this post was submitted on 18 Sep 2023
996 points (95.4% liked)

Lemmy.World Announcements

29157 readers
411 users here now

This Community is intended for posts about the Lemmy.world server by the admins.

Follow us for server news ๐Ÿ˜

Outages ๐Ÿ”ฅ

https://status.lemmy.world

For support with issues at Lemmy.world, go to the Lemmy.world Support community.

Support e-mail

Any support requests are best sent to [email protected] e-mail.

Report contact

Donations ๐Ÿ’—

If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.

If you can, please use / switch to Ko-Fi, it has the lowest fees for us

Ko-Fi (Donate)

Bunq (Donate)

Open Collective backers and sponsors

Patreon

Join the team

founded 2 years ago
MODERATORS
996
submitted 1 year ago* (last edited 1 year ago) by lwadmin to c/lemmyworld
 

Hello everyone,

Recently we have been dealing with a lot of spam from the kbin.social communities. There is a bug in kbin where moderation tasks are not federated to other instances. That means even if a moderator over at kbin removes a post, it will still be visible on Lemmy instances and it's up to the instance admins to clean it up.

There have been talks about this in the Lemmy admin channels with some instances considering defederating from kbin.social - and others who have already made that step.

We don't want to defederate, because we know this would impact the kbin community greatly - but we have to do something. That's why we have currently removed most of the kbin communities from Lemmy World, making them unavailable to our users. But the kbin users can still view and interact with our communities and users.

This means that those spam-accounts will stil be able to post in our communities too, but at least it makes the task of moderation already a little bit lighter on our team. But it was either this or defederation. The moderation tools on kbin are in an even worse state then Lemmy's.

We will keep monitoring the situation and will keep you up to date should anything change.

We hope you understand and support our decision.

The Lemmy World team

you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 175 points 1 year ago* (last edited 1 year ago) (18 children)

Hi - mod of a small kbin.social mag here - @13thFloor - and a lemmy.world user. Is there anything we can do on our end to help mitigate the problem, or make it easier to flag spam that makes its way to Lemmy? I'd be more than willing to include a note to the lemmy.world admins if a spam post is deleted off of a mag I mod here- just need to know who to contact.

Side notes - Ernest (kbin.social admin) just responded on the spam issue here. The community has been actively working over here to flag and remove spam accounts (I've personally flagged close to 100). According to the most recent news from @ernest earlier last week, we've got a software update incoming, and a magazine cleanup in the works that will hopefully make an impact.

[โ€“] thisisawayoflife 25 points 1 year ago* (last edited 1 year ago) (9 children)

How is it so easy to create spam accounts with Kbin? What kind of account validation is implemented? Email? Enforced 2FA? Just a curious dev who hasn't started their own lemmy or Kbin instance yet.

[โ€“] [email protected] 29 points 1 year ago (4 children)

There's just email verification at the moment. 2FA is on the roadmap, but I'm not sure if it will be in the next release. Here's the kbin codeberg site for more detail.

[โ€“] HowdWeGetHereAnyways 6 points 1 year ago (2 children)

It's a start, but 2fa can't stop spam.

If one can automate account creation including saving totp secrets, you suddenly have 2fa authenticated bots able to send spam.

Maybe you could get around that to some extent by leveraging sms verification during account creation, but how do you set that up to prevent burner numbers? Or smishing?

These are hard problems to address

[โ€“] elscallr 7 points 1 year ago

Not to mention there are a lot of fediverse users who moved here because they didn't want to give away personal information like their email and phone number.

[โ€“] Venat0r 2 points 1 year ago (1 children)

Also a lot of real people might want to sign up without needlessly giving away personal information like thier phone number...

Here's one (possibly dumb?) idea I just had: implement a shadow ban for a period on new accounts so moderators can check what they're posting before they're allowed to post.

[โ€“] iquanyin 1 points 1 year ago

i like this one! seems smart.

load more comments (1 replies)
load more comments (5 replies)
load more comments (13 replies)