似乎国外 fedi 也出了个“殆知阁”,他们上面的帐号发的帖子一部分克隆自现有 fedi 用户,另外一部分似乎是 AI 生成的。
虽然现在这个站似乎已经没了,还是建议各位实例管理员拉黑这个实例。
毕竟域名还在,不知道什么时候会回来。
这个实例:
https://mastodon.arell.ai/
建议使用通配符屏蔽(如果支持):
*.arell.ai
#FediBlock #联邦宇宙避雷针 #什么值得b #殆知阁
其它用户的报告:
https://social.growyourown.services/@homegrown/114879556671836673
https://disabled.social/@Aaidanbird/114882091881354955
https://mastodon.social/@tillybridges/114880389184406800
殆知阁事件:
https://blog.bgme.me/posts/mastodon-and-liberty-a-response-to-daizhige/
fediblock
Big time block needed (and take down for abuse?) of mastodon.arell.ai, which basically has cloned the Fediverse with unauthorized copies of everyone. #Fediblock (3.9K copies of users) (Update: The Fediverse appears to have successfully taken these guys down, woohoo!)
🚨 Scam Alert: "Verify your Fedi account" Phishing Attempt 🚧
Attention everyone on Mastodon! There's a scam making the rounds where malicious actors impersonate moderators or admins. They send private messages or make posts that mimic notifications, claiming that your account needs verification. These messages often include a link for you to "complete the verification process."
⚠️ This is a Scam!
Your server admin will never ask you to click a link to verify your account.
No other admin from any other server will either, even if they appear to be part of the main Mastodon team.
If your account is suspended, you won't receive a message about it. Instead, you'll see a notification upon logging in that your account is temporarily suspended.
How to Identify the Scam:
Fake admin accounts often use names containing "moderator" or "admin," but this doesn't mean they are legitimate.
Legitimate admins or instance owners usually have a badge or marking on their profile indicating their role.
What to Do:
If you receive a message or post urging you to click a link to verify your account, report it immediately.
If you have any doubts about your account status, contact your server admin or moderation team directly.
To verify the authenticity of an admin or instance owner, visit the "About" page of your instance. This page typically lists contact information for the real team administering your instance.
Always be cautious when interacting with accounts claiming to be from Mastodon or your instance's admin team.
Important Reminder:
Mastodon does not perform age verification. If you receive a message or post claiming to be from Mastodon or your instance's admin team, always verify its authenticity before taking any action.
Reporting the Scam:
If you encounter this scam, report it to your instance's admin team and use relevant tags, such as #FediBlock, to help raise awareness.
Personal Note:
I'm not a cybersecurity expert, but I find this new scam in the Fediverse quite interesting. If you feel like sharing your experiences with me, I would appreciate it! I'm looking to collect cases and get a broader view of this phishing attack. Maybe I'll even try to write a report about it. Feel free to tag me in any relevant posts.
Let's stay vigilant and help each other stay safe online!
#Mastodon #Fediverse #ScamAlert #Phishing #CyberSecurity #OnlineSafety #FediBlock #StaySafe #TechCommunity #SocialMedia #ScamAwareness #SecurityTips #ReportScams #VerifyBeforeYouTrust
#Fediblock recommendation, there's a rogue server cloning real accounts so it can impersonate them. There is no legitimate reason for such behaviour, admins should suspend it ASAP:
mastodon.arell.ai
Admins might want to suspend the main domain:
arell.ai
This would be good in case the owner tries the same stunt on a different subdomain. Blocking the main domain also blocks all of its subdomains.
(via @thomas)
Beware of @mastodon.arell.ai as someone found a copy of my account there and the instance apparently has been known for impersonating accounts