XMPP Service Operators - 2019-12-11

  362. atom

    Ge0rG: https://github.com/JabberSPAM/jabber-spam-fighting-manifesto/pull/23

  363. Licaon_Kter

    atom: TEN we have TENNNNN

  365. atom

    Licaon_Kter: 10 out of 10 is >80%

  367. Licaon_Kter

    ~80% let's be honest here

  369. atom

    Licaon_Kter: statistics show a clear misunderstanding of the purpose of the manifest.

  370. Licaon_Kter

    _"10 out of 10 agree with atom"_

  372. atom

    Licaon_Kter: you are witty, but your jokes do not solve the problem.

  373. Martin

    > Licaon_Kter: statistics show a clear misunderstanding of the purpose of the manifest. Why don't you help to clarify it?

  375. Martin

    What is the point they get wrong?

  378. Licaon_Kter

    atom: what is the problem? As Martin said, effing add a PR and clarify it instead of "omg delete github" reaction that 404 has

  381. atom

    Licaon_Kter: the problem is that the manifest is bad. it does not include a list of all manifest compliant servers. the list of servers subscribing by manifest becomes scapegoats.

  384. perflyst

    atom: are you new 404city support?

  386. perflyst

    atom: are you the new 404city support?

  391. Licaon_Kter

    atom: you know there's *another* list with the actual blocked servers, right?

  392. Licaon_Kter

    This is just a page with "I agree spam is bad"....and nothing else

  393. Martin

    > scapegoats Scapegoats for what?

  394. atom

    Licaon_Kter: Communities of servers such as blabber and disroot use the manifesto to criticize that all signatories want to enter registration by phone number and for block competitors' servers.

  395. atom

    The manifest is bad because it allows such interpretations.

  396. perflyst

    i am quite sure muppeth never said that

  397. atom

    perflyst: ask him to sign the manifesto, he will refuse.

  398. perflyst

    yes, for good reasons

  399. perflyst

    but i will put my hand for him in fire that he never said that all servers on the list will block any servers which not on the list nor forcing phone number

  401. atom

    > This is just a page with "I agree spam is bad"....and nothing else I understand this, others do not understand.

  402. atom

    > but i will put my hand for him in fire that he never said that all servers on the list will block any servers which not on the list nor forcing phone number This is what users of his server and his community say.he does not sign the manifesto for this reason.

  404. atom

    the manifest in the form in which it exists is unnecessary and harmful. Did the manifest win spam? - not. Did he create a bunch of criticism? - Yes

  409. Licaon_Kter

    atom: > Communities of servers such as blabber and disroot use the manifesto to criticize that all signatories want to enter registration by phone number and for block competitors' servers. Links? Pics? Provide some effing evidence...e

  410. Licaon_Kter

    Competitors? Wtf?

  413. atom

    Licaon_Kter: I have no purpose to convince you. If you are looking for evidence, you will find it yourself by creating a discussion.

  414. Martin

    > the manifest in the form in which it exists is unnecessary and harmful. Did the manifest win spam? - not. Did he create a bunch of criticism? - Yes People following the manifesto got spamming servers operators improve their spammer detection, countless spammers were deleted and some abandoned servers even shut down. It's progress. What did you expect? Spam instantly stopping from one day to another? It's a continuous process.

  418. atom

    Martin: spammers create accounts not on shabby servers, but on active servers. how will the manifest help from spam if the spammer creates an 100 000 account on yax.im?

  421. Martin

    yax.im is good at detecting spammy behavior so they go for easier victims.

  423. atom

    Martin: I got spam from yax.im

  430. marc0s has left

  431. marc0s has joined

  432. perflyst

    can happen, nothing is perfect but that is why contact addresses exist

  435. atom

    spammers receive $ 50-100 for spam mailings. New domain price $ 1

  437. Ge0rG

    I haven't had outgoing spam on yax.im in over a year. And before that, I was really fast at finding the accounts and deleting them.

  438. atom

    the price for 1000 captcha is also 1 dollar

  439. Ge0rG

    atom: you've created the discussion. You don't have any evidence. I know there was controversy about the manifesto, but not in the ways you argue

  440. atom

    Ge0rG: I do not have s2s for about a year. therefore, I have not received spam from yax.im for about a year.

