Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://tiggi.es/@DeltaWye" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>DeltaWye</span></a></span> <span class="h-card" translate="no"><a href="https://corteximplant.com/@SynAck" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>SynAck</span></a></span> <span class="h-card" translate="no"><a href="https://pounced-on.me/@Kuniti_shino" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Kuniti_shino</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.de/@ErikUden" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ErikUden</span></a></span> OFC that's the nature of most services tht are open t new users.</p><ul><li><a href="https://infosec.space/tags/Abuse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Abuse</span></a> being a statistical inevitability:</li></ul><p><a href="https://infosec.space/tags/Shitter" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Shitter</span></a> (rather <a href="https://infosec.space/tags/Teitter" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Teitter</span></a> before <a href="https://infosec.space/tags/Mus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mus</span></a> ruined it!) had <a href="https://infosec.space/tags/API" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>API</span></a> <a href="https://infosec.space/tags/RateLimiting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RateLimiting</span></a> to make <a href="https://infosec.space/tags/Spamming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Spamming</span></a> less effective (255 Statuses per 24hrs) even back when <a href="https://infosec.space/tags/TweetDeck" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TweetDeck</span></a> was a seperate company...</p><ul><li>Making dynamical limits that instantly lockout i.e. brand new accounts sending the same.message to 10+ others as a DM within 48 hours of registration should act as a speed-bump to <a href="https://infosec.space/tags/Spammers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Spammers</span></a>. </li></ul><p>It won't prevent it entirely but make it more cumbersome.</p><ul><li>Sadly <a href="https://infosec.space/tags/Mastodon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mastodon</span></a> <a href="https://infosec.space/tags/Developers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Developers</span></a> <a href="https://github.com/mastodon/mastodon/issues/28605" rel="nofollow noopener noreferrer" target="_blank">refuse to acknowledge the need for efficient filtering.and ban list managment</a> that every other web-facing application / system can do using blocklist feeds.</li></ul><p>This prevents remediation and correction of <a href="https://infosec.space/tags/banlists" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>banlists</span></a> & <a href="https://infosec.space/tags/blocklists" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>blocklists</span></a>, leaving <a href="https://github.com/greyhat-academy/lists.d/blob/95bab7b3601030e7ad57bfc0516fa91362c8fcd5/blocklists.list.tsv#L21" rel="nofollow noopener noreferrer" target="_blank">a lot if domains burned forever</a> as the only.options are <em>"replace"</em> and <em>"merge"</em> and the average <a href="https://infosec.space/tags/ActivityPub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ActivityPub</span></a> admin or even <a href="https://infosec.space/tags/User" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>User</span></a> isn't going to learn or setup a <a href="https://infosec.space/tags/git" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>git</span></a>!</p><ul><li>which is frustrating as I maintain <a href="https://github.com/greyhat-academy/lists.d/blob/main/activitypub.domains.block.list.tsv" rel="nofollow noopener noreferrer" target="_blank">multiple</a> blocklists to help cleaning up the mess.</li></ul><p>I.e. there isn't really a good way to combat <a href="https://infosec.space/tags/Typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Typosquatting</span></a>-based <a href="https://infosec.space/tags/Phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Phishing</span></a> beyond <a href="https://github.com/greyhat-academy/lists.d/blob/main/typos.domains.block.list.tsv" rel="nofollow noopener noreferrer" target="_blank">banning.offending domains</a>...</p>