and it's a string:

                                                redis-cli type "rate_limit:116094709108426294:follows:20504"
                                                string

                                                I got the value for this key and it was 400:

                                                redis-cli get "rate_limit:116094709108426294:follows:20504"
                                                "400"

                                                So I set it to 0 and that removed the rate_limit error and I was able to continue:

                                                redis-cli set rate_limit:116094709108426294:follows:20504 0
                                                OK

                                                redis-cli get rate_limit:116094709108426294:follows:20504
                                                "0"

                                                  AodeRelay boosted

                                                  [?]Christian Peach » 🌐
                                                  @chpietsch@fedifreu.de

                                                  RE: fedifreu.de/@chpietsch/1170593

                                                  Mastodon-Admins, verhindert die nächste Spam- und Propagandawelle!

                                                  Die Welle an höchst dubiosen Registrierungsversuchen mit zufälligen Usernames, seltsamen E-Mail-Adressen und sturzlangweiligen oder aus Bios geklauten Begründungen ebbt nicht ab.

                                                  Zum Glück bekommt unser Moderationsteam die meisten spammigen Anträge gar nicht mehr zu sehen, weil ein von @gunchleoc gespendetes und von mir verschlimmbessertes Shellscript alle abblockt, die bekannte Wegwerf-Mailadressen enthalten. Vielen Dank an derjan, der den ersten Pull-Request dafür eingereicht hat! Damit wurde ein Flüchtigkeitsfehler von mir behoben.

                                                  Jetzt muss sich das Moderationsteam nur noch mit den kreativeren Registrierungsanträgen beschäftigen. Ein typisches Muster ist, dass seltsame Maildomains verwendet werden. Wenn diese im auf Mailserver verweisen, die für unsere legitimen User nicht relevant sein dürften, sperre ich die gleich mit. Aktuell sind das z.B. die von spacemail•com aus den USA.

                                                  Ich checke die Maildomains wie die IP-Adressen gern auf der Kommandozeile mit host und whois. Wer kein Linux zur Hand hat, kann unter Android die App Termux (z.B. aus ) nehmen und mit pkg install dnsutils whois diese Tools darin installieren.

                                                  $ host domioni.pro
                                                  domioni.pro mail is handled by 0 mx2.spacemail.com.
                                                  domioni.pro mail is handled by 0 mx1.spacemail.com.

                                                  Aber ihr könnt auch gleich ins Web-Interface eures Mastodon-Accounts mit Admin-Rechten gehen, um seltsame Maildomains zu sperren. Das geht dort: EinstellungenModerationGesperrte E-Mail-DomainsNeue hinzufügen. Nach Eingabe einer Maildomain und Klick auf Domain auflösen passiert automatisch eine Abfrage der zu dieser Domain im DNS hinterlegten Mailserver. Durch Antippen der Kästchen vor mx1.… und mx2.… (s. Screenshot) sperre ich die Mailserver in diesem Fall gleich mit.

                                                  So ergänze ich die vom obigen Script jede Nacht importierte Sperrliste bei Bedarf manuell und gebe den Spammern immer weniger Chancen. Zur Nachahmung empfohlen!

                                                  AodeRelay boosted

                                                  [?]Christian Peach » 🌐
                                                  @chpietsch@fedifreu.de

                                                  RE: fedifreu.de/@chpietsch/1170506

                                                  Liebe Mastodon-Admins,

                                                  wenn ihr nicht Teil einer rechtsextremen (oder von Putin/Trump gesteuerten) Propadandamaschine werden wollt, dann tut was gegen die -Accounts, die sich evt. massenhaft auf euren Instanzen einnisten.

                                                  Was ihr tun könnte, habe ich mit Teilnehmenden des laufenden zusammengetragen.

                                                  Aktuelles Beispiel für diese FakeNews-Kampagnen: newsie.social/@dieKadda/117058

                                                  AodeRelay boosted

                                                  [?]Christian Peach » 🌐
                                                  @chpietsch@fedifreu.de

                                                  Auf dem habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:

                                                  Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?

                                                  Anlass

                                                  FakeNews-Kampagne und ähnliche: about.iftas.org/library/suspec

                                                  Vorsorgemaßnahmen

                                                  1. Schaltet Registrierungen von offen auf halboffen um, falls ihr das nicht schon getan habt. Und verlangt eine Begründung! Ihr findet das unter Einstellungen > Administration > Serverregeln > Registrierungen
                                                  2. Schreibt auf eure About-Seite, was in einer guten Begründung drinstehen sollte.
                                                  3. Sollte euch doch mal ein Spammer/Sleeper durchrutschen, dann wäre es fatal, wenn er Einladungen erzeugen dürfte. Leider ist das der Default. Ändert das bitte in Einstellungen > Administration > Rollen > Standard. Die allermeisten User nutzen diese Funktion eh nicht. Mods und Admins können dann weiterhin Einladungslinks generieren.

                                                  Abwehrstrategie E-Mail-Domain

                                                  Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools tootctl möglich.

