#fediadmin — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #fediadmin, aggregated by home.social.
-
Ein Zittern im Maschinenraum – und die holografische Standuhr zeigte kurz gleichzeitig Freitag und Samstag an. Chefingenieurin Bag'figs schaltete den Chrono-Schraubenschlüssel mit einem Wink ihrer vorderen Tentakel ab und verzog die drei Lippen zu einem Lächeln, froh, mit den Wartungsarbeiten wieder im Zeitplan zu liegen.
Wir sausen weiter mit den Raumschiff #WueSocial mit Warp 4.6.6 durch das #Fediverse#Mastodon #Upgrade #Fedimin #FediAdmin
-
pros of having your fedi handle as an email: its cool
cons of having your fedi handle as an email: -
FYI: They've replaced the "almost nobody opts in" quip located on: https://tiago.zip/almanac
original text: "because almost nobody opts in, and a snapshot of the few hundred people who did isn't useful for anything."
with: "if you don't know about it you can't opt in, and a snapshot of the few hundred people who did isn't useful for anything."
That being said, we don't condone any sort of mass data collection especially without consent.
This is a #Privacy nightmare. -
Shitty people with shitty opinions being inconvenienced by the results of their own inactions.
Cry me a river, you little baby.
(The account being reported is a Gaza-verified account).
-
FYI: User-Agent Almanac
Ongoing 24.5M fediverse posts and profile scrapes:
"why isn't this opt-in?
because almost nobody opts in, and a snapshot of the few hundred people who did isn't useful for anything. it also wouldn't reflect the network, which defeats the point of studying it.
i get that this isn't the answer everyone wants. if you disagree, you can opt-out above. if you control an instance and have any concerns, feel free to email me."
-
Today we're sharing additional guidelines about our Trade Mark Policy based on community feedback that we received.
The new guidelines, and more background about these changes, are available on our blog:
https://blog.joinmastodon.org/2026/08/sharing-guidelines-about-mastodons-trade-mark-policy/#Mastodon #Fediverse #SocialWeb #FediDev #MastoDev #FediAdmin #MastoAdmin
-
I have exciting news to share!! :mastodondance:
It looks like we're finally gearing up to start migrating people over into @Mastodon's new @zulip instance for certain parts of our community next week (#MastoAdmin #FediAdmin #FediDev #Mod etc.)! It has been a long time in the making and I'm sorry for the delay, but I'm so glad we're finally going to start getting people in there <3 We'll start by beta testing with a few individuals next week to make sure everything is ready for a larger wave of people to join <3 <3
More on #DefaultServerRecommendations soon too — stay tuned!
-
oi oi @gotosocial is there a way for me to see statistics on how many posts the relays my instance subscribes to actually successfully ingested, or a list of posts that originate from a relay subscription?
It doesn't seem like my federated timeline is now more varied or fuller, but I don't know how to check whether it's just unlucky timing/general scarcity of posts on the 'verse, or whether it's that my relay subscriptions do not work
-
What's with these "financial advisers" suddenly following me here? This feels like LinkedIn. There's nothing in my profile nor posts that scream "hey, come steal my money", is there?
-
Agora os bots de falsa verificação de contas no fediverso estão vindo pelo Pixelfed.
Lembrem-se: nenhum administrador vai pedir que você verifique a conta, logo administradores também não vão cobrar por isso.
Nem preciso dizer ainda que: não existe "análise automatizada" no fediverso.
Denuncie a conta e não clique em nenhum link.
:pixelfed: @blogamf: https://indieweb.social/@blogamf/117072752911777236
-
FYI, nefarious ppl are sending out NameCheap domain expiration emails to an email address I use exclusively for the Fediverse Observer registration and editing of my instance on that site.... They look legit except for the links where they ultimately go to. Be careful #NameCheap #domains #infosec
How they got that email address is beyond me
-
Another day, another shameless scrapper. This time it's shamelessly called "archiv scrapper". I guess it's not from Internet Archive.
