Post AVjTCTpsbgKJXGCBlo by flappypaddle@hijacked.download
(DIR) More posts by flappypaddle@hijacked.download
(DIR) Post #AVjMwQZMNsfx2wQmIK by alex@gleasonator.com
2023-05-17T01:36:53.971707Z
4 likes, 0 repeats
This is mildly annoying and very easy to prevent, but I don't feel like writing the MRF for it. Anyway, enable rate limiting on your server and use "by approval" registration mode or you're gonna be on Fediblock for a dumb reason.RT: https://social.selfprivacy.org/objects/71532636-b085-473d-b3c7-554eecadde90
(DIR) Post #AVjNaq490Yj9hp6EYi by realcaseyrollins@social.teci.world
2023-05-17T01:44:15.170939Z
0 likes, 0 repeats
@alex @xDXmbtPkjbaBhW @Gargron @Gargron tried this. It didn’t work.
(DIR) Post #AVjNyNWykfhk9koMYy by graf@poa.st
2023-05-17T01:48:31.241061Z
1 likes, 0 repeats
@alex alex come on. you know closing registrations or forcing by approval isn't the way to solve this. different captcha that requires user input beyond basic OCR, rate limiting the registration API endpoint and basic security fixes (that should be in the default nginx shipped with rebased and pleroma) are the way to solve it.
(DIR) Post #AVjOsjbjrFaMqJuV4S by alex@gleasonator.com
2023-05-17T01:58:36.841700Z
2 likes, 0 repeats
@graf Approval mode solves the problem. You're wrong.
(DIR) Post #AVjOwQ3GVb4tLiXhdA by graf@poa.st
2023-05-17T01:59:22.891169Z
3 likes, 0 repeats
@alex it solves the problem for platforms trying to stagnate, you're right. im trying to grow poast not sit around clicking 'approve' on everyone.
(DIR) Post #AVjP5bjoQeCYCRpDRg by alex@gleasonator.com
2023-05-17T02:00:57.726068Z
0 likes, 0 repeats
@graf Was your server getting mass registrations or just getting mentions? These are different problems.
(DIR) Post #AVjP8PgHiEldftVr6W by graf@poa.st
2023-05-17T02:01:32.992519Z
0 likes, 0 repeats
@alex no, because we took steps to prevent it. and we are taking steps to prevent the spam even federating to us. the proper solution. not locking down
(DIR) Post #AVjPD0FBiLR0EO1jw8 by graf@poa.st
2023-05-17T02:02:22.537504Z
0 likes, 0 repeats
@alex also yes we were getting them, sorryhere's a listtermbin.com/k095we've mitigated it by the fixes i sent to you in text
(DIR) Post #AVjPHhyH4zPH0UMM76 by alex@gleasonator.com
2023-05-17T02:03:08.927587Z
0 likes, 0 repeats
@graf What I'm saying is that pleroma.nobodyhasthe.biz and social.selfprivacy.org should be enabling "by approval" mode, not poast.
(DIR) Post #AVjPLiJnjLz1F4L368 by graf@poa.st
2023-05-17T02:03:56.859272Z
1 likes, 0 repeats
@alex NHTB has my fix in place, so do several other servers. what I'm saying is basic ratelimiting should be included in the pleroma nginx default config. we can lead this change instead of relying on others to solve it for us
(DIR) Post #AVjPg4Rv9qKvfhqLxo by graf@poa.st
2023-05-17T02:07:37.806201Z
0 likes, 0 repeats
@alex dont make me call you to bro out. im not trying to fight i want to fix this and ive been working all day to fix this and most of the afternoon yesterday
(DIR) Post #AVjQLPHwaEFIAxt4kK by alex@gleasonator.com
2023-05-17T02:14:02.895662Z
0 likes, 0 repeats
@graf This is an open source project provided to the community for free. Pay my salary, or submit a pull request with your suggested changes.
