WARNING: Phishing Attacks, HTML markup to hide urls, are now in Mastodon.

While Mastodon does not have markup to allow hiding urls, they share API with "friendica" and friendica ALLOW HIDING URLS.

And friendica accounts can post on Mastodon.
I have asked for a solution, none is forthcoming.

Click NO LINKS that come friendica. Be wary of links on Mastodon, as if Mastodon were "email" - without any protections.

Multiple reports of other fediverse branches allow hiding urls. No Clicking links

Mozilla, makers of open source free Firefox, joined Mastodon last week. Mozilla began testing Mastodon security, including how their server responded to attacks and more.

They found 5 major flaws, threats, including the ability to take over a server, control a server, with a post.

With a post. TootRoot.

"Mastodon fixes critical “TootRoot” vulnerability allowing node hijacking"

For 13 million users, #Mastodon NEEDS a security FOCUS.

Demand layers of protection.

https://arstechnica.com/security/2023/07/mastodon-fixes-critical-tootroot-vulnerability-allowing-node-hijacking/

Mastodon fixes critical “TootRoot” vulnerability allowing node hijacking

Most critical of the bugs allowed attackers to root federated instances.

Ars Technica
@kevinrns I see Mozilla.social online for months, but still closed for registration( that's why I'm at Vivaldi social right now.
@kevinrns This is why code needs to be open. Everyone can test it and help fix it.
@sten @kevinrns it needs to be open AND have resources that can audit it, security ain’t cheap
@Luk @kevinrns Yes! And for open code, the resources to code and audit can be with different organizations.

@kevinrns

Yikes.

In other news I would pay real money for people to stop using the word 'toot' to refer to posts in this place. It's the euphemism my dearly departed mother used to use for farting.

@resonancewright

Sure, i dont use paypal though.

@kevinrns some forks like glitch will show a preview of the target url for any links. Probably the only solution is if mastodon upstream does the same

@cinebox

Do you mean an image? An image of the resukting site doesnt expand the url. Show the url directly in the post. If a url is hidden, reveal it auromatically in plain text in the post, as the standard, as other software can do. As exampke it would display

"GO HERE" [ abcnews.com/perfectlynormal.html ]

@kevinrns yeah that’s what glitch does

@cinebox

Which is what 'glitch' (app version of mastodon) does?

Shows an image or reveals the hidden url automatically as plain text?

#MastodonNeedsRepair
#Mastodon

@kevinrns shows the URL for an <a>

Regardless, this isn’t exactly a new addition to the web

<a>: The Anchor element - HTML: HyperText Markup Language | MDN

The <a> HTML element (or anchor element), with its href attribute, creates a hyperlink to web pages, files, email addresses, locations in the same page, or anything else a URL can address.

MDN Web Docs

@cinebox

Yes phishing (phishing and hidden urls are good search terms) has been around for ages.

Imagine the fun if hashtags are included in the hidden part

Like if this want the hashtage for #climate but was i stead a hidden url. How many slow the click to check if a hashtag is a hidden url.

And now add editing to hidden urls.

@cinebox

Safety is ignored, power conglomerates have been taken down by phishing. School districts, hospitals. I would advise no one to access #Mastodon from a security needing computer. No hospital, school, business or utilities for now

#MastodonSecurity is an afterthought. #meta

@kevinrns can anyone tell us how to identify Friendica posts?

@yingtai

the address is @friendica or @something.friendica."some extension"

@kevinrns

are you talking about its use of BBCode or Markdown for formatted text in posts? i thought those links came through “raw” (unformatted) in most Mastodon clients — or is this something else? got a link to a writeup or bug report?

@kevinrns That is not new, is it?
Btw some clients like @Tusky have a feature to that makes links hidden by markup visible
@ConnyDuck @kevinrns @Tusky I would love this option in @tootapp too!
@blinkygal @ConnyDuck @kevinrns @Tusky Yeah that seems like it would be a good idea to add.
@Kevin Russell @KrissyKat 🏳️‍⚧️ Stop to think a moment. Which is the most well-known software in the Fediverse? That would be the first place to look for suspicious activities. You make it sound lik e "hiding urls" is something very suspicious. Would it be so strange if I wanted a 4 row link to an article to just show the title of the article instead?
I am not saying a bad actor couldn't use Friendica. Or any other software where this is perfectly normal. But my bet would be on something more well known. A warning is good - panic not so much.