Here's the full user-agent: "Mozilla/5.0 (archiv scraper)".
There's no info about ownership, site or e-mail, WYSIWYG. It uses VPNs with IP addresses from AS11878 (Tzulo).
So I think it's up to no good.
-
@chpietsch
Best ways to spot them:Check the ip on a site like ipqualityscore.com to see if it's from a datacenter or tor exit node.
Check if the domain of the signup emailadres is disposable using something like usercheck.com
Does the bio of the profile seem genuine? Take a section of it and search it between " " 's into a search engine and see if it matches an existing fedi profile, they often copy random profile's.
Doing this will find 95% of them
#FediAdmin #MastoAdmin -
RE: https://fedifreu.de/@chpietsch/117050639754423573
Liebe Mastodon-Admins,
wenn ihr nicht Teil einer rechtsextremen (oder von Putin/Trump gesteuerten) Propadandamaschine werden wollt, dann tut was gegen die #Sleeper-Accounts, die sich evt. massenhaft auf euren Instanzen einnisten.
Was ihr tun könnte, habe ich mit Teilnehmenden des laufenden #Fedicamp zusammengetragen.
Aktuelles Beispiel für diese FakeNews-Kampagnen: https://newsie.social/@dieKadda/117058626402342451
#PortalKombat #PutinTroll #TrumpTroll #SleeperAccounts #FakeNews #SpamRegistrations #RegistrationSpam #MastoAdmin #FediAdmin
-
Auf dem #Fedicamp habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:
Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?
Anlass
FakeNews-Kampagne #PortalKombat und ähnliche: https://about.iftas.org/library/suspected-portal-kombat-accounts/
Vorsorgemaßnahmen
- Schaltet Registrierungen von offen auf halboffen um, falls ihr das nicht schon getan habt. Und verlangt eine Begründung! Ihr findet das unter Einstellungen > Administration > Serverregeln > Registrierungen
- Schreibt auf eure About-Seite, was in einer guten Begründung drinstehen sollte.
- Sollte euch doch mal ein Spammer/Sleeper durchrutschen, dann wäre es fatal, wenn er Einladungen erzeugen dürfte. Leider ist das der Default. Ändert das bitte in Einstellungen > Administration > Rollen > Standard. Die allermeisten User nutzen diese Funktion eh nicht. Mods und Admins können dann weiterhin Einladungslinks generieren.
Abwehrstrategie E-Mail-Domain
Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools
tootctlmöglich.- Suche in ca. 70.000 Wegwerf-Domains: https://disposable.github.io/disposable-email-domains/lookup
- Repo dazu: https://github.com/disposable/disposable
- Bei so einer langen Liste steigt die Gefahr des Overblockings.
- Bewährte Teilmenge der obigen Liste mit ca. 7.000 Wegwerf-Domains: https://github.com/disposable-email-domains/disposable-email-domains
- Update: Von @gunchleoc bekam ich ein kurzes Shellscript, das diese Blocklist in eine Mastodon-Instanz importiert: https://codeberg.org/datenfreude/emailblock – am besten jede Nacht per Cronjob.
Abwehrstrategie IP-Adresse
Mit Standard-Tools wie
hostundwhoiskönnen Linux-Nutzende die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool istwtfis, wenn man die API-Keys einiger Webdienste hinterlegt: https://github.com/pirxthepilot/wtfisViele der Bots oder Klickarbeiter:innen nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.
Abwehrstrategie Begründung
Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.
Sehr sinnvoll erscheint es uns, die Über-Seite oder den Text über dem Antragsformular anzupassen, um Antragstellende aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.