  441. Ge0rG

    atom: so you tell me you received a spam message from yax.im once, and now it's your proof of the manifesto not working?

  442. Licaon_Kter

    > I have no purpose to convince you. If you are looking for evidence, you will find it yourself by creating a discussion. Why not put theis evidence there on Github instead of coming down the mountain with *"TEN"* in your hands?

  443. Licaon_Kter

    > atom: are you the new 404city support or PR or socket puppet or?

  444. atom

    Ge0rG: I do not argue about the manifesto.I suggest to execute pull request.

  446. atom

    Ge0rG: https://github.com/JabberSPAM/jabber-spam-fighting-manifesto/pull/23

  447. atom

    Licaon_Kter: yes

  449. perflyst

    > Ge0rG: I do not have s2s for about a year. therefore, I have not received spam from yax.im for about a year. so 404city users and the other way cannot chat with yax.im users?

  450. perflyst

    Nice anti spam

  453. Ge0rG

    perflyst: yes, sadly

  454. perflyst

    rather i would get spam than not being able to chat with someone

  457. Licaon_Kter

    Ge0rG: wait...so he bans server willynilly then comes to github to take the manifesto down? Hypocrisy much?

    Licaon_Kter: it's not a ban, we just have different opinions on which ciphers are secure

  461. atom

    perflyst, 404 (support ECC & RSA) <=> yax.im (support RSA)

  462. perflyst

    so 404 to yaxim works as you support "old" RSA and new ecc?

  463. perflyst

    or what do you wanna say

  464. atom

    404 use ECC

  465. perflyst

    even if the receiving server extremly unsecure, dont you want as admin the best server support? i mean normally you also allow weak ciphers on email so nobody has issues with any old shitty remote server

  466. perflyst

    what is the & for?

  471. atom

    perflyst, 404.city (ECC&RSA) => (conected) => yax.im (RSA) . Yax.im (RSA) = (no connected) = 404.city (ECC)

  473. perflyst

    so yaxims openssl (?) is old or what is the issue?

  474. perflyst

    or does yaxim manually forbids curves?

  475. Ge0rG

    perflyst: I don't trust into ECDSA

  476. perflyst

    ok, so basically you are blocking it?

  479. perflyst

    because ECC is a "standard" and anyone can use it

  480. atom

    perflyst, Yax.im server policy does not allow any ECC servers

  481. Ge0rG

    I've enabled ECDSA now.

  482. Ge0rG

    just so my users can keep sending spam to atom

  483. Licaon_Kter

    Ge0rG: 👍

  484. perflyst

    good choice :)

  485. atom

    Ge0rG, 👍

  486. Licaon_Kter

    Luckly there's no manifesto to keep you in check anymore, go ahead, by bold Ge0rG

  487. Ge0rG

    ECDSA is one of the worst crypto algorithms in modern use

  488. perflyst

    lets dont discuss this, this will not end good

  491. jayteeuk has left

  492. jayteeuk has joined

  493. Ge0rG

    atom: but you are the smartest of all. you still keep fighting spam, and doing what the manifesto tells, but you are not listed any more! :D

  494. perflyst

    (disroot does the same, ironically)

  495. Ge0rG

    BTW, there seems to be a new spam haven, exlpoit.im

  496. Ge0rG

    (note the typo)

  497. jayteeuk has left

  498. jayteeuk has joined

  499. Maranda has left

  500. Maranda has joined

  505. lorddavidiii has left

  506. lorddavidiii has joined

  511. Licaon_Kter

    Ge0rG: they're just a victim of your evil manifesto!!!!111

  512. Ge0rG

    speaking of which... my top 10 spam servers by number of messages in the last two weeks: messages bots domain ---------- ---------- ------------------------------------ 342 256 jabber.ipredator.se 334 303 darkengine.biz 326 264 xmpp.su 313 2 exlpoit.im 302 273 jabber.no 278 263 jabber.sibnet.ru 192 182 bytesund.biz 185 170 jabber.vikings.net 174 156 resolution1.net 158 153 ajabber.me

  513. atom

    1 bot = 1 messenges

  515. Licaon_Kter

    Ge0rG: nice bots

  516. Licaon_Kter

    atom: 1 bot 156 messages

  519. atom

    Other servers

  520. Ge0rG

    no spam from 404.city because no s2s ;)

  521. atom

    xmpp.is recently deleted 100,000 account created per day. xmpp.is use captcha

  522. Ge0rG

    how recently?

