this post was submitted on 09 May 2025
155 points (98.7% liked)

Fediverse

37494 readers
109 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)

founded 2 years ago
MODERATORS
 

I've been noticing an influx of users with anonomized usernames (ie: fjdasklfpudiosa722104891fdaf20j.srv.us).

As a moderator this concerns me because it immediately triggers a 'this is a bot or nefarious actor' instinct. Is there any reason not to be wary of these accounts?

all 43 comments
sorted by: hot top controversial new old
[–] mEEGal@lemmy.world 51 points 5 months ago

sounds reasonable, because this definitely looks like low-effort bots

[–] death@infosec.pub 40 points 5 months ago* (last edited 5 months ago) (2 children)

I've been using Fedi for a long time and from the very beginning I've been afraid of spam and bots ruining it, at least temporarily. Spam is still a problem with e-mail, and it's been around for 40 years and they've developed very sophisticated anti-spam mitigations for it.

[–] Zero22xx@lemmy.blahaj.zone 15 points 5 months ago (3 children)

The problem is that most of the 'spam' comes from official things like websites that you've signed up to and didn't realise would also include dumb fkn emails periodically. And they don't always do it right away either. I've had emails suddenly start arriving from somewhere that I signed up to like a year before.

Personally, my spam mitigation is to have one email address for signing up to shit with. Then these assholes can email me until they're blue in the face and I don't care because the only time I ever visit that inbox is for verification. And then I have another email address for personal use that never gets used because who uses email for personal use these days?

In conclusion. Email is for signing up to things and collecting trash that I'll never look at.

[–] death@infosec.pub 15 points 5 months ago (2 children)

That's probably just mail that lands in your spam folder without being entirely blocked. According to Microsoft and Google approximately 99% of incoming spam (of the ~160 billion spam emails sent per day) never even reaches their users mailboxes. I assume that's roughly standard across email providers. I am concerned comparably sophisticated filtering may become necessary on the Fediverse eventually.

[–] SorteKanin 5 points 5 months ago

I get the concern but I don't think you need to be as concerned as with email. Email is a lot simpler without a lot of validation. On the fediverse, HTTP Signatures are used to verify requests, so you can't spoof stuff as easily.

That said, spam mitigation will probably still be an issue that continuously needs to be dealt with.

[–] swelter_spark@reddthat.com 2 points 5 months ago

My Google and Microsoft accounts are the only ones I ever get random spam on, tbh. I've never had any amount of unasked for mail with a paid provider or ISP's email.

[–] Flax_vert@feddit.uk 5 points 5 months ago

I, for the life of me, couldn't stop nextdoor from emailing me. I could unsubscribe myself from one category of email and they'll start popping up again. Just had to block it on my end.

[–] schnurrito@discuss.tchncs.de 2 points 5 months ago (1 children)

IMHO messages from things you've signed up to are unlikely to be "spam". I've always understood that word to mainly mean completely unsolicited messages from people you have no previous relationship with at all; though if it's clearly unwanted it might include some of the former too.

[–] spankmonkey@lemmy.world 5 points 5 months ago* (last edited 5 months ago)

A ton of things I have signed up for spam me with trash emails that they don't put in the 'sales' or 'offers' categories I unchecked. Just because I was forced to create an account to buy one thing doesn't mean I have a 'business relatiotionship' that justifies multiple daily reminders of what they have in stock.

[–] Kirk@startrek.website 2 points 5 months ago

If an instance has a lot of spam, admins tend to notice and block it. In the future it's likely admins will have more tools too, but for now the system works pretty well.

[–] Kualdir@feddit.nl 27 points 5 months ago (3 children)

Technically it can be someone who just wants to be anonymous, but honestly they could at least use something readable

[–] AnonomousWolf@lemmy.world 17 points 5 months ago (3 children)

Using a barcode username is nice for being anonymous

Eg.

IlIIIllIIl

It's a combination of lower case L and upper case I

[–] Kualdir@feddit.nl 9 points 5 months ago

Flashbacks to Rainbow Six Siege cheaters 💀

[–] dr_robotBones@reddthat.com 4 points 5 months ago

That's incredible, I'll use this in the future

[–] nokturne213@sopuli.xyz 2 points 5 months ago
[–] joyjoy@lemm.ee 6 points 5 months ago (1 children)

If they want to be anonymous, sure. But they should at minimum change their display name to "Anonymous"

[–] Kualdir@feddit.nl 1 points 5 months ago

Totally agreed

[–] Hamartiogonic@sopuli.xyz 3 points 5 months ago (1 children)

Also, some people will intentionally add numbers at the end of the alias to make it look like all the good names were already taken. Sort of like a joke or a reference to all the bigger social media platforms.

