There is an ongoing spam attack on the fediverse for the last couple of days. It's more widespread than before, as attackers are targeting smaller servers to create accounts. Before, usually only mastodon.social was targeted and our team could take care of it. For server administrators out there: If you don't need open registrations, switch over to approval mode. If you do, blocking disposable e-mail providers is a massive stopgap to the problem. Mastodon also supports hCaptcha.
@Gargron Still the problem is Mastodon. See https://github.com/mastodon/mastodon/discussions/29267.
Please see these issues (two of them are created by me and are related) as well:
*Require blocking of disposable email providers and/or require a captcha provider when registrations are open*
https://github.com/mastodon/mastodon/issues/29270
*Set new registrations on new servers to manual approval by default*
https://github.com/mastodon/mastodon/issues/29269
*Ability to greylist new servers*
https://github.com/mastodon/mastodon/issues/29266
*Ability to use heuristic spam filtering tools*
https://github.com/mastodon/mastodon/issues/29265
*Instance-wide filtering*
https://github.com/mastodon/mastodon/issues/29256
cc @renchap
@Gargron Still the problem is Mastodon. See https://github.com/mastodon/mastodon/discussions/29267.
Please see these issues (two of them are created by me and are related) as well:
*Require blocking of disposable email providers and/or require a captcha provider when registrations are open*
https://github.com/mastodon/mastodon/issues/29270
@Gargron but attackers can setup mastodon with different domains to go on spam the fediverse
@Gargron@mastodon.social yeah and sadly it's a very clever one, we can't do much about it as messages are coming from different users, from different servers, and it has no text only an image, so we can't even filter that :(