(DIR) Post #AVjQQBPHcdziZRb7HU by graf@poa.st
2023-05-17T02:15:57.354633Z
0 likes, 0 repeats
@alex this is actually really petty
(DIR) Post #AVjQZoJwJLRlrkgmKu by p@freespeechextremist.com
2023-05-17T02:17:43.457421Z
3 likes, 1 repeats
@alex @graf > What I'm saying is that pleroma.nobodyhasthe.biz and social.selfprivacy.org should be enabling "by approval" mode, not poast.If only it were possible to rely on other nodes in the network not being negligent or malicious. "We don't need filtering! We just need other servers to stop doing anything malicious!"This is like that "Pleroma doesn't force email confirmation! Make the software make people verify their email addresses!" bug you filed when you were using Mastodon.All this other software on the internet has been built with the expectation that you cannot control other nodes on the network and they might be buggy or actively malicious, and it was all built that way because you cannot control other nodes on the network and they might be buggy or actively malicious. You have to plan around that instead of just wishing that other people ran their nodes the way you want. This is the same approach that got that stupid spammy blockbot merged into your shitty excuse for a fork, and you said "Oh, it's all Pete's fault! He shouldn't do that!" instead of saying "A random person on the internet can abuse this, so someone on the internet will abuse it, so I should fix it to prevent that problem."
(DIR) Post #AVjR0ZJyBeDhAGSjD6 by graf@poa.st
2023-05-17T02:22:32.408911Z
2 likes, 0 repeats
@p @alex im not proposing sweeping changes at all. i just think basic ratelimiting should be included or even documented since this has been an issue for at least 2 (two)! years without any resolution. switching the captcha provider solves the easily bypassed captcha and allows instances that dont want to verify emails the ability to not have to require itrate limiting the api endpoint responsible for resgistrations to reasonable amounts turns an unmanageable flood into something that is very easily mitigated if the aforementioned fix isnt in place there's all kinds of ways to handle this. ive been trying my best to handle all of them and we've only had a handful of accounts despite hundreds of attempts and none of them made any automated posts.we're on the right track and fighting about it isnt the solution. we need to work together not demand payment from one another to do literally nothing
(DIR) Post #AVjRDKgJvZ63We0FMm by alex@gleasonator.com
2023-05-17T02:23:52.757766Z
1 likes, 0 repeats
@graf The actual solution is an MRF. But I do not have the time to implement it. Pleroma already has a built-in rate limiter on the registrations endpoint, so an nginx patch should not be needed. The built-in rate limiter is enabled by default, but could be misconfigured depending on the setup. In other words, we're already doing all the things we're supposed to be doing by default, but this is still happening to some servers. I'm not sure the nginx approach is the right solution. It's a bandaid. Configuring the built-in rate limiter will fix it, and a new MRF could stop duplication spam.
(DIR) Post #AVjROKFzqXGxOUvr1M by alex@gleasonator.com
2023-05-17T02:26:45.995037Z
0 likes, 0 repeats
@graf https://docs.soapbox.pub/backend/configuration/cheatsheet/#pleromawebplugsremoteip
(DIR) Post #AVjRPFsbbf1a6kQzc8 by graf@poa.st
2023-05-17T02:27:00.166247Z
1 likes, 0 repeats
@alex and im working on an MRF right now
(DIR) Post #AVjRaKTWrQAXXuzAPI by alex@gleasonator.com
2023-05-17T02:28:54.713312Z
0 likes, 0 repeats
@p @graf I agree with you.
(DIR) Post #AVjRlDxJRO4AVl6z2m by matty@nicecrew.digital
2023-05-17T02:30:59.043289Z
0 likes, 0 repeats
Well, approval mode solves the problem of people being able to get in without any moderation but it doesn't necessarily stop the issue of being spammed with signups. I think adding a different kind of Captcha (the more interactive one) for signups would help mitigate this issue. It seems that most of the accounts come in bursts, all at the same time so they're obviously using some sort of software to read the image and then pass it.Would rate limiting help mitigate this, or a stronger bot mitigation at signup? I think it's something that can be discussed especially if this becomes more of an issue in the future.
(DIR) Post #AVjRmTBqHkRO37VAsi by p@freespeechextremist.com
2023-05-17T02:31:12.986569Z
3 likes, 0 repeats
@alex @graf Took you long enough.
