Head's up, the "you must confirm your profile" scam is proliferating on the Fediverse. I wonder if they are trying to gather driver's licenses and credit card numbers? It's a scam.

#scam #MastoAdmin #cybersecurity

crap. Thanks for the warning.

@ai6yr

Maybe it's time to block Mastodon.social after all.

@ai6yr
Never trust anybody that uses that many emojis unironically ๐Ÿ˜‘
@ai6yr Mastodon dot social again. Glad I blocked that instance weeks ago.
@ai6yr of course itโ€™s coming from mastodon.social, their moderation sucks
@ai6yr confirm your account by sending me $1,000,000 USD.

@ai6yr

Honestly this is evil enough Mastodon
itself should issue regular warnings.๐Ÿ‘ˆ
Including importantly to new users, ๐Ÿ‘ˆ
during the setup and joining process.๐Ÿ‘ˆ

#Mastodon #coders #johnMastodon #joinMastodon #nubie #noobie #privacy #anonymity #trick #hacking

@kevinrns @ai6yr @Gargron posted a warning about it last week

@ai6yr
Always look at the text between the double-slash and the first slash.

Why would mastodon.social send you to "gig.com" for critical account maintenance?

They wouldn't.

@ai6yr Yeah, I've suspended two from mastodon.social so far today, and at least two yesterday.

@ai6yr

yeah, chasing the code using curl is fun. It's some russian script kiddie running through a swedish bank, which makes me wonder how long they'll be active.

I do kinda wonder how resilient their system is to a few hundred thousand requests of straight garbage, but looks like they're mostly just funneling toward the payment site.

@ai6yr I figured most people are on the Fediverse because they would never ask for this info.
@ai6yr ...wtf is gig dot com?
@FrankHghTwr I trimmed the rest of the malware/spam site off there.
@FrankHghTwr @ai6yr Hmmm, looking at it, seems to be.. some kinds of service company, online casinos, AI and more.
@ai6yr I have suspend the account already for violating Rule 8 from our server rules
@Kira Apparently there have been a whole series of them on mastodon.social -- hope they have it under control now
@ai6yr
Links to gig.com. Totally legit.

@ai6yr is it perhaps possible to have all external links lead to a page "you are leaving mastodon ... we will never ask for your ..."?

to be fair i don't know if measures like this are effective in practice

@saxnot @ai6yr
Like all the shitty social media sites do that don't want you to use anything outside their own network... Yeah, that'll be real popular๐Ÿคข

Of course, being Mastodon, it could be something that can be turned off in settings, the warning page could even have instruction how to do so. Still not a great idea, but maybe worth considering.

Although... How would that even work? Links to other Mastodon instances are just regular links, there is no way of differentiating between a link to another instance and a link "leaving Mastodon".

@ai6yr Can imagine after 25 July this sort of scam will become widespread and targeted at #uk users across social media sites and the fallout from the success of that #phishing will be pretty catastrophic...

#onlinesafetyact #scamalert #infosec

@Rastal @ai6yr This is how stupid ideas from people who consider themselves security experts end up, people who do nothing but create more vulnerabilities.

#UK

@Rastal @ai6yr That why AV in the UK is not lasting 2 weeks.
@ai6yr three item bulleted list with each item starting with an emoji followed by word colon explanation โ€‹โ€‹

@ai6yr If only Mastodon could do something against this spam on their flagship instances.

Hmmm. Open signups.

Hmmm. No admin-side filtering.

Hmmm. This sucks.

Add reject pattern to Admin setting by noellabo ยท Pull Request #29247 ยท mastodon/mastodon

It was created to refuse a large amount of spam by malicious attackers. This can be used immediately, but if there is something to improve, please suggest.

GitHub