Spam attack on Twitter/X rival Mastodon highlights 'fediverse' vulnerabilities | TechCrunch
techcrunch.com
external-link
A spam attack that impacted the open source X rival Mastodon, Misskey and other apps highlights how the decentralized social web, also known as the
@[email protected]
link
fedilink
English
121Y

IP bans are not very useful considering that almost nobody has a static IP these days.

CGNAT IP addresses change frequently and can be shared by over 100 users. I find it very annoying to have to connect to a VPN until my IP changes because someone else got the IP I’m using banned.

Browser fingerprinting would be a better way of detecting ban evaders.

Mnglw
link
fedilink
11Y

browser fingerprinting is inherently bad for privacy and would require scripts that nobody wants to run

not to mention the GDPR issues with servers having that amount of data

@[email protected]
link
fedilink
English
31Y

I’m not a fan of fingerprinting either, although good luck avoiding it considering just how much of the web is behind Cloudflare.

Mnglw
link
fedilink
51Y

the fediverse largely prides itself on no tracking, in fact in the past instances that used cloudflare have been harshly criticised.

This is against the fediverse’s core values

I’ve had my server behind Cloudflare this entire time. Should I not be doing that? At a minimum I need something to hide my server’s real IP.

haui
link
fedilink
01Y

They‘re useful for a very short amount of time and add frustration for the spammer but yes, the downsides are large as well.

If a person knows how to change their ip after being banned, they probably dont use a normal browser either, dont you think? Or have I missed something about browser fingerprinting? You can post to lemmy over an api, right?

Create a post

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

  • 1 user online
  • 40 users / day
  • 147 users / week
  • 307 users / month
  • 2.32K users / 6 months
  • 1 subscriber
  • 3.01K Posts
  • 43.4K Comments
  • Modlog