Takeaways
All pulled from the analysis, emphases are mine:
- Many Fediverse instances have open sign-ups without proper limits, enabling this to even happen in the first place.
- Open registrations should NEVER be enabled on instances without proper protections and monitoring.
- It's important to note that this attack doesn't require any novel exploit, just the existence of unmonitored, un-protected instances with open registration. From what we've seen, these are usually smaller instances.
- If you must have open registrations on your instance, use the proper anti-spam and anti-bot mechanisms. We also recommend blocking sign-ups using Tor IP addresses and temporary email domains.