XMPP Service Operators - 2018-11-14

  117. edhelas yes
  118. edhelas same for me
  119. edhelas draugr.de, unstable.nl...
  120. edhelas looks like I'll have to put some more servers on the blacklist
  121. Ge0rG has left
  122. Licaon_Kter edhelas: did you contact the admins?
  123. edhelas :3 natuulijk
  124. Licaon_Kter edhelas: and the spam continued because they did nothing so off to the ban list? Hmmm
  125. edhelas for now I just contacted them
  126. edhelas let's see
  127. edhelas but if I still have spam
  128. edhelas then it's blacklist yes
  129. Ge0rG I've got a spam escalation process of: 1. try to contact server admin (XEP-0157, website), wait up to a week 2. contact the server IP abuse department, wait up to two weeks 3. blacklist the server (not yet implemented)
  130. Ge0rG Also an internal spam tracking tool
  131. Ge0rG it's not perfect yet, but it allows tracking progress of the domain and IP admins.
  132. Ge0rG Also could somebody please report 0nl1ne.cc and blackjabber.cc to leaseweb abuse, because they are only forwarding my reports to the server owners instead of shutting the f***ing spam boxes down.
  133. edhelas blackjabber.cc is blacklisted
  134. Ge0rG edhelas: according to the Manifesto, I'd like to maintain a common and public list of blacklisted domains, including at least a reference to the previous escalation process
  135. edhelas is this list somewhere ?
  136. edhelas the issue about exposing that list is that the spammers can easily know how to circumvent it :)
  137. Ge0rG edhelas: circumvent it by... going to other unmaintained IBR-enabled servers?
  138. Link Mauve edhelas, I meant spammy IBR registrations, not spam from other servers.
  139. Ge0rG Link Mauve: what's the difference?
  140. Link Mauve Even though the former is probably the first step to the latter.
  141. Link Mauve Ge0rG, one happens on my server and I can block it immediately, the other will go on for years.
  142. Ge0rG Link Mauve: just put your own domain on the blocklist. All problems solved.
  143. edhelas IBR registration is just not a good idea to me anymore
  144. edhelas not without at least a captcha or something like that
  145. Link Mauve edhelas, CAPTCHA doesn’t do anything.
  146. Link Mauve We didn’t have fewer successful account creation before we disabled it.
  147. Link Mauve And as a user it’s painful for no benefit.
  148. Link Mauve (Except to Google.)
  149. edhelas I'm wondering if in the process of checking if a server is "spam risky" or not, having IBR enabled would not lower the score automatically
  150. Ge0rG edhelas: I run an IBR server and have got zero spam bot registrations in the last three months or so, because I'm preventing most spam delivery
  151. Link Mauve They don’t seem to know that about my server.
  152. Ge0rG ingress spam stats from last two weeks on yax.im: messages bots domain ---------- ---------- ------------------------------------ 5741 1153 otr.chat 3742 1403 0nl1ne.cc 3661 1738 blackjabber.cc 2974 2268 jabberes.org 2968 917 aquilius.de 1438 555 jabber.ipredator.se 1372 982 legalize.li 1353 523 fin77.info 1282 473 kommandostab.de 1216 605 jabber.sampo.ru
  153. edhelas what tool are you using to detect spam ? it's with ejabberd ?
  154. Ge0rG edhelas: it's based on prosody mod_firewall
  155. Ge0rG Error> No Contact Addresses for otr.chat
  156. Licaon_Kter Let me say it again, force "OMEMO on for the first message"...zero spam until they implement it in all sorts of bot clients ;) then we reap the benefits of free libs :D
  157. Link Mauve Licaon_Kter, zero message from most of my users either then.
  158. Link Mauve You could as well block s2s with me.
  159. Licaon_Kter Clearer...unless it answers in the first message with captcha or 1+1=2 any messages (not to admin) are blocked.
  160. Ge0rG is there a website on otr.chat? I'm on a limited wifi currently
  161. Link Mauve Yes, but An error occurred during a connection to otr.chat. SSL received a record that exceeded the maximum permissible length. Error code: SSL_ERROR_RX_RECORD_TOO_LONG
  162. Licaon_Kter Link Mauve: why? No Gajim? No Converse? No ChatSecure? No Dino?
  163. Ge0rG Licaon_Kter: "zero communication until everybody leaves XMPP"
  164. Licaon_Kter Link Mauve: not s2s...not sure you got my idea
  165. Link Mauve Licaon_Kter, there are some Gajim and some Conversations, the other ones you quoted are insignifiants in my client stats, and most messages are using OTR or plain text.
  166. Holger Link Mauve: I understand your point about IBR being painful for users, but if you're saying it's not painful for today's spammers I think that's just plain wrong.
  167. Link Mauve Heck, there are more messages sent using legacy PGP than with OMEMO.
  168. Link Mauve Holger, CAPTCHA*.
  169. Licaon_Kter Link Mauve: ok, and it kills them to enable OMEMO for 1 message?
  170. Ge0rG Licaon_Kter: a security question would be a good trade-off between just blocking everything incoming and a proper spam filter
  171. Holger Link Mauve: Indeed :-)
  172. Link Mauve Licaon_Kter, probably yes.
  173. Licaon_Kter Ge0rG: yes... That..but I upped the hardness by OMEMO...
  174. Ge0rG Holger: IBR is painful for users?
  175. Licaon_Kter Link Mauve: oh Fffs go back to Watsayp
  176. Holger Ge0rG: CAPTCHA.
  177. Link Mauve Licaon_Kter, see https://stats.jabberfr.org/d/000000002/jabberfr?panelId=36&fullscreen&orgId=1 for live message statistics.
  178. Link Mauve Licaon_Kter, why would I tell that to my users?
  179. Licaon_Kter Link Mauve: I didn't say that
  180. Link Mauve (You can Ctrl-click on the yellow “message” at the bottom to only see statistics about messages with a body-like element being transferred.)
  181. Licaon_Kter Link Mauve: but I had my share of captchas and really....I'm fedup with those too.
  182. Licaon_Kter Link Mauve: ctrl on mobile? Yeah
  183. Ge0rG is there anybody in this room actually doing something against spam? reporting abuse to server admins / hosting companies? making usable plugins or filters?
  184. Link Mauve Ge0rG, I am.
  185. Ge0rG pulls a number at OVH now.
  186. Ge0rG okay, otr.chat has hello@otr.chat as the contact email. Dumped the JID list to them.
