this post was submitted on 22 Jun 2023
11 points (100.0% liked)

Waveform

31 readers
1 users here now

A place to talk about how we organise ourselves.

founded 1 year ago
MODERATORS
 

Sounds pretty suspicious to me.

top 24 comments
sorted by: hot top controversial new old
[–] [email protected] 8 points 1 year ago (1 children)

I just joined yesterday because I saw a post that I can’t find. But it reminded me to ditch Reddit and find some Lemmy instances. I’m glad I found this one and was able to sign up. Just my 2 cents.

[–] [email protected] 3 points 1 year ago

Well I’m happy you chose to join us 🤗

[–] [email protected] 4 points 1 year ago (1 children)

I was able to delete most of the fake users, but the user count on the homepage does not update 🤷 I can't find that number saved in the database anywhere.

[–] [email protected] 2 points 1 year ago (1 children)

Nodinfo.json maybe? Thats what the fedidb site pulls the numbers it seems.

[–] [email protected] 3 points 1 year ago (1 children)

Yeah but that's not a file that just exists. Turns out the aggregates were saved to the database so I updated the user count there manually. Should be okay now.

[–] [email protected] 1 points 1 year ago
[–] [email protected] 1 points 1 year ago (1 children)

Yeah you're right. That doesn't sound right. Will take a look.

[–] [email protected] 1 points 1 year ago (1 children)
[–] [email protected] 3 points 1 year ago (1 children)

Thanks for letting me know, I have blocked the bot in our firewall for now and will delete the fake account shortly

[–] [email protected] 1 points 1 year ago (1 children)

Cool,

Stumbled upon this accidentally.

[–] [email protected] 1 points 1 year ago (1 children)

Yeah, idk what it is. It seems like a weak attack 🤷🏼‍♂️ one account every few seconds. Nothing that would topple any server except a raspberry pi.

I can see it's an amateurishly written script, making it easy to pick out in the firewall. Oh well

[–] [email protected] 1 points 1 year ago (1 children)

Sounds manageable.

I had some kind of cloudflare error message today but maybe unrelated.

[–] [email protected] 2 points 1 year ago (3 children)

Yeah that's unrelated. I moved the server to a new ip address to isolate it from my personal projects. It took a while for these changes to propagate.

[–] [email protected] 1 points 1 year ago (1 children)

Good to hear, saw the cloudflare error most of the day today and was worried because several small instances were being hit. Would it make sense to enable captcha and email verification to the signup process so you don't get hit by more bots?

Seems like some actors would like to slowly cultivate bot accounts on smaller instances that fly under the radard of bigger ones

[–] [email protected] 1 points 1 year ago

We’ve got some headroom on this instance. I’m currently using about 7% of the available resources.

Though tuning lemmy isn’t easy. But I’m working on it. (I want federation to be faster because posting content takes a while now).

[–] [email protected] 1 points 1 year ago (1 children)

Let me know if you ever need help with server admin stuff. I'm not an expert, but did web dev for 15 years and still comfortable enough on the old Linux CLI.

[–] [email protected] 2 points 1 year ago (1 children)

So far I’m good. But I’ll keep you on my Mind should this situation change.

[–] [email protected] 2 points 1 year ago (1 children)

Cool. Also if you need funds towards hosting costs, I can manage a small monthly contribution.

I noticed the main Irish mastodon instance uses this - looks very interesting (perhaps longer term)

https://opencollective.com/

[–] [email protected] 2 points 1 year ago

I appreciate the thought but hosting this really doesn't take enough time for me to take any money for it. I'm just happy you're all here.

[–] [email protected] 1 points 1 year ago

Ah I see, thought it might be maintenance related.

[–] [email protected] 1 points 1 year ago (1 children)

Lemmy explorer ( https://lemmyverse.net/communities?query=synthesizer ) does not show this instance. Is it related to this issue with fake user count? Or Waveform just hidden from explorer to prevent bot invasion?

[–] [email protected] 1 points 1 year ago (1 children)

Good question, I wasn't aware of the explorer but in the logs of the instance I can see that the did query the instance from time to time. I will get in touch with them to see why this instance isn't on there.

[–] [email protected] 2 points 1 year ago (1 children)
[–] [email protected] 2 points 1 year ago

Strange, I think they may have just needed some time to catch up with the vast amount of new instances.