-
tom
morph jid: windy@conversations.im
-
tom
morph jid: whatiftres@jabber.cz
-
tom
morph jid: kgxhzfudg@conversations.im
-
tom
morph jid: wrathling@conversations.im
-
tom
morph jid: foxxly@chatterboxtown.us
-
tom
I am currently under a spam wave attack
-
tom
these jids are being created live
-
tom
any information about them would be appreciated
-
tom
morph jid: ottemawto@jabber.fr
-
tom
morph jid: cappitaii@jabber.cz
-
tom
morph jid: rekks@conversations.im
-
tom
arretint@conversations.im
-
tom
morph jid: redliner@conversations.im
-
tom
morph host utdfudjgx@jabber.cz
-
Martin
Is it really necessary to spam all the JIDs of this morph here? Maybe sou can do a morph MUC for interested people.
-
agh
It is not necessary, and borders on spam itself.
-
The Custodian
Wasn't there a blacklist aggregation where you report them to submit@reports.xmppbl.org and interested parties can subscribe to a feed to filter ?
-
sunglocto (sunglocto.net)
yes
-
tom
> Wasn't there a blacklist aggregation where you report them to submit@reports.xmppbl.org and interested parties can subscribe to a feed to filter ? unfortunately no client software actually implements this ↺
🤔 1 -
tom
when it comes to muc spam
-
Martin
The muc host should do, I guess.
-
tom
should != does
-
Kris
There are several bots that implement it when the server doesn't.
-
マリウス
re: morph no way this person is doing all of this manually; I'm starting to think that's some openclaw bs.
-
Kris
No this is a very disturbed person with nothing else to do.
-
Martin
tom: Then approach the server admins, I don't think spamming all operators here with JIDs is a solution.
-
Kris
They predate LLM by some years.
-
Kris
And reporting makes little sense as they switch accounts every 5 minutes or so.
-
tom
When morph spams they attack a whole bunch of servers at ounce
-
tom
I've been able to narrow it down to 4 servers they seem to be able to easily make accounts on
-
マリウス
it's especially not helpful as to all of us who don't log chats it's temporary. Hence I asked whether there's sort of a _living document_ where everyone can add their JIDs?
-
tom
``` conversations.im jabber.cz jabber.fr chatterboxtown.us ```
-
tom
If you are an op, please check those jids
-
tom
i'd be curious to know what ip they are coming in on and useragents
-
Kris
> it's especially not helpful as to all of us who don't log chats it's temporary. Hence I asked whether there's sort of a _living document_ where everyone can add their JIDs? Those are thowaway accounts they never use again after 5 minutes. ↺
-
Kris
We need more servers to implement the new account reputation XEP and a way to block accounts based on that.
-
moparisthebest
> We need more servers to implement the new account reputation XEP and a way to block accounts based on that. so everyone can block all new accounts and kill XMPP? ↺
-
Kris
How does it kill xmpp when new accounts can only join local mucs for a few days?
-
agh
>> We need more servers to implement the new account reputation XEP and a way to block accounts based on that. > > so everyone can block all new accounts and kill XMPP? Or block people who do not agree with a group's agenda. ↺
-
Menel
Every server should do what they want. Only let's not fool yourself that it will stop a dedicated human who does things non automated.
-
moparisthebest
> How does it kill xmpp when new accounts can only join local mucs for a few days? because new users can't join and chat like they can on every other platform, so they'll give up and move to IRC or discord etc where they can meanwhile it won't slow down morph at all, he already creates many accounts manually well before using them ↺
-
based.pt
>> >> so everyone can block all new accounts and kill XMPP? > > Or block people who do not agree with a group's agenda. honestly im not against it
-
based.pt
main reason i like xmpp is provacy, then its security but after that its freedom
-
based.pt
if i want i can make my own federation separate from the rest
-
based.pt
i think if you want to mass block people based on agenda and stuff i think it should be possible
-
agh
>> How does it kill xmpp when new accounts can only join local mucs for a few days? > > because new users can't join and chat like they can on every other platform, so they'll give up and move to IRC or discord etc where they can > > meanwhile it won't slow down morph at all, he already creates many accounts manually well before using them So essentially turning XMPP into a pseudo Walled Garden. We can see how certain groups would stand to benefit from that. ↺
-
agh
> i think if you want to mass block people based on agenda and stuff i think it should be possible It already is, thru private MUCs ↺
-
based.pt
>> i think if you want to mass block people based on agenda and stuff i think it should be possible > > It already is, thru private MUCs thats true actually
-
based.pt
you could autonate it with bots i think?
-
tom
>> it's especially not helpful as to all of us who don't log chats it's temporary. Hence I asked whether there's sort of a _living document_ where everyone can add their JIDs? > > Those are thowaway accounts they never use again after 5 minutes. Problem is how easily and quickly morph was-- is able to create accounts on reputable servers like conversations.im. normally conversations is able to protect against that. ↺
-
moparisthebest
how?
-
tom
> Every server should do what they want. > Only let's not fool yourself that it will stop a dedicated human who does things non automated. If a single person with obsessive mental issues can cause this much damage xmpp-wide we don't stand a chance when there are financial incentives to abuse xmpp professionally unless something changes. ↺
-
tom
This is just an early warning sign.
-
agh
What exactly is the damage?