                                                  Abwehrstrategie IP-Adresse

                                                  Mit Standard-Tools wie host und whois können Linux-Nutzende die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool ist wtfis, wenn man die API-Keys einiger Webdienste hinterlegt: github.com/pirxthepilot/wtfis

                                                  Viele der Bots oder Klickarbeiter:innen nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.

                                                  Abwehrstrategie Begründung

                                                  Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.

                                                  Sehr sinnvoll erscheint es uns, die Über-Seite oder den Text über dem Antragsformular anzupassen, um Antragstellende aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.

                                                  Eine Lösung für Matrix-Fans

                                                  Für Matrix-Nutzende hat die @FediverseFoundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: git.fediverse.foundation/ff_pu

                                                  Allgemeine Anti-DDoS-Maßnahmen

                                                  Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:

                                                  Ideen für Fallen

                                                  Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: mastodonpy.readthedocs.io

                                                      Screenshot des Mastodon-Admin-Webinterfaces mit dem ersten Schritt der Funktion „Neue E-Mail-Domain sperren“.

                                                      Alt...Screenshot des Mastodon-Admin-Webinterfaces mit dem ersten Schritt der Funktion „Neue E-Mail-Domain sperren“.

                                                      Screenshot aus dem Admin-Webinterface einer von mir betreuten Mastodon-Instanz. Gezeigt wird der zweite Schritt der Funktion „Neue E-Mail-Domain sperren“. Die beiden MX-Domains habe ich angehakt.

                                                      Alt...Screenshot aus dem Admin-Webinterface einer von mir betreuten Mastodon-Instanz. Gezeigt wird der zweite Schritt der Funktion „Neue E-Mail-Domain sperren“. Die beiden MX-Domains habe ich angehakt.

                                                        AodeRelay boosted

                                                        [?]Christian Peach » 🌐
                                                        @chpietsch@fedifreu.de

                                                        RE: fedifreu.de/@chpietsch/1170506

                                                        Liebe Mastodon-Admins,

                                                        wenn ihr nicht Teil einer rechtsextremen (oder von Putin/Trump gesteuerten) Propadandamaschine werden wollt, dann tut was gegen die -Accounts, die sich evt. massenhaft auf euren Instanzen einnisten.

                                                        Was ihr tun könnte, habe ich mit Teilnehmenden des laufenden zusammengetragen.

                                                        Aktuelles Beispiel für diese FakeNews-Kampagnen: newsie.social/@dieKadda/117058

                                                        AodeRelay boosted

                                                        [?]Christian Peach » 🌐
                                                        @chpietsch@fedifreu.de

                                                        Auf dem habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:

                                                        Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?

                                                        Anlass

                                                        FakeNews-Kampagne und ähnliche: about.iftas.org/library/suspec

                                                        Vorsorgemaßnahmen

                                                        1. Schaltet Registrierungen von offen auf halboffen um, falls ihr das nicht schon getan habt. Und verlangt eine Begründung! Ihr findet das unter Einstellungen > Administration > Serverregeln > Registrierungen
                                                        2. Schreibt auf eure About-Seite, was in einer guten Begründung drinstehen sollte.
                                                        3. Sollte euch doch mal ein Spammer/Sleeper durchrutschen, dann wäre es fatal, wenn er Einladungen erzeugen dürfte. Leider ist das der Default. Ändert das bitte in Einstellungen > Administration > Rollen > Standard. Die allermeisten User nutzen diese Funktion eh nicht. Mods und Admins können dann weiterhin Einladungslinks generieren.

                                                        Abwehrstrategie E-Mail-Domain

                                                        Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools tootctl möglich.

                                                        Abwehrstrategie IP-Adresse

                                                        Mit Standard-Tools wie host und whois können Linux-Nutzende die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool ist wtfis, wenn man die API-Keys einiger Webdienste hinterlegt: github.com/pirxthepilot/wtfis

                                                        Viele der Bots oder Klickarbeiter:innen nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.

                                                        Abwehrstrategie Begründung

                                                        Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.

                                                        Sehr sinnvoll erscheint es uns, die Über-Seite oder den Text über dem Antragsformular anzupassen, um Antragstellende aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.

                                                        Eine Lösung für Matrix-Fans

                                                        Für Matrix-Nutzende hat die @FediverseFoundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: git.fediverse.foundation/ff_pu

                                                        Allgemeine Anti-DDoS-Maßnahmen

                                                        Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:

                                                        Ideen für Fallen

                                                        Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: mastodonpy.readthedocs.io

                                                            AodeRelay boosted

                                                            [?]Christian Peach » 🌐
                                                            @chpietsch@fedifreu.de

                                                            Auf dem habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:

                                                            Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?

                                                            Anlass

                                                            FakeNews-Kampagne und ähnliche: about.iftas.org/library/suspec

                                                            Vorsorgemaßnahmen

                                                            1. Schaltet Registrierungen von offen auf halboffen um, falls ihr das nicht schon getan habt. Und verlangt eine Begründung! Ihr findet das unter Einstellungen > Administration > Serverregeln > Registrierungen
                                                            2. Schreibt auf eure About-Seite, was in einer guten Begründung drinstehen sollte.
                                                            3. Sollte euch doch mal ein Spammer/Sleeper durchrutschen, dann wäre es fatal, wenn er Einladungen erzeugen dürfte. Leider ist das der Default. Ändert das bitte in Einstellungen > Administration > Rollen > Standard. Die allermeisten User nutzen diese Funktion eh nicht. Mods und Admins können dann weiterhin Einladungslinks generieren.

