XMPP Service Operators - 2023-02-24

  116. Ellenor Bjornsd.

    > nuegia.net wrote: > they told my themself they were going to create a ton of bogus accounts on various open reg servers to spam me with and then i didn't, although honestly that's more from fatigue and wanting to forget you existed than any change of heart.

  118. Ellenor Bjornsd.

    So, have fun with your server filled with right wingers. That's all I'll say.

  122. Ellenor Bjornsd.

    Mind also that you and we have about the same reputation here - nobody-knows-us essentially single-user server operators who have a bloodfeud.

  220. Thomas

    I activated captcha in my muc. The users don't get a captcha. It's empty. What is wrong?

  221. Harper

    if you're using ejabberd be sure you enabled the listen module for it too

  222. Licaon_Kter

    Thomas: which clients?

  223. Thomas

    Harper: I have activated the captcha with Gajim. Where can I enable the listen module?

  224. Thomas

    Licaon_Kter: the captcha is in the browser

  228. Ellenor Bjornsd.

    Licaon_Kter: it's a server feature requiring a user to click a link to be able to speak

  229. Harper

    some will show it inline, some won't, but if the link is blank then it is broken on server side

  230. Licaon_Kter

    I know what it is...if the server has no captcha setup, not sure what Thomas thought they enabled via Gajim

  241. Thomas

    Its a muc on the dismail server

  260. kuba_ has joined

  282. Django has joined

  293. Thomas has left

  294. Thomas has joined

  422. xso has left

  423. xso has joined

  478. rozzin

    > it's a server feature requiring a user to click a link to be able to speak That's supposed to help?

  487. Maranda has joined

  489. Guus

    I am confident that there is no single silver bullet to fix this problem. Many smaller improvements are likely needed. Not doing something because it won't fix the entire problem will leave us with _no_ fixes. That's worse.

  490. Licaon_Kter

    Guus: it's more about "threat model"

  492. Mjolnir Archon has joined

  493. Maranda

    Guus: there's no silver bullet but problem is that most servers that allow ibr just allow it unrestrictedly without any kind of verification or restriction

  494. Guus

    I don't think that defines a singular definition.

  510. Licaon_Kter

    rozzin: wait, no, not voice...you can join at first... then, after 6 months, using 3 older users refferals...then you get voice

  528. rozzin

    Licaon_Kter: > Think someone banned the admin here over their black cat pic/name, and that's not helpful I still don't quite understand what the rationale for that ban was—AFAIK he was always well-behaved here, so it seems like if he was basically kicked out of op-club ʿfor being too uglyʾ or something that just makes it harder for people to get reach him with admin issues..., which seems counterproductive TBH.

  529. Licaon_Kter


  537. moparisthebest

    It's not like requiring email for registration would fix anything, what like spammers can't get emails?

  538. benk

    They can

  539. Guus

    Again: there is no one single silver bullet here.

  540. moparisthebest

    Maranda: walled gardens do shitty things, unsure how that's relevant

  541. Menel has left

  542. Maranda

    And left just a few scattered human solvers registering accounts on matrix.org to actually attempt spamming, moreover the Muppet actually plaguing XMPP with the gross spam is using all servers with unsecured registration

  544. Maranda

    moparisthebest: your definition of Walled Garden doesn't meet mine ™️

  545. Menel has joined

  546. moparisthebest

    Will if a "network" is controlled by 1 company such that they can turn other people's servers off... I'm not sure what else you'd call it

  555. moparisthebest

    Define "securing open registration" because as far as I knew that is still an unsolved problem

  556. benk

    personally I'm not a fan of open registration

  557. Licaon_Kter

    Maranda: not sure you realise that many won't be here if their first encounter back in 2015 would have asked me to use an email. I host, yes, but why would I do that if my first impression would have been "just another silo"?

  558. Licaon_Kter

    Maranda: not sure you realise that many won't be here if their first encounter back in 2015 would have asked thew to use an email. I host, yes, but why would I do that if my first impression would have been "just another silo"?

  559. Licaon_Kter

    Maranda: not sure you realise that many won't be here if their first encounter back in 2015 would have asked thew to use an email. I host, yes, but why would I do that if my first impression would have been "just another silo" collecting emails?

  560. moparisthebest


  561. benk

    it looks good if you're an innocent user, so you think like, "I'm a nice person so it's nice to just sign up quickly" but as soon as you realize what is liable to go wrong then you wouldn't want risking them logging into your service

  563. moparisthebest

    But also note that collecting emails has never stopped any spammer

  564. benk

    collecting e-mails has only enabled spam

  565. moparisthebest

    Google usually requires a physical cell phone number to register an account now, also stops 0 spammers

  566. moparisthebest

    But if anyone has great ideas for "securing registrations" that not even Google or Facebook etc has thought of, by all means share

  567. Ellenor Bjornsd.

    I run closed registration but I have a shall-issue policy. If you ask, I will give.

  568. bkil

    Telegram and WhatsApp as well. And most spam on matrix originates from those two.

  569. bkil

    moparisthebest: You have already been invited to mod-ideas and I have also linked to my quite extensive notes about it.

  570. Maranda

    > <moparisthebest> Define "securing open registration" because as far as I knew that is still an unsolved problem Just adding (re)CAPTCHA suffices to give enough security to bar most of the automated registrations like it or lump it

  571. moparisthebest

    Also please remember anyone can spin up unlimited XMPP servers on unlimited subdomains trivially

  572. Ellenor Bjornsd.


  573. moparisthebest

    They aren't automated though

  575. moparisthebest

    This whole recent spam attack has been done manually by a human

  576. Maranda

    > <moparisthebest> Google usually requires a physical cell phone number to register an account now, also stops 0 spammers And you insist in denying the obvious so that's all I have to say

  577. bkil

    Ellenor Bjornsd.: I have been rejected from multiple shall-issue mailing lists because the owner "did not like the looks of my email address" without any sane reasoning or method for appeal.

  578. Licaon_Kter

    Maranda: how many "disposable email" domains do you ban?

    Is sme.moparisthebest.com one? (Hint: it is, MX records point at mailinator)

  602. Maranda

    Again pointless discussion

  603. benk


  604. bkil

    And it was not a disposable email address, it was a well known local provider (but intentionally not gmail.com)

  605. Maranda

    Denying the obvious, over dumb reasoning not my thing

  613. Maranda

    moparisthebest: and said (multiple times) already that while it may not stop human solvers it slows 'em down

  614. moparisthebest

    You mean it takes them a full second to solve a captcha? Unsure that's helpful

  620. rozzin

    Martin: > I put it up to document which servers I block. Other people can decide to follow it, but it's still my personal blocklist without any documented inclusion criteria etc. How do you even remember then? Or does it not matter?

  621. Martin

    There's a comment for each entry.

  626. Maranda

    > <moparisthebest> You mean it takes them a full second to solve a captcha? Unsure that's helpful I'm sorry but you have no arguments, and you're bickering nd trolling over the meaning of examples. *Fin*

  627. Maranda

    > <moparisthebest> You mean it takes them a full second to solve a captcha? Unsure that's helpful I'm sorry but you have no arguments, and you're bickering and trolling over the meaning of examples. *Fin*

  635. kuba_ has joined

  636. Licaon_Kter

    Maranda: what happens when a user that jumped through the hoops ends up beingwa spammer? Does that lower your trust in the email provider?