[–] Kualdir@feddit.nl 3 points 5 months ago (1 children)

I don't really understand that one haha

[–] swelter_spark@reddthat.com 1 points 5 months ago

It used to be common.

[–] DarkDarkHouse@lemmy.sdf.org 17 points 5 months ago

No more wary than, say, CriticalBadger or SuccessfulCrab45. Some of the more obvious bots have very normal-looking names.

[–] e0qdk@reddthat.com 14 points 5 months ago (1 children)

I picked an RNG name since my old common username (from reddit, etc) was not available when I started on kbin.social (RIP) and I couldn't think of anything else I wanted to be called. I deliberately kept it short though. Not sure what to make of other RNG names -- esp. long unintelligible ones -- but I've seen at least one account that I think is legit which has a long, bizarre RNG-looking username and a non-English display name, so 🤷️

[–] paequ2@lemmy.today 2 points 5 months ago

Brother! 🍻

[–] user@startrek.website 13 points 5 months ago (1 children)

You're mostly right -- those names sound like overkill. However do note I have been using Bitwarden's Name Generator (random noun + number) and I've evolved the scheme a bit ( it is now always 'user' and I keep adding numbers until the generated username is available ).

[–] Redecco@lemmy.world 11 points 5 months ago (1 children)
[–] businessfish@lemmy.blahaj.zone 8 points 5 months ago

john user himself

[–] hisao@ani.social 10 points 5 months ago

My first guess with this would be: they were read-only, then they wanted to post something or write a reply to someone and at the time considered it to be a one-time thing and created sort of "throwaway account" for that specifically, but then they kept visiting the place and it kind of just stick with them. Yet again, my guess might be completely wrong. But at least this is one of the possible motivations behind such accounts.

[–] x00z@lemmy.world 7 points 5 months ago

Privacy.

You can be suspicious but shouldn't just outright start banning them.

[–] meh@lemmy.blahaj.zone 6 points 5 months ago

some people don't like personalizations. this is the first account in at least 10 yrs i picked a username for. normally it's just the string a password generator spit out. this time, i guess i figured after surving 18 months on world before deleting the account and moving. i could put 5 seconds into picking a name, since i'll likely be on lemmy until it dies. at some point in the next year i may add the word 'no' to my bio but thats an excessive amount of personalization for me.

[–] capybara@lemm.ee 5 points 5 months ago

If I wanted to create bot accounts I would generate believable names

[–] swelter_spark@reddthat.com 5 points 5 months ago (1 children)

I always use randomly-generated user names. I try to avoid strings of random numbers and letters, but coming up with reasonably nice-looking random names is time-consuming, and some people might not care that much.

[–] AA5B@lemmy.world 1 points 5 months ago (3 children)

Have you found a convenient way of generating those? And does it integrate with any password manager you might be using?

I use Apples “Hide my email” with the password manager so I always have a randomly generated email and randomly generated password and they’re managed together. However there’s not really support for a username distinct from but in addition to email, nor a way to generate those randomly

[–] MangoPenguin@lemmy.blahaj.zone 5 points 5 months ago

Bitwarden does it nicely, you can click the random button on the username field when adding a new entry.

[–] statler_waldorf@sopuli.xyz 3 points 5 months ago

Bitwarden includes a username generator with a few different options for types.

[–] swelter_spark@reddthat.com 2 points 5 months ago

I use random websites that don't require Javascript, tbh, and manually paste the name into KeePassXC.

[–] RandomVideos@programming.dev 4 points 5 months ago

There are people that have a name that looks random, but has a meaning

[–] paequ2@lemmy.today 4 points 5 months ago* (last edited 5 months ago)

😆😂🤣 Uuuuhh... Aaaah... I normally generate a random password and use it as my username for most services. Like even my bank.

This is because I've realized the username is mostly useless and is just a handle for my account. It doesn't matter to me if my username is jsmith, meow123, or kekxbek. In fact, it's easier if I don't have to come up with something novel or cool. Either way it goes in my password manager, so it's not like I have to even remember it.

I'm a real boy. I promise. Not a malicious bot.

Although... If I were a malicious bot, that's exactly what I would say! 😲

[–] crawancon@lemm.ee 3 points 5 months ago

maybe we could create a suspicious account review channel and submit them there for folks to do some digg'ing.

not sure about comms with other Admins but it would be nice to harmonize efforts amongst them a bit more/better.

[–] AA5B@lemmy.world 2 points 5 months ago

It’s actually a good idea - I need to figure out how to do that.

For the last several years I’ve used randomly generated email addresses for every account. I can turn off forwarding when they’re inevitably leaked to spammers and there’s one less thing for demographers to aggregate data on me with. That works well when every service insists on a working email address.

But then I get lazy and use a more obvious username so I can remember it. I need to be able to auto-generate those as well