  524. Ge0rG

    my last spam from them was Nov 28th

  525. Ge0rG

    yow stpeter

  528. atom

    I disabled in-band 404.city to combat spam

  529. Ge0rG

    I've heard spammers also use web registration

  531. atom

    Ge0rG, Yes, spammers can bypass Google captcha and regular captcha Ejabberd and Prosody.

    >Ge0rG‎: how recently? About a month ago

  536. paul has left

  537. paul has joined

  540. Ge0rG

    atom: can you tell the date? > my last spam from them was Nov 28th

  544. Maranda

    > Ge0rG, Yes, spammers can bypass Google captcha and regular captcha Ejabberd and Prosody. 🤔

  545. Maranda

    Hmm nay

  546. Maranda

    Maybe regular

  547. Martin

    Ge0rG: https://xmpp.is/2019/10/17/registrations-closed-once-again/

  550. Maranda

    Maybe regular

  551. Maranda

    At this time Prosody stable does not support SNI in their HTTP library. I have enabled Google’s captcha but it will not work without SNI support from Prosody. Please see this tweet for further details:

  553. Maranda


  554. Maranda

    That doesnt make sense... 🤣

  557. Maranda

    Because no spam bot on xmpp can solve recaptcha

  558. Ge0rG

    Recaptcha can be bought from India

  559. Maranda

    Ge0rG: "chingalini" human solving yay 🤓

  560. Maranda

    Too much money for xmpp

  561. stpeter

    How much?

  562. Maranda

    Again the more I read the more *PEBCAK* resonates impedingly in my mind

  563. stpeter

    I don't know how much money people pay for XMPP spam vs. email spam....

  564. Maranda

    stpeter: too much, nothing pierced through mod_spim_block from when I implemented reCAPTCHA, and for nothing I mean nothing

  565. Maranda

    Not even just mail verification for IBR

  566. Licaon_Kter

    atom: get Maranda, the enemy of privacy, asking for email

  568. Maranda


  569. Ge0rG

    And use recaptcha

  570. Maranda

    And sending stuff to evil google

  571. Maranda

    > And use recaptcha 💖💋

  572. Licaon_Kter

    Hey, I can't even solve reCaptcha, so it must be gud

  573. Maranda

    Licaon_Kter: well it works

  589. Ge0rG

    I'm not doing any of those, but spammers on my server won't ever reach their audience, and get deleted promptly. And my users can just simply do IBR

  590. 404.city has joined

  591. atom has joined

  596. atom

    Recaptcha is useful when adding contacts or first sending messages. Recaptcha at registration is ineffective. https://rucaptcha.com/ $0.60 = 1000 recaptcha solution

  597. 404.city has left

  602. ackerman1scott has left

  603. ackerman1scott has joined

  604. stpeter

    Interesting. That makes sense.

  612. Licaon_Kter

    Martin: https://xmpp.is/2019/10/20/registrations-are-back-again/

  615. Martin


  616. louiz’

    just a response to your last link, I think

  617. Martin


  618. Licaon_Kter

    Martin: and reCaptcha saves the day

  623. Licaon_Kter

    Martin: right, just that it seemed they're given up

  624. Ge0rG

    So it's time to report to them again

  632. atom has left

  633. madmalkav has left

  634. madmalkav has joined

  637. volker has left

  638. SouL has left

  639. Alin has joined

  640. SouL has joined

  645. atom has joined

  646. atom

    > Ge0rg wanted to know when they deleted spammers, not when they added recaptcha… Martin: Use backup before mass bot registration

  647. Martin


  648. Martin

    I don't have registry open.

  649. atom

    Martin: incorrectly translated you

  650. Ge0rG

    What? Just restore from backup and lose everything that happened after it?