@shimriez

Online security is layer after layer after layer of protections.
Clear visible URLs is the most basic of protections.

"What is phishing and how dangerous is it?"
News - By Darren Allan - last updated June 24, 2022 👈
It’s one type of threat that really shouldn’t be underestimated
https://www.techradar.com/news/what-is-phishing-and-how-dangerous-is-it

"Three common types of phishing scams"
https://www.getcybersafe.gc.ca/en/blogs/three-common-types-phishing-scams

https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams

"Shortcut LNK Files May Contain Malware"
https://www.opswat.com/blog/shortcut-lnk-files-may-contain-malware

What is phishing and how dangerous is it?

This is a threat that should not be underestimated.

TechRadar pro
@kevinrns do you have any example/POC of this?

@fuomag9

Example of hidden urls posted on mastodon? Just one sec, back searching, didnt bookmark it.

Here it is. Again I have no idea if the hidden url is still there, still the same as it was, about to be edited, or safe.

YMMV

https://mstdn.social/@hankg@friendica.myportal.social/110664223061565419

Hank G ☑️

I love Star Trek INtakes. This one has several. #StarTrek #StarTrekInTakes #humor #funny #GeekHumor

@fuomag9

This post has, what I assume, but do not trust, a perfectly safe url behind the blue html markup.

Now add mastodon editing to hidden urls.

"The first five urls he used, behind the hiding html, were fine, no malware, just porn pop ups," a security researcher might say, "until the sixth and seventh edit, then it was ransomware."

https://mstdn.social/@hankg@friendica.myportal.social/110664223061565419

Hank G ☑️

I love Star Trek INtakes. This one has several. #StarTrek #StarTrekInTakes #humor #funny #GeekHumor

@kevinrns

Anytime I see a link in social media I might want to visit, I copy it then paste it into the Trace URL form at https://wheregoes.com. Then I copy and paste the final link in the trace, sometimes after making some obvious modifications to it, into the browser to visit the link. I usually use Tor browser for this

It's hassle but it really makes me think twice before deciding to visit a link. It has also been a bit eye opening.

Good luck, everyone. Be careful out there!

Link Checker | Redirect Checker - WhereGoes

Where does this link go? This link checker is a tiny URL expander! It's also a great redirect checker! Know where you are going with WhereGoes.

WhereGoes

@jrredho

Online protection is layer after layer of safety measures, as your apparent risk increases, like John, you add layers.

There is NEVER a good reason to hide urls.

If you "trust" a site you might skip a layer, like John uses, if he is on johnswebsite.net or mybrothersblog.com mastodon is tens of thousands of websites run by randos, mostly but not all, lovable randos.

Removing ANY protections from Mastodon is a conspiracy of dumb.

@kevinrns glitch-soc, a mastodon fork also has the ability to do this

Google.com

Example Domain

@Ember

I want warnings and protections from these silly security noob lapses. Wtf. Wtaf. That fork of mastodon was written by Putin of course, with help by Bannon, the Chinese and Cambridge Analytica

@kevinrns @Ember im sorry what

@SympathyTea @Ember

Hiding urls is entirely and completely a security lapse. Its either a noob failure, or planned breakage.

@kevinrns @Ember im less focused on that
what do you mean by "that fork (glitch-soc) was written by Putin?

@SympathyTea @Ember

That is the explanation for the question.

@kevinrns @Ember glitch-soc also shows the actual domain next to it

@esm @Ember

Ah, that is good practice, and should be Mastodon's

Luci For Tai Chi (@[email protected])

@[email protected] @[email protected] dudebros who think they’re being allies by arguing with fascists and spreading propaganda can get the fuck away from me and stop speaking for me

Queer Party!
@kevinrns @Ember
this reply is literally all you need to know; what the actual fuck
@kevinrns so wait, are you worried about this kinda thing?
Example Domain

@yukijoou

Hey look, "whatever the hell this fediverse branch is" can phish svams too.

