hhmx.de

Cliff

Cliff (@cliffwade@allthingstech.social)

Föderation EN So 18.02.2024 14:07:07

@Gargron and the team really need to do something about sign-ups on Mastodon in general.

There is no reason why after all of this time that Mastodon doesn't have some kind of captcha or something similar for when users sign up.

This process really needs to be refined and made better, as in, way better, because right now it's absolutely awful and is part of the reason why we're getting these waves of spam bots.

An image that says Random Thoughts in a peach/orange looking font.

(Medien: 1)

Ryan Wild

Ryan Wild (@wild1145@mastodonapp.uk)

Föderation EN So 18.02.2024 14:17:02

@CliffWade @Gargron The doc's are missing one of the config flags but docs.joinmastodon.org/admin/co

HCaptcha is something you can enable on Mastodon. You'll need to define both

`HCAPTCHA_SECRET_KEY` and `HCAPTCHA_SITE_KEY` in your .env.production file.

Cliff

Cliff (@cliffwade@allthingstech.social)

Föderation EN So 18.02.2024 14:18:38

@wild1145 I believe this is only for those that are fully self-hosted. I'm not sure someone like @mastohost can change this for us, though it's worth asking.

In the end, this should simply be part of Mastodon by default and admins shouldn't be forced to enable it or anything similar. Should be in the dashboard.

@Gargron

Ryan Wild

Ryan Wild (@wild1145@mastodonapp.uk)

Föderation EN So 18.02.2024 14:21:18

@CliffWade @mastohost @Gargron I can't speak for the 3rd party hosting, but their support should be able to enable it. I agree generally that having more of the settings in the admin dashboard would be great.

The challenge with it being "enabled by default" is you have to sign up for HCaptcha / similar so you'd have to do a step either way. I know there's a lot of work happening to improve the documentation but as you say that doesn't help 3rd party hosting.

Masto.host

Masto.host (@mastohost@mastodon.social)

Föderation EN So 18.02.2024 15:15:28

@wild1145 @CliffWade Yes, hCaptcha is supported on Masto.host. The admin just needs to send their hCaptcha keys and request it to be activated.