Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Maikel 馃嚜馃嚭 馃嚜馃嚫
Maikel 馃嚜馃嚭 馃嚜馃嚫
@maikel@vmst.io  路  activity timestamp 2 days ago

How many dormant fake accounts might exist in the fediverse or more importantly, how easy is it to fake that "joined on" date on a profile if you have access to the instance database ?

#Mastodon #Scams #askfedi

  • Copy link
  • Flag this post
  • Block
webhat
webhat
@webhat@infosec.exchange replied  路  activity timestamp 2 days ago

@maikel I'm unsure what you're asking. Are you asking whether you can fake the joined on date on server you completely control?

Because that is obviously possible, because you control the server. You could even have the instance send different joined on dates to different instance

  • Copy link
  • Flag this comment
  • Block
Maikel 馃嚜馃嚭 馃嚜馃嚫
Maikel 馃嚜馃嚭 馃嚜馃嚫
@maikel@vmst.io replied  路  activity timestamp 2 days ago

@webhat I did not know that. I thought the protocol somehow prevented that case from happening the same as changing handles fucks up federation somehow.

Thank you for letting me know. Now I know the joined date is another scam vector.

  • Copy link
  • Flag this comment
  • Block
webhat
webhat
@webhat@infosec.exchange replied  路  activity timestamp 2 days ago

@maikel everything that is coming from a federated instance can be manipulated by that instance, not just the join date

It's the same for any website, if you control the server you control the communication to the outside world. The only way to mitigate against things like that is to have some kind of web of trust, and even that is no guarantee

I don't see how the protocol would be able defend from a malicious or compromised instance

Here's the code for Mastodon:
https://github.com/mastodon/mastodon

GitHub

GitHub - mastodon/mastodon: Your self-hosted, globally interconnected microblogging community

Your self-hosted, globally interconnected microblogging community - mastodon/mastodon
  • Copy link
  • Flag this comment
  • Block

BT Free Social

BT Free is a non-profit organization founded by @ozoned@btfree.social . It's goal is for digital privacy rights, advocacy and consulting. This goal will be attained by hosting open platforms to allow others to seamlessly join the Fediverse on moderated instances or by helping others join the Fediverse.

BT Free Social: About 路 Code of conduct 路 Privacy 路
Bonfire social 路 1.0.1 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Code of Conduct