Comments

This profile is from a federated server and may be incomplete. Browse more on the original instance.

jerry, to fedia in Closing registrations in Fedia.io due to spammers
@jerry@fedia.io avatar

There were lots of changes around the same time. I removed fedia.io from the CDN a few days ago though didn't announce it, yet the errors continue.

jerry, to fedia in Closing registrations in Fedia.io due to spammers
@jerry@fedia.io avatar

What works for me on both mastodon and Lemmy is a free text question: why do you want to join?

The user enters whatever they like and it goes into a moderation queue. Both lemmy and mastodon send me an email when a new account is ready to review.

I read the response and choose to whether to approve their account. At the moment, spammers are really bad at answering the “why do you want to join” questions.

jerry, to fedia in Closing registrations in Fedia.io due to spammers
@jerry@fedia.io avatar

Howdy! Mbin (and lemmy) are very different things. It’s sort of like the difference between Twitter and Reddit. You can sort of interact back and forth, but to get the full experience, you have to either be on a lemmy or mbin (or piefed) instance.

jerry, to fedia in Fedia.io instability
@jerry@fedia.io avatar

it's hard to make a blanket statement, because it depends on the details of the application. CSRF attacks are definitely real and common, but using csrf tokens isn't critical in every application. For example, I think we have CORS headers enabled, I don't think we have functionality that allows embedded iframes, but we do allow links - if we have administrative functions that can be triggered solely with GET parameters, then someone could trick an administrator into doing something that caused damage by clicking on a link in a post. The only one that would obviously work that I can see is "logout", which would be annoying, but not world ending, and would work for everyone, not just administrators.

jerry, to fedia in Fedia.io instability
@jerry@fedia.io avatar

ok - I just had it happen again while looking at logs. interestingly, there was NOT a CSRF log when that happened. There were a bunch of other errors, but enough that I could look through all of them and see that they were all related to activitypub issues - signaturevalidator and the like

jerry, to fedia in Fedia.io instability
@jerry@fedia.io avatar

Indeed. I am trying to get it to happen again now that I’ve got the logs filtered down to a manageable level.

jerry, to fedia in Fedia.io instability
@jerry@fedia.io avatar

I do not have 2fa turned on right now.

jerry, to fedia in Fedia.io instability
@jerry@fedia.io avatar

I do not have 2fa active at the moment

jerry, to fedia in Fedia.io instability
@jerry@fedia.io avatar

I have so many errors in prod.log that it's hard to tell for certain, but when I try to filter out those that are associated with failed federation events, that seems to be when I'm left with. I am trying again to see if I can confirm

jerry, to fedia in Fedia.io instability
@jerry@fedia.io avatar

Most interesting: the problem had only been happening on MS Edge on my laptop. I have been using safari on my phone without issue. Just a bit ago, i refreshed the page and now every time I revisit the site, I have to log back in, just like on Edge. It’s like the old session expired and the new ones aren’t sticking. I’ll try FF on my phone.

Note: even in the time I started typing this reply to when I hit the “add comment” button, I got logged out

jerry, to fedia in Fedia.io instability
@jerry@fedia.io avatar

This annoys me about the fediverse - people take a chance on coming here and then repeatedly get left in the dark when their instance is shut down. That's why I was so very happy when you and others helped me get fedia.io back to healthy.

jerry, to fedia in Fedia.io instability
@jerry@fedia.io avatar

I moved fedia.io away from fastly. I have a nagging feeling it has something to do with fastly. Can you let me know if you continue to see this?

jerry, to fedia in Account creation issue
@jerry@fedia.io avatar

If you can, please try again. If you still have problems, shoot me an email to jerry@infosec.exchange and I'll troubleshoot the issue

jerry, to fedia in Fedia.io now behind Fastly CDN
@jerry@fedia.io avatar

thank for pointing that out. Its on my list to fix

jerry, to fedia in Fedia.io now behind Fastly CDN
@jerry@fedia.io avatar

Ahh - thank you!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • meta
  • Macbeth
  • All magazines