Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove outdated instances. #629

Open
trankten opened this issue Apr 3, 2024 · 1 comment
Open

Remove outdated instances. #629

trankten opened this issue Apr 3, 2024 · 1 comment
Assignees

Comments

@trankten
Copy link

trankten commented Apr 3, 2024

I've published this through Mastodon but I think it's worth bringing it here because it raises some considerations that need to be addressed.

Please consider removing servers using outdated software from joinmastodon.org as they might be a security risk for new users and the Mastodon experience will not be the best nor the latest.

Some servers at JoinMastodon.org such as IRSoluciones.social (Public local timeline here: https://irsoluciones.social/public/local) have a public timeline filled of spam bots, see image below:

imagen

JoinMastodon.org encourages new users to join there which is unattended, unmoderated, the software is outdated and might present a bad experience and a security risk for the new users. The server has open registrations and also an outdated version of Mastodon which has known security issues, but new comers who join through JoinMastodon.org don't know this and they just see a "Create account" button, inviting them to join Mastodon there.

imagen

Please consider adding a check in JoinMastodon.org to remove or hide servers whose server software version is below a threshold or has known security bugs, and when possible, keep an eye to remove servers to the Mastodon Server Covenant when they are not getting updated to avoid new users have a bad experience when joining Mastodon using a decentralized server!

The server I'm pointing here is just one of many more that were created back in 2022 when people thought making a Mastodon server would bring them fame and wealth.

Have a great day!

  • Trankten from TKZ.One
@andypiper andypiper self-assigned this Apr 3, 2024
@trankten
Copy link
Author

It's been 2 weeks. Daily SPAM bots there. No answer from their admins. Sadly the instance is still recommended at joinmastodon.org to create new accounts there for new joiners with an outdated and vulnerable server version.

imagen

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants