Elektrine lite

← Feed

@thanksstevenkim@social.vivaldi.net

2026-09-25 09:38 UTC

Another update from running my Mastodon server, mustard.blog. After I blocked direct API account registration, the automated signup activity changed tactics almost immediately: a rejected API signup was followed by the normal browser signup flow, including rules acceptance, username lookup, account creation, and email confirmation. That showed me the existing honeypots and timing checks weren’t enough for a client capable of reproducing normal browser behavior. I’ve now moved hCaptcha to before account creation, while keeping web signup and manual approval available. API signup remains blocked, and existing OAuth/rate-limit protections stay in place as additional layers. No evidence of server compromise or unauthorized admin access was found. The main lesson this time: blocking one path doesn’t stop automation if another path is available — defenses have to follow the workflow, not just individual indicators. The little mustard planet survives another round. 🌭🪐 #Mastodon #Fediverse #SelfHosting #SysAdmin #Security #OpenSource

Replies (0)

No replies.