-
agh
Morph is not stupid.
-
tom
>> How does it kill xmpp when new accounts can only join local mucs for a few days? > > because new users can't join and chat like they can on every other platform, so they'll give up and move to IRC or discord etc where they can > > meanwhile it won't slow down morph at all, he already creates many accounts manually well before using them Perhaps the plugin should also report on how many stanzas in the last 90d a newly registered user makes ↺
-
Menel
tom: there is only one way to stop people manually doing this stuff : Don't federated with any server that allows anonymous registration.
-
tom
Thats not true
-
tom
We need better spam mitigation software
-
Menel
Email is much more restricted and closed off then xmpp but even there it's laughable easy to create a lot of accounts at free providers and spam a single person. If you do it manually... You can't protect it.
-
tom
And admin tools
-
tom
Not just xeps with no client implementation
-
tom
Even if its a standalone tool, thats what privileged entity could be used for.
-
tom
Doomerism theres nothing we can do isn't helpful. Individual servers will do what they need to, but having tools that make it easy for an admin to raise and lower a security level would help significantly. Sort of like a DEFCON. This is how most adaptive network security products work.
-
tom
Email has weighted spam detection. Xmpp doesn't have such a system.
-
agh
Hmm the weighted spam system of email is a good point.
-
moparisthebest
Because it doesn't work with short messages
-
moparisthebest
And email is 99% spam so how is that working out
-
agh
It works pretty well. I get more spam on my cellular number than email.
-
tom
> And email is 99% spam so how is that working out Rspamd works really well. ↺
-
agh
That is easily sorted with disabling all notifications within the dialer and SMS applications.
-
Menel
Email spam systems wouldn't stop someone manually writing and harassing you. They work well on auto spam messages send to millions
🔼 4 -
Kris
>> How does it kill xmpp when new accounts can only join local mucs for a few days? > > because new users can't join and chat like they can on every other platform, so they'll give up and move to IRC or discord etc where they can > > meanwhile it won't slow down morph at all, he already creates many accounts manually well before using them It is perfectly normal to have account cooldown periods. Many apps implement that. And morph will quivklx run out of accounts if they have a cool down.✎ ↺ -
Kris
>> How does it kill xmpp when new accounts can only join local mucs for a few days? > > because new users can't join and chat like they can on every other platform, so they'll give up and move to IRC or discord etc where they can > > meanwhile it won't slow down morph at all, he already creates many accounts manually well before using them It is perfectly normal to have account cooldown periods. Many apps implement that. And morph will quickly run out of accounts if they have a cool down. ✏ ↺
-
moparisthebest
hard disagree on both points /shrug
-
based.pt
the morph obcession😭😭✎ -
based.pt
the morph obsession😭😭 ✏
-
based.pt
this community really is small
😂 4 -
TheCoffeMaker
dudes ... enjoy morph, use his companion to practice the trolling arts
-
array
morph has been obsessed with me lately too lol
-
array
didnt know he was an annoyance to everyone else outside the 3 or so mucs i see him in
-
moparisthebest
Just link him the txt file and he'll leave
-
array
> Just link him the txt file and he'll leave this one? https://www.moparisthebest.com/morph.en.txt ↺
-
array
moparisthebest, btw your yubikey framework expansion is sick!
❤️ 1 -
moparisthebest
>> Just link him the txt file and he'll leave > this one? https://www.moparisthebest.com/morph.en.txt That's the one ↺
-
icebound.dev
If you are under attack set your channel to moderated for 24 to 48 hours.
-
jjj333_p [pain.agency]
> ``` > conversations.im > jabber.cz > jabber.fr > chatterboxtown.us > > ``` tom, ive blocked all of these except conversations.im, seems to be the only server of the bunch i have legitimate users from ↺
-
jjj333_p [pain.agency]
> If you are under attack set your channel to moderated for 24 to 48 hours. this does work, i dont because of an edge case with my bridge setup, but thats a me issue ↺
-
icebound.dev
> this does work, i dont because of an edge case with my bridge setup, but thats a me issue Edge cases are edge cases, for the mass majority of us setting the channel to moderated is an effective way at curbing spam. ↺
-
jjj333_p [pain.agency]
I also recommend disabling muc dms except for to mods, however morph doesnt seem to really ever touch dms
-
jjj333_p [pain.agency]
> Edge cases are edge cases, for the mass majority of us setting the channel to moderated is an effective way at curbing spam. yes i figured i was implying that ↺
-
jjj333_p [pain.agency]
i was agreeing with your message even
-
icebound.dev
Apologies.
-
jjj333_p [pain.agency]
> this community really is small theres 4 people on xmpp and 5 of them are trolls ↺
-
jak2k
Who or what is morph?
-
based.pt
xmpp lore
-
jak2k
> xmpp lore Where can I read more about that? ↺
-
based.pt
ask the elders
-
TheCoffeMaker
>> this community really is small > theres 4 people on xmpp and 5 of them are trolls yeap .. we like bridges u know ↺
-
TheCoffeMaker
>> xmpp lore > > Where can I read more about that? https://www.moparisthebest.com/morph.en.txt ↺
🤦 1 -
jjj333_p [pain.agency]
> Who or what is morph? jak2k, its not up to date, but https://www.moparisthebest.com/morph.en.txt is a good start ↺