Mastodon is a sloppy fucking mess. Security is a joke.

Do Not EVER CLICK Any Links On Mastodon.

#Mastodon Is Just As Safe As Email 👈

@kevinrns running akkoma here, i assume pretty much all fediverse software will allow you to post such links though. and yeah, it’s “just as safe as emails”, it’s still just a fancy html editor after all, why would it be safer?

you’re still on the internet, i’d argue you’re still expected to follow basic security advice, like checking the url you’re going to when hovering, checking the url bar before entering any information, and using a context-aware password manager for all your logins that doesn’t autofill when the domain doesn’t match.

this kind of link customisation feature has been available on forums and online boards for decades at this point. some more modern internet discussion platforms seem to have removed it, which i think made some people forget, or just not learn, to use those other, safer, ways of ensuring the url you’re clicking on is what you expect. maybe mastodon should warn users with a pop-uo before opening such links? i don’t know, i’m not a ux designer, you can advocate for it upstream with whichever fediverse software you’re using if you want it tho, fedi is all about havibg options, after all

@yukijoou

Did I answer this? The freedom to hide urls reminds me of the right to racist propaganda.

Let me phish! For freedom.

@kevinrns well, this is the web, you are free to use extensions on your webbrowser that change that behaviour if you don’t like it. it seems far from the same as propaganda to me

if you’re just looking for excuses to be angry at something, i see no point in arguing further. if you really want change, i suggest advocating for it on the mastodon and other fediverse-compatible social network’s issue trackers

keep in mind though that this is an ability websites have had since the world wide web was invented at cern, and this is the first time i’ve heard it being compared to propaganda

Link shorteners have existed for a long time; I think you're making a bigger deal out of this than it is.
@kevinrns What does this exactly mean? do you mean like, using markdown's ability to hide links with text? or is there some actual security vuln with this
SearXNG instances

Online and offline instances

@sneexy

Just a sloppy mess. Like email.

@kevinrns Micro.blog also federates and allows markup urls.

@andrewbriscoe

Thanks, All hidden urls must be automatically revealed. Relying on your device to tell the difference between a long press, when remembered, and a click that loads the malware, is like saying "Rattlers in you hallway? ust grab 'em behind the ears.

Its not security.

Dont click any links in Mastodon, the urls are behind markup to hide the actual destination.

Dont Click On Mastodon Ever.

@Kevin Russell I know what fishing is. I know what a link shortener is. That is not what is used here. To see the full url, most clients let you do that by long pressing. This is neither shady nor what you call hidden. It's a feature that most software outside Mastodon uses.
Friendica is not a bad actor. Neither is Akkoma, Calckey, Hubzilla and the others. So no need to worry.

@shimriez

Mastodon needs to reveal full links in plain text when they are hidden.

@kevinrns I'm also not sure why you'd single-out frendica, since Wordpress can do thist too.

@spraoi

Mastodon must automatically reveal hidden urls, in plain text, beside the hidden url.

as is security sensible, as is done elsewhere.

Mastodon is 13 mikllion randios, on ten thousan rando servers. No idea who any are, its email squared.

Do not click links on mastodon, like you dont click links in email

@kevinrns
Great resource, thanks for the link 😎

@MostlyTato

search-engine "how hidden links phishing malware"

@kevinrns been a while since I had to deal with webpages, but can't you filter this stuff out at one of the many layers before finally sending out the html? I use my own antibrowser thin client for net/cloud apps so I would never see this particular problem.

@otheorange_tag

Mozilla, after joining Mastodon, because they love free, freedom and free people controlling their lives, took a moment to seriously test Mastodon, and found five critical threats, including the ability to root a Mastodon server with a post, a toot.

Automatically revealing actual urls, beside links under markup, is a basic layer of protection.

I hope Mozilla has more tests, more suggestions and joins in helping make #Mastodon security focused.

https://arstechnica.com/security/2023/07/mastodon-fixes-critical-tootroot-vulnerability-allowing-node-hijacking/

Mastodon fixes critical “TootRoot” vulnerability allowing node hijacking

Most critical of the bugs allowed attackers to root federated instances.

Ars Technica