(DIR) Post #AVjSFQ9QfA4H1RB5pQ by NotoriousDOG@eveningzoo.club
2023-05-17T02:36:26.496340Z
3 likes, 1 repeats
This will fix it 😤
(DIR) Post #AVjSHYCVhmxsZDdPxQ by ins0mniak@freespeechextremist.com
2023-05-17T02:36:50.054322Z
1 likes, 0 repeats
@p @alex @graf WEll sucking dicks takes up a shitload of his time.
(DIR) Post #AVjSSfEnslBtZr0Tgm by alex@gleasonator.com
2023-05-17T02:38:43.273226Z
0 likes, 0 repeats
@matty @graf I built the registration microservice on Truth Social, and it involves configurable "challenges" including email verification and SMS verification. Captcha could be a challenge. "I am not a robot" could be a challenge. Etc. Admins can enable and order the challenges however they want.But for a Fediverse server, IP rate limiting is good enough. "By approval" mode is also a good default unless you have a reason not to be, such as wanting to be a public square. To those who say "then you'll get a flood of approval requests": first of all, enable rate limiting. Second, this is significantly less damage, as it is only an inconvenience to you as an admin rather than an inconvenience to your users and potentially the whole network.
(DIR) Post #AVjSeRFlhZiRgF4YXg by flappypaddle@hijacked.download
2023-05-17T02:39:21.279713Z
0 likes, 0 repeats
If you only had a little protein in your diet.. several of us got hit overnight and you're just going to throw your hands in the air and say yeah who cares? Are you only capable of writing a pretty front end and a socket between protocols? Stand beside your shit or deprecate it.
(DIR) Post #AVjSeRslMauLdBJhK4 by graf@poa.st
2023-05-17T02:40:56.781605Z
1 likes, 0 repeats
@flappypaddle @alex hostility isnt the answer friend, like i helped you and others we all need to work together to solve this, not fling shit at eachother
(DIR) Post #AVjSgvjtKLJcoGLmsK by matty@nicecrew.digital
2023-05-17T02:41:24.828832Z
0 likes, 0 repeats
This is true. I'm just trying to help as much as I can - normally it's via ideas since I can't do coding.
(DIR) Post #AVjSmzjtMsjEx9F64u by Hoss@shitpost.cloud
2023-05-17T02:42:28.678522Z
1 likes, 0 repeats
Give it a year and you'll be able to tell a robot to code whatever ideas you want in their entirety.
(DIR) Post #AVjSoKFyZP7EsOssTI by p@freespeechextremist.com
2023-05-17T02:42:45.455430Z
1 likes, 0 repeats
@ins0mniak @alex @graf :brandt:
(DIR) Post #AVjSofOC03AMPxtEh6 by alex@gleasonator.com
2023-05-17T02:42:41.540881Z
1 likes, 0 repeats
@flappypaddle @graf Why do I always have to be the one that solves it? I gave you so much, and you demand more. I'm not the Giving Tree. There are solutions, and I even made several recommendations in this thread.
(DIR) Post #AVjSsmW9RG35gUZh0C by flappypaddle@hijacked.download
2023-05-17T02:41:41.631084Z
0 likes, 0 repeats
Alex's solution is not one. I am a little annoyed as anyone who was hit deserves to be. Especially you.
(DIR) Post #AVjSsnzxvtUYHFX172 by alex@gleasonator.com
2023-05-17T02:43:28.164370Z
0 likes, 0 repeats
@flappypaddle @graf Write an MRF, retard. That's my answer.
(DIR) Post #AVjSuAa1ScFGbP2zya by matty@nicecrew.digital
2023-05-17T02:43:48.438788Z
1 likes, 0 repeats
But that's cheating...
(DIR) Post #AVjT2fuoq90y6VpY3c by Hoss@shitpost.cloud
2023-05-17T02:45:19.462789Z
2 likes, 0 repeats
That's what all the dweebs with no other marketable skills are going to say when the robot takes their job for real.