                                                            Abwehrstrategie E-Mail-Domain

                                                            Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools tootctl möglich.

                                                            Abwehrstrategie IP-Adresse

                                                            Mit Standard-Tools wie host und whois können Linux-Nutzende die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool ist wtfis, wenn man die API-Keys einiger Webdienste hinterlegt: github.com/pirxthepilot/wtfis

                                                            Viele der Bots oder Klickarbeiter:innen nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.

                                                            Abwehrstrategie Begründung

                                                            Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.

                                                            Sehr sinnvoll erscheint es uns, die Über-Seite oder den Text über dem Antragsformular anzupassen, um Antragstellende aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.

                                                            Eine Lösung für Matrix-Fans

                                                            Für Matrix-Nutzende hat die @FediverseFoundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: git.fediverse.foundation/ff_pu

                                                            Allgemeine Anti-DDoS-Maßnahmen

                                                            Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:

                                                            Ideen für Fallen

                                                            Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: mastodonpy.readthedocs.io

                                                              [?]Rimuru » 🌐
                                                              @Tempest@burningboard.net

                                                              ⚠️ 696 scammer and spam accounts (including the accounts that continuously promote and defend them)!

                                                              All sorted alphabetically by domain first, making it easy to identify which domains may be problematic. 👀

                                                              github.com/Fediverse-Express/F

                                                                [?]IFTAS » 🌐
                                                                @iftas@mastodon.iftas.org

                                                                martinmuc.de/blog/invite-chain

                                                                Please review your existing invite codes, and your invite permissions.

                                                                  [?]Travis KJ5DCL » 🌐
                                                                  @travis@nangang.travnewmatic.com

                                                                  how are y'all monitoring the logs for your instance? Currently researching bolting nginx exporter onto my reverse proxy and creating rules for that.. but what else? I've got both and running in my . As well as kube-prometheus-stack.

                                                                    [?]Fedi.Tips » 🌐
                                                                    @FediTips@social.growyourown.services

                                                                    Are you running a server on the Fediverse, either Mastodon or some other type?

                                                                    Would you like it to be listed on the human-curated server directory at fedi.garden/fedi-gardens-full- ?

                                                                    Is it compatible with all seven points at fedi.garden/about-this-site ?

                                                                    If the answer to all these is yes, please message my other account at:

                                                                    ➡️ @FediGarden

                                                                    Let me know a little bit about your server in your message, or send a link to your About page 🙂

                                                                      [?]Saorsa » 🌐
                                                                      @Saorsa@public.mitra.social

                                                                      We made a policy document to combat some of the bad faith allegations being posted to #Fediblock regarding neondystopia.world and to outline where we stand on moderation practices.

                                                                      We've gone and leveraged Misskey pages for conveniently finding information about the instance. I do hope this will help some of the system administrators and moderators of instances to reach an informed conclusion on whether to peer with our instance in future.

                                                                      Tags: #SelfHosting, #FediAdmin, #MastoAdmin, #ServerAdmin, #Moderation, #Moderators, #FediMods, #MastoMods, #TrustAndSafety, #SocialMedia, #FediMeta, #Fedi, #Federation, #Fediverse, #Community, #Fediblock, #Sociology, #Blocklist.

                                                                        [?]Saorsa » 🌐
                                                                        @Saorsa@neondystopia.world

                                                                        Hey @FediTips@social.growyourown.services, I've been thinking lately about drawing up some documentation for folk to use on the Fediverse. @xaetacore and I have noticed lately that there is a rather toxic culture surrounding and have wanted to write some guides to help the users on instances curate their own experience on the Fediverse rather than relying solely on the moderation of their instance to do so.

                                                                        We hope to supplement and improve existing moderation efforts rather than replace them entirely. It is our hope that by prompting a shift in the responsibility of curating content from instances to their users. Instance operators and their moderation won't feel compelled to act as an arbiter of philosophy by selecting which content may and may not be seen beyond the scope of generally agreed upon illegal or egregious content.

                                                                        Instead, offering more user agency by providing the tooling, framework and guidance through which they can curtail undesirable content without sorting to suspending entire instances at the expense of the users on there that have done nothing wrong.

                                                                        Would you be interested in promoting or boosting such efforts?

                                                                        , , , , , , , , , , , , , , , , .

                                                                          [?]thehole [any] » 🌐
                                                                          @thehole@dasforum.org

                                                                          Took some time, but we are now on 4.7.0

                                                                            [?]Travis KJ5DCL » 🌐
                                                                            @travis@nangang.travnewmatic.com

                                                                            @Larvitz aewsome :) my instance just has me :) so mine only took a few seconds ('pre' and 'post'). and everything is fine!