Post by @jackemled@furry.engineer

Kevin Beaumont
@GossiTheDog @cyberplace.social

Running a Mastodon server is becoming increasingly problematic due to GenAI.

There’s multiple different things happening, including but not limited to:

- very aggressive scraping of user content and block evasion, with the resource costs that come with it

- AI agents aggressively trying to register accounts and evade restrictions

- rising cost of RAM - Mastodon is memory hungry, RAM is really expensive now

It’s odd to experience first hand, it’s like being consumed by.. a void.

Vysogota
@petko @petko.me

@GossiTheDog what blocking is in place that is being successfully evaided?

edit: i already know anubis is useless

Replying to @petko@petko.me
Luna Lactea
@jackemled @furry.engineer

@petko @GossiTheDog Literally everything, because these companies have the money to spend on cat & mouse games & we have none. All moderators can do is pile hacks on top of their networking setups to block protocol abuse & manually sort through registration applications to kick out bots.

7 likes
The origin reports likes but does not publish who liked this post.
Refresh interactions
Vysogota
@petko @petko.me

@jackemled, thank you but I was looking for concrete examples... That are not anubis since I already know it doesn't work.

Replying to @petko@petko.me
Ganondalf
@Walruths @mastodon.social

@petko @jackemled

"Anubis doesn't work" seems a bit of a quick and concrete judgement. I find it or something like it is a good first step and cuts out the low-effort bots at least unless it really is that bypassable by literally everything.

If this is our future, every account should be an instance. Bloat? Sure, but bot farms wouldn't be able to pull it off at scale for every single bot. For us individually? Ez pz.

Replying to @petko@petko.me
Vysogota
@petko @petko.me
a bunch of phone in racks in an industrial room doing scraping

@Walruths

me: *deploys anubis*

the scrapers: *phone go brrr*

Replying to @petko@petko.me
Vysogota
@petko @petko.me

@Walruths at one point I thought that deploying proof of work at scale (i.e. *everyone* deploying it) would be able to offset the economy of scraping. Now I no longer believe that. There is no world where a data center full of stolen/upcycled phones solving proof of work will give up sooner than your users.

Replying to @petko@petko.me
Ganondalf
@Walruths @mastodon.social

@petko

That is awfully dire.

BUT, I'm still leaving it on.

If they're gonna eat me, I'm at least going to stab them until they get to my arm.

Vysogota
@petko @petko.me

@Walruths put @iocaine on. Poison the effing bots. Ban all that try to crawl poisoned links.

Replying to @petko@petko.me
Cosmin
@cosmin @social.linux.pizza

@petko
> a data center full of stolen/upcycled phones solving proof of work

Mind blown.

In my country, some large electronics retailers have recently started mobile phone buy-back campaigns. They evaluate your old phone and give you a voucher with a value based on the device's state and capabilities. They pay more than they used to.

Silly me, I thought it was for the environment.

@Walruths

Replying to @petko@petko.me
Alice Pea (she/her) 🏳️‍⚧️
@alice_pea_3526 @mastodon.social

@petko @Walruths How to #DDoS an self-hosted blog 101

SIM farms in low-income countries with cheap mobile data.

#Clankers #AI #Scrapers #DDoS

Luna Lactea
@jackemled @furry.engineer

@Walruths @petko Anubis & other proof of work systems do work & that is the problem. They harm real users far more than they harm attackers, because the large companies executing these DDoS attacks can afford the power bill, but my phone battery can't last when every other webpage needs me to spend a few percent of the charge to be able to access it.

Making every account its own server is not a solution. The technical barrier to entry to real users is far too high, it's far too expensive, & it defeats the moderation ability that exists now. A large company such as Google or OpenAI can also afford to do this for the purpose of doing more attacks without issue.

econads
@econads @mendeddrum.org

@jackemled
Invitation only? :(

@Walruths @petko

Luna Lactea
@jackemled @furry.engineer

@econads @Walruths @petko That would work as long as none of the attacker's accounts were successfully created before. If even one got in, it would begin generating a million invitations. I'm sure invitation creation can be disabled too though.

Replying to @petko@petko.me
Benjamin Sonntag-King
@benjamin @piaille.fr

@petko @jackemled We recently saw:
- a real chrome browser with a TLS fingerprint of a chrome browser
- able to interpret JavaScript and even webasm
- able to do all what a chromium could do basically.
Solving a invisible doublesha challenge and asking for 1 page.
Then coming from a few other IPs with the same cookie for 1 page per IP address.
If it uses too many different IPs and we block it (which is not a good idea for people on 4G) it come again on a new IP with no cookie (so viewed as a new user)
And it used about a million IP in 48hours...

That sucks...