(DIR) Post #AVjT4Impnrdkwzs68O by graf@poa.st
2023-05-17T02:45:37.581473Z
3 likes, 0 repeats
@Hoss @alex @matty i didnt know shit about elixir but im trying my bed
(DIR) Post #AVjT7ZJQojjv4afyzI by flappypaddle@hijacked.download
2023-05-17T02:43:55.494889Z
0 likes, 0 repeats
You're right. Your integration of a service which doesn't work is not your problem.
(DIR) Post #AVjT7acbwufx8MeoWO by alex@gleasonator.com
2023-05-17T02:45:36.386115Z
1 likes, 0 repeats
@flappypaddle @graf Are you going to speak to my manager? 🤣
(DIR) Post #AVjTCTpsbgKJXGCBlo by flappypaddle@hijacked.download
2023-05-17T02:45:09.321815Z
0 likes, 0 repeats
If I can't trust your code or for you to fix it, I can't trust you. Thank you.
(DIR) Post #AVjTCUdVdA1e1BPp7w by alex@gleasonator.com
2023-05-17T02:47:02.041359Z
0 likes, 0 repeats
@flappypaddle @graf Did you pay me? If you have ever given me so much as even $10, I apologize. But you do understand we live in a capitalist world, right? I am suffering constantly.
(DIR) Post #AVjTK7HYLQVju3mT4a by graf@poa.st
2023-05-17T02:48:27.740024Z
4 likes, 0 repeats
@flappypaddle @alex alex isnt responsible for the captcha options available in upstream pleroma. i think they are very poor implementations and they haven't been resolved since this particular spam script was used in 2020, 2021, early 2022i am looking into options and if i can find one just as good without use of an API I will try it on poast and upstream it to rebased if it's functional for us.getting upset at alex for someone choosing to use your instance to spam others isn't the way. we need to work together not ostricize eachother. help me help everyone
(DIR) Post #AVjTMRJIqpTObBhtnE by Hoss@shitpost.cloud
2023-05-17T02:48:49.961041Z
0 likes, 0 repeats
If by "things change over time" you mean "tens of thousands of people who had six-figure jobs working functionally 10-20 hour weeks will be totally unemployed and lucky to find work as Walmart greeters" than yes, things change over time.
(DIR) Post #AVjTSFrSKchKpMSG0W by alex@gleasonator.com
2023-05-17T02:49:47.341374Z
2 likes, 0 repeats
@flappypaddle @graf Oh no!! I'm going to lose a $0.00 customer
(DIR) Post #AVjTXYSgbRN1xoOcZk by graf@poa.st
2023-05-17T02:50:54.687368Z
3 likes, 0 repeats
@alex @flappypaddle that means you too alex, stop instigating fights with people we desperately need to work together toward a resolution. shitflinging isnt going to solve anything even if he's being a piece of shit to you. you are the one who instilled this value in me two years ago. dont forget we are in this together
(DIR) Post #AVjTgtRdxPZHeFMSps by Hoss@shitpost.cloud
2023-05-17T02:52:35.528149Z
1 likes, 0 repeats
It's not really that hard to learn to use another language if you have all the base knowledge, an AI will be even better at it.Source: CS degree
(DIR) Post #AVjTmbRBoxXtXLs6HA by brimshae@poa.st
2023-05-17T02:53:38.832291Z
0 likes, 0 repeats
@graf @alex Grow Poast? Aren't you usually telling people to bug off and join/start their own instances?
(DIR) Post #AVjTnyyRnZecp75MPo by Tony@clew.lol
2023-05-17T02:53:53.357244Z
1 likes, 0 repeats
The "challenge" of coding is mostly syntax. Otherwise, an AI should be able to figure out just about any language as long as it has access to the syntax library. At the core it's just the computer's way of telling it's components to do stuff. Since AI is a computer, as long as it has the syntax, it should be able to figure out how to get itself to do whatever you want.