Eine Lösung für Matrix-Fans
Für Matrix-Nutzende hat die @FediverseFoundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: https://git.fediverse.foundation/ff_pub/fedi-signup-bot
Allgemeine Anti-DDoS-Maßnahmen
Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:
- Proof of Work, z.B. Anubis
- IP-Sperrlisten, z.B. https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker
- UserAgent-Sperrlisten
- Tarpitting/Teergrubing/Fallen
Ideen für Fallen
Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: https://mastodonpy.readthedocs.io
#PortalKombat #PutinTrolle #TrumpTrolle #AntiSpam #AntiFakeNews #Spam #FakeNews #disinformation #MastoAdmin #FediAdmin #Registrierungen #Fedicamp2006 #Fedicamp2006Tag3
-
Mastodon.cloud has been poorly moderated for a long time. Sujitech has all but abandoned it, so we are... actually somewhat relieved. It was a source of spam and ick, any more. We defederated with them due to their lack of response, but we may recommend a temp re-federation to allow for possible joins.
https://mastodon.cloud/@TheAdmin/116880479865941905
-
2026-08-04 09:41:41.476645378 09:41:41.472 [error] #PID<0.6879624.0> running Pleroma.Web.Endpoint (connection #PID<0.6879656.0>, stream id 1) terminated
2026-08-04 09:41:41.476648251 Server: bv.umbrellix.org:80 (http)
2026-08-04 09:41:41.476651513 Request: GET /api/v1/timelines/home?max_id=B91YtrzqT53zKD2U2C&with_muted=true&limit=20
2026-08-04 09:41:41.476653911 ** (exit) an exception was raised:
2026-08-04 09:41:41.476656417 ** (ArithmeticError) bad argument in arithmetic expression
2026-08-04 09:41:41.476659714 (pleroma 3.15.2) lib/pleroma/web/mastodon_api/views/status_view.ex:607: Pleroma.Web.MastodonAPI.StatusView.render/2
2026-08-04 09:41:41.476662899 (pleroma 3.15.2) lib/pleroma/web/mastodon_api/views/status_view.ex:564: Pleroma.Web.MastodonAPI.StatusView.render/2
2026-08-04 09:41:41.476665548 (elixir 1.17.3) lib/enum.ex:1703: Enum."-map/2-lists^map/1-1-"/2
2026-08-04 09:41:41.476668848 (pleroma 3.15.2) lib/pleroma/web/mastodon_api/views/status_view.ex:266: Pleroma.Web.MastodonAPI.StatusView.render/2
2026-08-04 09:41:41.476671983 (pleroma 3.15.2) lib/pleroma/web/mastodon_api/views/status_view.ex:157: Pleroma.Web.MastodonAPI.StatusView.render/2
2026-08-04 09:41:41.476674512 (elixir 1.17.3) lib/enum.ex:1703: Enum."-map/2-lists^map/1-1-"/2
2026-08-04 09:41:41.476677045 (elixir 1.17.3) lib/enum.ex:1703: Enum."-map/2-lists^map/1-1-"/2
2026-08-04 09:41:41.476679938 (phoenix_template 1.0.4) lib/phoenix/template.ex:126: Phoenix.Template.render_to_iodata/4
2026-08-04 09:41:41.476681695
#fediadmin #lang_en -
wie sind so eure erfahrung mit den moderations-tools verschiedener fediverse dienste?
kenne nur die mastodon moderations UI und sehe da verbesserungspotenzial
bin dort auch schon durch die issues gegangen: es gibt durchaus gute ansätze aber einige gute ideen sind seit jahren nicht weiter verfolgt worden
-
The scrapper is now called Almanac and the old URL now redirects to <https://tiago.zip/almanac>. The contents gathered are used for "research and fedi-wide search".
At the end of the page it says that the scrapper is not opt-in because no one would.
So I guess what's left for those who want to opt-out is the tag, blocking the user-agent (until it changes?) or contacting the site owner.
-
The technical cost per user (excluding moderation) of a Fediverse server is determined by how large your server is.
A single person's microblogging server typically costs about 5 euros per user per month through managed hosting, but a server with dozens of people on it typically costs about 0.5 euros per user (and it gets even cheaper per user beyond that).
