Riddle me this. How can a spammer start their account creation from /auth/confirmation? He does this every week. He never accesses /auth/sign_up. He always first shows up in the logs accessing /auth/confirmation.

I have his ASN blocked by the Cloudflare firewall from accessing /auth/sign_up. I see in the Cloudflare logs that he tried to access /auth/sign_up but got a 403 from Cloudflare. The request is nowhere in my logs. It was truly blocked by the proxy server.

But, then suddenly he's using /auth/confirmation with the same blocked ASN seconds later and creates the account. Today I added the same ASN restriction to /auth/confirmation to try to stop future sign-ups, but this is beside the point.

It's like he tries to go to sign_up, gets a 403, and then uses some alternative means to begin the signup process.

He's not getting in with an invitation code, either.

Can he be using an existing account in some way to get an access token for an API call of some type to begin registration?

How does he do this?

#MastoAdmin #MastoDev @Gargron @ClearlyClaire

All Qtriots in control #QAnon #Conspiracy #photography #dogs #nature #camping #anime #music #BSD #cycling #DOS #fedi22 #fitness #FOSS #GNU #infosec #Lego #linux #MOC #MSDOS #OpenSource #OpSec #OSINT #pinball #privacy #RightToRepair #security #StarTrek #Unix #believeinfilm #fedi22 #photography #filmphotography #35mm #filmisnotdead #Politics #Fediblock #Trump #Caturday #Dutch #English #LGBTQIA #Minecraft #Programming

@Mastodon do our purchases support the development of moderator tools and administrative tooling that we've been asking for for years?

There's a lot to say about the new #Mastodon version but the most impactful change for me so far is the new boost icon. It now visibly changes when pressed, while previously it would barely change colour/thickness, a difference often too subtle to notice on screens with low constrast/brightness.

We released Mastodon 4.3 today, packed with a lot of awesome features: https://blog.joinmastodon.org/2024/10/mastodon-4.3/

I want to thank @Claire, @Gargron, @dave for their hard work on the code, as well as @samhenrigold for the design. Also a lot of thanks to our regular contributors, including @matt and @thisismissem

Now let's focus on 4.4! We have a lot of exiting things to work on, we will do our best to release it before September 2025 😅

We’re growing our product team!

Are you an #iOS Developer who wants to lead our official #Mastodon iOS #App?

This is a remote full-time position and requires an overlap with the CET timezone.

Ideally:

1. You are a senior iOS Developer comfortable with a mature codebase
2. Proficient in #Swift and #Apple Frameworks (UIKit, SwiftUI, Combine)
3. Prior experience with social media networks is a big plus!

For more info/to apply:
https://jobs.ashbyhq.com/mastodon/bc91c481-d30a-4e73-9eb8-ac29f4e905e2