(DIR) Post #AVjTuGjMgzJxdH1p3I by graf@poa.st
2023-05-17T02:55:00.781521Z
7 likes, 0 repeats
@brimshae @alex spotted the nigger who isnt capable of reading the room80-85% of babbys first instance is poast. they come to fediverse because of poast or other larger instances. I have always treated poast as a jumping off point and we have ALWAYS encouraged people to start their own. you wanna start shit, start an instance and start it from there otherwise lurk moar faggot
(DIR) Post #AVjU3GBI6ZcQXBNUPY by Tony@clew.lol
2023-05-17T02:56:39.160542Z
2 likes, 0 repeats
*sounds of lurking intensify slightly
(DIR) Post #AVjU4TjbCQcqrJ0Rnc by p@freespeechextremist.com
2023-05-17T02:56:52.909959Z
1 likes, 0 repeats
@Hoss @matty @graf Been hearing that since the 80s. I'll believe it when I see it.
(DIR) Post #AVjU96YsmbaGRBCRRQ by Hoss@shitpost.cloud
2023-05-17T02:57:40.640017Z
0 likes, 0 repeats
See you in a year.
(DIR) Post #AVjUBDU80scQUMyzia by KitlerIs6@seal.cafe
2023-05-17T02:58:05.451122Z
1 likes, 0 repeats
That's not true though, at least of modern gpt AIs. Even when you provide them the exact definitions of the syntax and an example of the code they fail even hello world examples on novel languages.
(DIR) Post #AVjUGQGpu6uJagFRLM by Hoss@shitpost.cloud
2023-05-17T02:59:00.789233Z
1 likes, 0 repeats
I really don't think this is a problem that's going to take long to be overcome. Barely a speedbump.
(DIR) Post #AVjUIGaGtCBs7yDZSq by Tony@clew.lol
2023-05-17T02:59:22.149974Z
0 likes, 0 repeats
My knowledge comes from google and like 400 hours of codecademy. Anyone who writes code or programs software for a living should be taken much more seriously than me on everything computer related 😅
(DIR) Post #AVjUOGVW5TQHcwr1hQ by KitlerIs6@seal.cafe
2023-05-17T03:00:26.956018Z
1 likes, 0 repeats
You are far too impressed by modern AI. The level of adaptability you are talking about requires actual thinking and understanding, two things which are far beyond current AI's ability.
(DIR) Post #AVjUPWKYk50KzYKNRw by p@freespeechextremist.com
2023-05-17T03:00:41.070168Z
0 likes, 0 repeats
@Hoss @matty @graf https://en.wikipedia.org/wiki/Predictions_and_claims_for_the_Second_Coming
(DIR) Post #AVjUuZYcnL3ZyciI88 by KitlerIs6@seal.cafe
2023-05-17T03:06:17.534804Z
1 likes, 0 repeats
You were there lol.
(DIR) Post #AVjUuoEcE0xpUuT1Wa by Marvin@fans.sonichu.com
2023-05-17T02:55:43.820765Z
0 likes, 0 repeats
I started on glindr and I was like 90% of that instance. Then I launched my shitty instance from the cwcki domain.
(DIR) Post #AVjUySzZ9AnylyAi5A by graf@poa.st
2023-05-17T03:06:58.859697Z
1 likes, 0 repeats
@Marvin @alex @brimshae ive never seen a single person from that instance in 2.3 years of poast. glad you did friend
(DIR) Post #AVjVGO9vr0EYzqZAzA by KitlerIs6@seal.cafe
2023-05-17T03:10:13.833856Z
0 likes, 0 repeats
It was when I had kronor ask gpt 4 to do something with pancake stack.
(DIR) Post #AVjVNf23WEuTM1Lkp6 by Hoss@shitpost.cloud
2023-05-17T03:11:31.082384Z
0 likes, 0 repeats
You could've said the same shit about things it wasn't capable of a couple years ago that it does now with ease.