Getting together with a few other people can make it cheaper for all of you.
-
Happy #SysAdminDay! 🍰 🧁
Liebe Admins, habt Dank für eure Geduld, Hingabe und Ausdauer! Ohne euch läuft nichts – keine #Cloud, keine #ITSicherheit, kein #Datenschutz, keine #Kommunikation.
Danke fürs Durchhalten und unermüdliche Verbessern!
🙏 ⌨️ 💪
#Systemadministration #FediAdmin #SysAdmin #ITsecurity #Admin #AdminLeiden #Digitalisierung
-
#FediAdmin when checking signup approvals on your server, check the ip address they're signing up with. If it's from a VPS, that's very suspicious and likely to be bot (that's how the bots seem to behave rn. Using normal looking gmail.com emailadresses but ip is coming from a VPS).
You can use something like https://whatismyipaddress.com/ip/ip.address.goes.here. or something like https://ipinfo.io/ -
Have you ever had a long multi-message threaded email conversation in your inbox with a generic subject line like "email"?
Even if not, you can probably imagine how frustrating and worthless it feels, right?
That's how the Fediverse feels for me every day thanks to a specific stubborn and prolific author who intentionally misuses ActivityPub's "Subject" field in long multi-post threaded posts, every day with a generic, meaningless title.
-
Dear admins, mods, and modmins...
Alas, the same "open registration" instances are used over and over again to harass and troll the fedi. Yes, we understand the arguments for allowing open registration.
But tbh? We find those arguments unconvincing given the abuse we see.
The fedi has a serial troll / spammer problem and open registration contributes to its continuation. Offering them the means to register and immediately harass people makes for a less friendly fediverse, not a more friendly one. Reviewing a "reason for joining" before approving an account is not too much to ask. If it is, then we respectfully suggest that the instance has either too many members or too few moderators.
When an instance becomes a go-to for trolls because it offers instant access, that instance creates work for every other federated instance, makes fedizens into victims, and feeds the trolls' need for attention. That there is such a simple solution (manual approval / vibe check) is kind of infuriating at times.
We know that this plea / request will not convince those driven by growth and open registration no matter the cost to the fedi community. But if we convince at least one open registration instance to switch to screened approvals, we will consider it a win.
Lastly: If you're on an open reg instance, we suggest POLITELY asking your admin / mods to change their policy.
-
It really bugs me that #Facebook is still the go-to platform for local information for most people.
Everything I’ve done with myLocal NewsBot project is intended to make Mastodon/the Fediverse equally useful for up-to-date local news and information, and for the most part I think it’s been successful; I’m able to stay up to date, even ahead of traditional news sources.
The remaining nuts that need to be cracked IMO are local business pages and groups (and maybe Marketplace). We need something on the #Fediverse side that speaks to those needs.
-
Every community operates differently, whether you're running a single-user instance, an app, or a large community hub.
Over 280 nodes are represented so far in our annual operations survey, but we want to make sure _your_ unique trust and safety challenges are included before we wrap up this extended week.
Help us get you the resources and tools you actually need. This survey is for #FediAdmin #MastoAdmin #Moderators - don't miss your chance!
Boost for visibility!