  651. atom

    Ge0rG: yes. xmpp.is used backup for delete 100 000 bot account

  656. Ge0rG

    Because you can't just delete them?

  657. marc0s has joined

  658. atom

    I think this server has a daily backup

    That doesn't matter

  667. Maranda

    atom, but that doesn't work, *coughs*

  670. tom

    Why was recaptcha chosen over any other captcha system?

  675. sonny has left

  676. Maranda

    tom, because it's the only one that _does something_?

  677. tom

    What is does something?

  678. tom

    I don't understand

  679. Maranda

    the opposite of _does nothing_

  680. tom

    I don't understand

  681. Maranda


  682. Licaon_Kter

    tom: not bypassed

  683. tom

    Perhaps your doing something wrong them. The whole point of captchas are to stop bots

  684. atom

    > Why was recaptcha chosen over any other captcha system? recaptcha is a good captcha, but it is powerless against schoolchildren introducing captcha for 1 dollar per month.

  687. tom

    » recaptcha is a good captcha It is really not in my experience. For one it false-positives 90% of the time if your not signed into a Google account or using a Google branded browser, it also leaks your metadata to Google which use it in nefarious ways which may not always be GDPR compliant or follow the correct privacy laws per jurisdiction, and a lot of people are not comfortable or OK with helping Google replace drivers with AI or listening to random audio recordings from people's homes.

  688. tom

    And other times it will just decide that it does not like you and make you infinitely solve visual puzzles

  689. atom

    tom: recaptcha has translation into all languages ​​of the world

  690. tom

    Recaptcha is especially a problem for the handicapped, and a lot of the times it will not let you solve audio based captchas

  691. tom

    Not to mention you must ping google to even load the javascript in, which is a privacy hazard in of itself

  692. Maranda

    > it also leaks your metadata to Google which use it in nefarious ways huhu care elaborating which such important metadata does it leak to google that it could use in such "nefarious" ways please?

  693. atom

    tom: recaptcha is a good captcha for stop bots, because it is not able to be solved by a bot.I'm talking about technology. google good or evil is a separate issue.

  694. tom

    It's not able to be solved by non-google using people either

  698. atom

    people have to pay for solving captcha. if you need to enter a lot of captchas, the cost rises.

  702. atom

    plus it slows down mass mailing. the number of people deciding on captcha is also limited.

  706. tom

    There are plenty of replacement captcha services and self hosted solutions, as well as protocol-level options such as rate-limiting certain endpoints per ip range

  707. Pingu from Woodquarter has joined

  708. tom

    And adaptive intrusion prevention systems

  709. atom

    even a simple captcha will cause problems for spammers if they receive it when adding a contact.

  712. tom

    Just slapping a javascript captcha on something, and the worse one at that doesn't just *reduce* the amount of bots, it also reduces your legitimate traffic, angers users, and violates their privacy by allowing information disclosure to third parties

  713. tom

    I run ecommerce websites. There's a lot more at stake when your dealing with actual money is products than just a message passing system that can be used for spam

  714. atom

    tom: what other measures do you offer besides captcha?

  728. Maranda still didn't get an answer.

  729. Maranda


  730. Ge0rG

    atom: today's xmpp spam can be easily detected and blocked without any captcha

  735. Martin

    contains russian, contains something about coins and telegram links → spam

    Martin: these are popular topics of discussion among Russians

  742. Martin

    Ok, a message containing all three things can be a normal message?

  747. Frinkel has joined

  748. atom

    Martin: Some spam bots divide one message into several and even lead a simple dialogue. Now this type of spam bots has become less popular.

  749. Ge0rG

    atom: the worst one so far just sent different versions of "hello" and spammed you when you responded

  752. atom

    Ge0rG: yes

  754. Ge0rG

    But I've only seen one such bot, with a single JID. Easy to block again

  758. atom has left

  759. atom has joined

  761. stpeter

    Oh I've seen several of those.

  784. Ge0rG

    stpeter: please tell me their JIDs

  785. stpeter

    In the future I will. I didn't note them before.

  811. atom has left

