Post by @jackemled@furry.engineer
Running a Mastodon server is becoming increasingly problematic due to GenAI.
There’s multiple different things happening, including but not limited to:
- very aggressive scraping of user content and block evasion, with the resource costs that come with it
- AI agents aggressively trying to register accounts and evade restrictions
- rising cost of RAM - Mastodon is memory hungry, RAM is really expensive now
It’s odd to experience first hand, it’s like being consumed by.. a void.
@GossiTheDog what blocking is in place that is being successfully evaided?
edit: i already know anubis is useless
@petko @GossiTheDog Literally everything, because these companies have the money to spend on cat & mouse games & we have none. All moderators can do is pile hacks on top of their networking setups to block protocol abuse & manually sort through registration applications to kick out bots.
7 likes
@jackemled, thank you but I was looking for concrete examples... That are not anubis since I already know it doesn't work.
"Anubis doesn't work" seems a bit of a quick and concrete judgement. I find it or something like it is a good first step and cuts out the low-effort bots at least unless it really is that bypassable by literally everything.
If this is our future, every account should be an instance. Bloat? Sure, but bot farms wouldn't be able to pull it off at scale for every single bot. For us individually? Ez pz.
@Walruths at one point I thought that deploying proof of work at scale (i.e. *everyone* deploying it) would be able to offset the economy of scraping. Now I no longer believe that. There is no world where a data center full of stolen/upcycled phones solving proof of work will give up sooner than your users.
That is awfully dire.
BUT, I'm still leaving it on.
If they're gonna eat me, I'm at least going to stab them until they get to my arm.
@petko
> a data center full of stolen/upcycled phones solving proof of work
Mind blown.
In my country, some large electronics retailers have recently started mobile phone buy-back campaigns. They evaluate your old phone and give you a voucher with a value based on the device's state and capabilities. They pay more than they used to.
Silly me, I thought it was for the environment.
@Walruths @petko Anubis & other proof of work systems do work & that is the problem. They harm real users far more than they harm attackers, because the large companies executing these DDoS attacks can afford the power bill, but my phone battery can't last when every other webpage needs me to spend a few percent of the charge to be able to access it.
Making every account its own server is not a solution. The technical barrier to entry to real users is far too high, it's far too expensive, & it defeats the moderation ability that exists now. A large company such as Google or OpenAI can also afford to do this for the purpose of doing more attacks without issue.
@petko @jackemled We recently saw:
- a real chrome browser with a TLS fingerprint of a chrome browser
- able to interpret JavaScript and even webasm
- able to do all what a chromium could do basically.
Solving a invisible doublesha challenge and asking for 1 page.
Then coming from a few other IPs with the same cookie for 1 page per IP address.
If it uses too many different IPs and we block it (which is not a good idea for people on 4G) it come again on a new IP with no cookie (so viewed as a new user)
And it used about a million IP in 48hours...
That sucks...