-
こんにちは!インスタンス https://misskey.sukonbu.party/ の管理者です。
現在、他サーバーからの移行や新規アカウント作成を問わず、人数と期間を限定して新規ユーザーを受け付けています。当インスタンスは招待制のため、ご希望の方は [email protected] までメールをお願いいたします。
様々な趣味・関心を持つ人が集まる、のんびりとしたインスタンスです。アップタイムは99.30%で、fediverse.observer では100点のスコアを獲得しています。
当インスタンスについてご質問があれば、お気軽にお尋ねください! #Misskeyサーバー紹介 #サーバー紹介 #インスタンス紹介 #ミスキー #マストドン #新規登録受付中 #招待制 #お引越し #移住先探し #newinstance #newinstancewhodis #findaserver #FindAnInstance #misskey #fediverse #fedi #fediadmin #fediadmins #mastoadmin #mastodon #mastodonmigration #fediverses -
Hello! I'm an administrator of instance https://misskey.sukonbu.party/
We are currently accepting limited amounts of new users for some time, whether it is to migrate from another instance or to have a new account. Our instance is invite-only so you'll need to send us a mail at [email protected]
We're a relaxed instance of varying interests with an uptime of 99.30% and a score of 100 from fediverse.observer
You can feel free to ask any questions you have regarding us! #newinstance #newinstancewhodis #findaserver #FindAnInstance #misskey #fediverse #fedi #fediadmin #fediadmins #mastoadmin #mastodon #mastodonmigration #fediverses -
CW: Start of an investigation into the Support_Team spam
You've seen the spam, now let's do some investigation.
The spam posts often contain a link to [email protected], which requires you to scroll down to the post they actually want you to fall for, which is https://mastoturk.org/@Support_Team/116967223561146251. This is a post probably trying to steal your Mastodon account. It's on a probably-uninvolved Turkish mastodon server. Carefully abusing
wget --max-redirect=0, I found out that the x.gd link redirect service points to hxxps://updatenotification.click/izyzf4g6c (link silenced by changing https to hxxps). I don't feel like pulling that over my clearnet connection, so let's go out via Tor...[ParkView ellenor]~/mastospam $ http_proxy=http://127.0.0.1:8118 wget -Oupdatenotification.click --max-redirect=0 https://updatenotification.click/izyzf4g6c --2026-07-23 04:56:46-- https://updatenotification.click/izyzf4g6c Resolving updatenotification.click (updatenotification.click)... 2606:4700:3033::ac43:a1cf, 2606:4700:3035::6815:a06, 104.21.10.6, ... Connecting to updatenotification.click (updatenotification.click)|2606:4700:3033::ac43:a1cf|:443... connected. HTTP request sent, awaiting response... 403 Forbidden 2026-07-23 04:56:46 ERROR 403: Forbidden.It didn't like that, not at all... Let me try spoofing my user agent to Firefox.
[ParkView ellenor]~/mastospam $ http_proxy=http://127.0.0.1:8118 wget -Oupdatenotification.click --max-redirect=0 --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0" https://updatenotification.click/izyzf4g6c --2026-07-23 05:02:36-- https://updatenotification.click/izyzf4g6c Resolving updatenotification.click (updatenotification.click)... 2606:4700:3033::ac43:a1cf, 2606:4700:3035::6815:a06, 104.21.10.6, ... Connecting to updatenotification.click (updatenotification.click)|2606:4700:3033::ac43:a1cf|:443... connected. HTTP request sent, awaiting response... 403 Forbidden 2026-07-23 05:02:36 ERROR 403: Forbidden.Can't believe it. What is it detecting? The fact that I'm using Tor (via Privoxy in this case)? Okay, you win, malware daddy, I'll give you my real IP.
[ParkView ellenor]~/mastospam $ wget -Oupdatenotification.click --max-redirect=0 --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0" https://updatenotification.click/izyzf4g6c --2026-07-23 05:04:52-- https://updatenotification.click/izyzf4g6c Resolving updatenotification.click (updatenotification.click)... 2606:4700:3033::ac43:a1cf, 2606:4700:3035::6815:a06, 104.21.10.6, ... Connecting to updatenotification.click (updatenotification.click)|2606:4700:3033::ac43:a1cf|:443... connected. HTTP request sent, awaiting response... 403 Forbidden 2026-07-23 05:04:52 ERROR 403: Forbidden.Okay so at this point I've hit a bit of a hard stop. What would you, the reader, suggest I do from here to try to bypass this?
#FediAdmin #BelieveInUmbrellix #lang_en