Salta al contenuto principale


โš ๏ธ Scam alert: if anyone ever asks you to "temporarily change" the email address on your Mastodon account, DO NOT DO THIS.

There is currently a scammer posing as a server admin telling people to temporarily change their Mastodon account's email to an address supplied by the scammer. This is a scam, don't do it.

Real admins will NEVER ask you to do this.

You can see examples of this scam in the thread at ohai.social/@redsad/1157080301โ€ฆ

(Thanks @markwyner for the warning about this! ๐Ÿ™ )

#FediTips

Questa voce รจ stata modificata (1 giorno fa)
in reply to Fedi.Tips ๐ŸŽ„

"Just temporarily set your passcode to 1 1 1 1 to reenact Meet the Spy..."
in reply to Fedi.Tips ๐ŸŽ„

> Real admins will NEVER ask you to do this.

yeah, *real* admins can change your email directly, without asking you :DDD
(usually we don't)

@markwyner

in reply to โ—

@fembot

Wellโ€ฆsort of. For example, Iโ€™m a moderator, but not an admin. I can see the email address of an account on our server, but I canโ€™t edit it. However, a moderator who is also an admin could.

We also canโ€™t see emails for accounts on other servers, even as an admin.

@mo @FediTips

in reply to Mark Wyner Wonโ€™t Comply

@fembot @mo
Offtopic:
That's something people should be more aware in general. Any service that isn't (properly!) End-to-End Encrypted or can't be, like Social Media or Cloud services (if you want all the fancy Office, Gallery etc. features to work), can't prevent server admins from doing whatnot with any user account.
I'm admin of my families' cloud server. If I wanted to I could disable 2FA, change email, password and keys of any user account and take full control.
in reply to Mike. ๐Ÿฉผ๐Ÿ‡จ๐Ÿ‡ฆ

@MikeImBack

Spam is complicated. Once a person with nefarious intentions has access to a single account from someone, they can use info from that to take myriad other actions.

For example, they can use it to gain access to other accounts that person owns. They can also use the hacked account to impersonate the person, phishing with people the victim knows.

@FediTips

in reply to Mark Wyner Wonโ€™t Comply

@MikeImBack But wouldn't the scammer need to know the account's password for this to work? (Or am I missing something?)
in reply to Mark Wyner Wonโ€™t Comply

email I can see, but anyone on mastodon that has multiple accounts is not like to fall for phishing scams you'd think...they're just going after the wrong people here
in reply to Fedi.Tips ๐ŸŽ„

Can non-admins even see the email?

The reason ask is because I use unique emails for different thingsโ€ฆ and I expect only the admin could see the email I used for mastodon.

in reply to Phillip Upton

Admins/mods can indeed see account email addresses. And IPs. We use those tools to help keep things safe. I believe this is true for most every system where you have an account.

Itโ€™s possible thereโ€™s a setting that restricts email addresses to only admins, with no mod access. But Iโ€™m not sure about that. I just assume all mods have access. But mods are sort of admins in many ways.

@FediTips

Questa voce รจ stata modificata (21 ore fa)
in reply to Fedi.Tips ๐ŸŽ„

I'd like to think that @Mastodon users are more intelligent than to fall for that.... ๐Ÿ˜‚
in reply to kaffando

@kaffando

Wellโ€ฆyouโ€™d be surprised how many people get confused about this kind of thing. Itโ€™s easy to assume our knowledge/experience is universal, but itโ€™s not. There are a lot of non-tech-savvy folks on Mastodon.

@FediTips @Mastodon

in reply to Mark Wyner Wonโ€™t Comply

@kaffando @Mastodon

But, but, ... thanks to this e-mail switch campaign, there are now fewer non-tech-savvy accounts on Mastodon.

in reply to kaffando

@kaffando @Kazinator @Mastodon Don't say that, scams win eventually simply by being so prevalent. Just browse r/Scams for a while and you'll see posts from IT experts who, contritely, describe how they fucked up and got hacked by a scammer.

Even worse is what happens through a compromised account. If someone would manage to get into my account an LLM trained on my public posts might extort money from many friendly people faster than I could reach our two admins.

in reply to kaffando

@kaffando @Mastodon

I doubt it is a lack of intelligence that is the reason why people fall for scams; some people have a very trusting nature, or are tired/ill or distracted, stressed out and for a moment let their guard down.

I sincerely hope you are never caught off guard like so many intelligent folk.

in reply to Fedi.Tips ๐ŸŽ„

Re last: If anyone asks you to do that regarding your alovertheplace.ca account, talk to me. I will nuke them and their instance from orbit.
in reply to Fedi.Tips ๐ŸŽ„

Something very similar was attempted with me through Steam. That was two or three years ago. I think the perpetrator got what was coming to him, because I reported the incident to all three mediums/platforms he tried to exploit to do it.
in reply to Fedi.Tips ๐ŸŽ„

Also, don't feel bad if you fall victim to a scam. There's no shame in it. We're all vulnerable to one type of scam or another, and the biggest protection is accepting that and staying vigilant.
in reply to thermonuclear small claims

@fullfathomfive

Absolutely. I do see some shaming and disbelief that folks are susceptible. That bothers me. It happens. Thank you for offering this reassurance to people.

@FediTips

in reply to Fedi.Tips ๐ŸŽ„

p.s. To add a bit of context, the scammer may message you to claim they reported you by accident. They then try to convince you to get in touch with a different account that pretends to be an admin who can "fix" the situation. All of the things they tell you are lies.

The scammer is actually running both accounts and just wants to take over your account by tricking you into changing your email address to their email address. They would then use your account to post other scams.

Questa voce รจ stata modificata (18 ore fa)

reshared this

in reply to Fedi.Tips ๐ŸŽ„

I've seen a similar scam go around on discord. I'd imagine it'd be easy to fall for this sort of thing if you aren't tech inclined or don't know about this stuff. I hope all of these jerks get exactly what's coming to them and like someone else said in this thread, let's not shame people if they do end up falling for scams.
in reply to Kaliah

Yeah, never a good idea to shame anyone as:
1) They are victims, it's just wrong to shame victims
2) All of us are vulnerable, we should all be keeping our guard up
3) Shaming discourages victims from warning others, so the shaming is just helping the scammers
Questa voce รจ stata modificata (17 ore fa)
in reply to Fedi.Tips ๐ŸŽ„

@Kaliah
Hereโ€™s a good post from @pluralistic himself about how even if this sort of thing is your world, it still only takes a moment of distraction.

So yeah. It can happen to anyone. Blaming the victim doesnโ€™t help, however โ€œobviousโ€ it seems to someone else with distance and hindsight.

pluralistic.net/2024/02/05/cybโ€ฆ

in reply to Fedi.Tips ๐ŸŽ„

That is such an obviously bad idea that I wouldn't do it regardless of whether the person asking was a real admin or not.
in reply to Fedi.Tips ๐ŸŽ„

It is the kind of scam where someone asks you to empty your bank account into theirs in order to keep your money safe. It seems like people still fall for that.
@markwyner
in reply to Fedi.Tips ๐ŸŽ„

๐Ÿ‘†๐Ÿผ

Ping @admin .

Une comm en ce sens dans la langue de Moliรจre pourrait รชtre une bonne chose, non ?
@markwyner

โ‡ง