Hey, really need help from an administrator ASAP to deal with a new form of abuse.
Conversation
Replying to
Think it's more of a social engineering thing and they just tricked users into thinking it's the same account name with how they presented it.
Relying on what users tell me is happening so I'm not sure if their clients really screwed this up or people trusted the display name.
1
Replying to
it’s a social engineering attack, but one the clients could make more obvious. we’re working on it.
1
2
Replying to
Yeah, this morning I happened to have one of the messages myself and realized how they are tricking people now that I can look at it myself.
Display name being used to make something that looks like a trusted UI that's part of the client combined with trick to see account diff.
1
1
If multiple people have the same display name, Element seems to disambiguate by showing (account) but it's possible to add that to your display name which is a really strong way of tricking people since it mimics the trusted client UI. Can see how they tricked people with it now.
1
These continued raids on our channel combined with the other attacks on the project are a huge pain.
They've found this new way of doing it where they don't actually need to be in the channel to cause problems.
Strongly suspect certain new accounts of being the same people too.
1
Don't have as much ability to moderate as IRC where we can ban banned on hostmasks, People can bypass that on IRC but it takes more work and it slows them down. Freenode is generally pretty good at making this harder to abuse. Finding it much harder to moderate on Matrix.
1
The same people still appear to be causing problems and trolling people in the channel. Don't really have a good way to deal with it without a way to do temporary IP bans, etc.