(DIR) Post #AVjVNpqlIZPauB9OFM by graf@poa.st
2023-05-17T03:11:33.890020Z
1 likes, 0 repeats
@NotoriousDOG @alex @matty this is poor especially with the rise of AI you can very easily copilot OCR and AI together to bypass this. you need shit like tiktok has where you have to spin stuff to make the image look normal
(DIR) Post #AVjVRnpWkaapnaSsTY by graf@poa.st
2023-05-17T03:12:16.860983Z
0 likes, 0 repeats
@NotoriousDOG @alex @matty actually you dont even need OCR you could likely just prompt it "fill in the missing word from this sentence" <$api_response>
(DIR) Post #AVjVT2hMxIosCaEwwy by NotoriousDOG@eveningzoo.club
2023-05-17T03:12:31.297906Z
0 likes, 0 repeats
Can’t be spinning shit when high and drunk 😤
(DIR) Post #AVjVa4zso8gzMGFtL6 by UnityOstara@poa.st
2023-05-17T03:13:47.627861Z
1 likes, 0 repeats
@graf @NotoriousDOG @alex @matty Hey! Everyone is complaining about the Canadian Wildfires smoke tripping down into Minnesota but I think it smells nice!
(DIR) Post #AVjVgrPFjiXhEZM5C4 by NotoriousDOG@eveningzoo.club
2023-05-17T03:15:00.873048Z
0 likes, 0 repeats
The only time Mr graf replies to me is when I’m being a smart ass and he thinks I’m trying help. Graf, my man. Imma computer retard. I own apple products. I’m mad because my laptop has changed colors 😬
(DIR) Post #AVjWCSqyYhioLqONsm by graf@poa.st
2023-05-17T03:20:42.572504Z
2 likes, 0 repeats
@NotoriousDOG @alex @matty no i generally reply to anyone i see in my notifications. because mine move so fast i dont always see people so i dont respond. sorry if i gave u the wrong impression friend
(DIR) Post #AVjWDz8c0lgMllMnQG by KitlerIs6@seal.cafe
2023-05-17T03:20:53.910427Z
0 likes, 0 repeats
Not really.
(DIR) Post #AVjWFAcEp3kuemmzEe by KitlerIs6@seal.cafe
2023-05-17T03:21:12.650256Z
0 likes, 0 repeats
I swear you were in that thread.
(DIR) Post #AVjWOXmy2EYf8JHG7c by NotoriousDOG@eveningzoo.club
2023-05-17T03:22:54.811130Z
0 likes, 0 repeats
I know graf, I know. I can only imagine what your inbox looks like. You’ve always answers my questions when asked.
(DIR) Post #AVjWgn7dlS7BtweEro by Deus@charcha.cc
2023-05-17T03:09:55.441711Z
0 likes, 0 repeats
Alex - How much would writing an MRF cost? Perhaps there’s a way to resolve this by pooling in 💰 ??And just how does one go about rate limiting? Looking up only shows me this 2020 post that’s of no use. /Here we go, learning more about the Fediverse.https://pleroma.social/announcements/2020/01/25/develop-rate-limiter-enabled-by-default/
(DIR) Post #AVjX0N3MOk1qqDyxk0 by KitlerIs6@seal.cafe
2023-05-17T03:29:44.896948Z
1 likes, 0 repeats
https://seal.cafe/@kroner/posts/ATeyC4oSO3CVI150yG
(DIR) Post #AVjfWlJiWKX0zhabSq by Deus@charcha.cc
2023-05-17T04:24:43.109061Z
0 likes, 0 repeats
Ah! Those Roblox ones. Even I struggle with those 😀
(DIR) Post #AVjfggJdyAtYNZHjEW by brimshae@poa.st
2023-05-17T05:07:02.230892Z
0 likes, 0 repeats
@graf @alex That's the Graf I know and expect! :002_blush:
(DIR) Post #AVjgG3mWiS2bICfGDY by UnityOstara@poa.st
2023-05-17T05:13:25.766998Z
0 likes, 0 repeats
@brimshae @graf @alex After being banned from old Twitter, coming to Poast, it's so much better! I'm only on new Twitter for a few people but Poast is my home!
(DIR) Post #AVjgJ8TJjbAEhw97IG by UnityOstara@poa.st
2023-05-17T05:13:59.036751Z
0 likes, 0 repeats
@brimshae @graf @alex Graf is a King!