So some spam signups just happened (all username12345678@gmail.com format e-mail) This caused bounced mail to increase, causing Mailgun to block our domain to prevent it getting blacklisted.
So:
- Mail temporarily doesn’t work
- I closed signups for now
- I will ban the spam accounts
- I will check how to prevent (maybe approval required again?)
Stay tuned.
Edit: so apparently there is a captcha option which I now enabled. Let’s see if this prevents spam. Registrations open again.
Edit2 : Hmm Mailgun isn’t that fast in unblocking the domain. Closing signups again because validation mails aren’t sent
Edit 3: I convinced Mailgun to lift the block. Signups open again.
Is there a growth target for the community? I see that Lemmy.world is almost equal in size to lemmy.ml. Will this instance remain open indefinitely?
No target. I will keep this open as long as it’s possible. It’s up to others to start as many Lemmy instances as possible, and the Lemmy devs to create a better join-lemmy with a rotating ‘recommended server’ preferring smaller instances. But that’s difficult. Because you also don’t want 1000 users to land on someone’s Raspberry Pi instance without backup which they can just stop if they get bored of it. Same issue goes for Mastodon as well… but that’s being worked on.
Tangential question but it’s been on my mind. Should mods be encouraging images to be posted on outside image hosting services (Imgur or something) to reduce the load on Lemmy.world? I actually don’t know how much images affect the server.
Nah… It’s only 27GB of images right now. I have around 800GB space, and can have disks (cheap HDDs in case of images) added to the server. Also pictrs will support S3 in the newer version. But good that you’re all thinking with me!
I have no technical knowledge or assistance to offer but thanks for what you do
Those usernames are so unimaginative. Who would pick a name like that?
I know, right? That’s the kind of thing an idiot would have on their luggage!
12345 is the code to my luggage
Now, can you tell me where your luggage is?
OK that makes sense, I was trying to sign up and couldn’t figure out why everything was timing out. Sorry if my attempts looked like spam.
edit: it still doesn’t work for me btw
Last time a website I was managing was bombarded with spam signups, I set up a regular expression to check for the incredibly distinctive format the spammers were using… then it reports success but doesn’t actually create the account or send an email. Spam problem over.
Very clever, only problem is it’s not a general solution.
I ran into the issue on my instance as well, but checking the Captcha option in admin settings, stopped the signups for me.
Thanks for the tip- I’m having the same issue. How do I ban those accounts? I can’t even tell who my users are
I did it in the database, so if you can access your database I can assist.
My instance also experienced this. I’m the only active user (I made it a day ago), but the user count is up to 2K now. It stopped after I enabled captchas, but I want to remove these spam accounts so they don’t cause issues elsewhere.
I don’t even have a slight clue as to what I should look for in my database.
Contact me via Matrix if possible @ruud:h-y-p-e-r.space
If you haven’t figured it out yet or got a response yet, hop onto the instance admin group on matrix for Lemmy (details are on the GitHub or join Lemmy page somewhere I believe) and one of the many other folks running instances can probably walk you through it
can’t have anything nice nowadays
How about adding a captcha? I was surprised there was none when I signed up.
Yes the devs should do that. We’re currently discussing the the Lemmy matrix chat.
I’m down as long as its privacy friendly and doesn’t use non-free javascript
And accessible
Captchas are laughably easy to get around but they do work against dumb script kiddies which seems this attack is originating from.
How to add something to the list if it isn’t advertised on the old sub?
Lucky me, I guess, since I use a masked email address that looks fake too (anon addy). I really dislike to give my email address when testing Reddit alternatives.
Just buy a cheap domain to point to anonaddy or simplelogin so you dont need to use one of their domains
Sounds frustrating. Thanks for doing what you do and letting us join your server! Hope the captcha works out.
User on kbin here, just tried to sign up to lemmy.world… looks like everything crashed and burned when tried to sign up there.
It was you all along!
Thanks for staying on top of things! Really appreciate your efforts!
Wanna recruit a helper who promises nothing but benevolent assistance?
The spam battles are heating up!
I love how transparent you are with the management of this instance. Kudos!
This, Refreshing 😀👍