Well, I quickly read through that list and I’ll say this: considering the insane amount of stuff that gets silently filtered out, whoever views Lemmy through that thing must think it’s pretty quiet 🙂
And that’s a large part of the issue. The frontend doesn’t actually disclose this blocklist at all. In fact, it actively takes steps to obfuscate things and make it appear as if the blocklist doesn’t exist at all.
For example, attempting to view a blocked instance shows a generic network error, rather than a “this instance is being blocked by your frontend” error. And blocked users aren’t simply flagged and/or collapsed. They’re entirely hidden, as if they don’t exist at all. So someone using this as their primary frontend wouldn’t even know that they’re missing entire posts and/or comment chains, because anything from the blocked users is simply gone.
Additionally, the blocklist is downloaded (in plaintext, over http) when the frontend is booted, so it’s not a file that gets updated with the git version updates. Meaning the dev can silently update it even if users haven’t pulled new versions. Simply rebooting your frontend would be enough to pull an updated blocklist. This gives the dev an extreme amount of censorship power, because they can effectively change users’ configs without any action on the users’ part.
It was only originally discovered because the admin for db0 used the frontend. And notably, db0 is on the block list. They were previously using an old version of the frontend that didn’t include the hidden blocklist yet. They updated their Lemmy stack a little while ago, and suddenly their entire frontend was broken (the entire feed was completely empty) and showing a generic version incompatibility error.
After lots of troubleshooting, the db0 admin eventually discovered that the frontend was downloading a hidden blocklist and automatically blocking the instance that it was running on. Because when they updated their stack, the new version of Tesseract included the secret blocklist. So it downloaded the blocklist when it booted up, found that db0 was on the list, and silently hid every single post because they were all from a blocked instance. This resulted in a completely empty feed.
Considering the amount of effort put into the blocklist by the Tesseract dev to keep it hidden, you would think they would have included an exception if it was running on a blocked instance to help keep it hidden.
Yup, and this is just speculation, but I guess it’s supposed to be an anti-spam thing, but it targets a lot of people/communities/instances that post actually good content
but I guess it’s supposed to be an anti-spam thing
Oh my God, I swear some people will just never get it.
No dude, this isn’t just someone trying to block spam, this is ideologically targeted to silently remove specific viewpoints from people who use the stylesheet without disclosing that they’re doing that.
This obviously has nothing to do with spam. Keep giving people like this the benefit of the doubt, and see where it leads us.
Edit: I just saw your pfp… Were you aware that this blocked the entirety of Blahaj? The de facto trans instance?
Yeah, I’m pretty unabashedly anti-capitalist, so I’m not surprised I ruffled some feathers. I was just pointing out that the idea that this was just a spam filter taken too far doesn’t really hold up.
I don’t think it’s anti-spam. It looks pretty much like a personal blocklist, it blocks a lot of users that have political views that the tess dev doesn’t agree with. It blocks political keywords often used by certain ideologies that I guess the dev doesn’t agree with, for example, no ones blocking “neoliberal” as a keyword because of spam.
This looks entirely like a personal blocklist which is completely fine, but secretly adding it to the frontend is v dubious…
It’s a shame I think the dev is a good person from the convos I’ve had with them, but this crosses a bit of a line…
Well, I quickly read through that list and I’ll say this: considering the insane amount of stuff that gets silently filtered out, whoever views Lemmy through that thing must think it’s pretty quiet 🙂
And that’s a large part of the issue. The frontend doesn’t actually disclose this blocklist at all. In fact, it actively takes steps to obfuscate things and make it appear as if the blocklist doesn’t exist at all.
For example, attempting to view a blocked instance shows a generic network error, rather than a “this instance is being blocked by your frontend” error. And blocked users aren’t simply flagged and/or collapsed. They’re entirely hidden, as if they don’t exist at all. So someone using this as their primary frontend wouldn’t even know that they’re missing entire posts and/or comment chains, because anything from the blocked users is simply gone.
Additionally, the blocklist is downloaded (in plaintext, over http) when the frontend is booted, so it’s not a file that gets updated with the git version updates. Meaning the dev can silently update it even if users haven’t pulled new versions. Simply rebooting your frontend would be enough to pull an updated blocklist. This gives the dev an extreme amount of censorship power, because they can effectively change users’ configs without any action on the users’ part.
It was only originally discovered because the admin for db0 used the frontend. And notably, db0 is on the block list. They were previously using an old version of the frontend that didn’t include the hidden blocklist yet. They updated their Lemmy stack a little while ago, and suddenly their entire frontend was broken (the entire feed was completely empty) and showing a generic version incompatibility error.
After lots of troubleshooting, the db0 admin eventually discovered that the frontend was downloading a hidden blocklist and automatically blocking the instance that it was running on. Because when they updated their stack, the new version of Tesseract included the secret blocklist. So it downloaded the blocklist when it booted up, found that db0 was on the list, and silently hid every single post because they were all from a blocked instance. This resulted in a completely empty feed.
Considering the amount of effort put into the blocklist by the Tesseract dev to keep it hidden, you would think they would have included an exception if it was running on a blocked instance to help keep it hidden.
Don’t give them ideas, it’ll be harder to find the next one.
I guess the lesson here is “compile from the source repo and code review before you install a new frontend”
Oh that’s mental. I didn’t realize it was that bad. Something new to worry about scanning for when using open source!
Yup, and this is just speculation, but I guess it’s supposed to be an anti-spam thing, but it targets a lot of people/communities/instances that post actually good content
It’s not anti spam at this point. No one obfuscates something that much for antispam.
It’s also a weird place for anti-spam, to have it be client side. That should be done on the server, rather than the various clients handling it.
True! Idk, that part is just speculation, hence why I said I guess, not I know. Either way, they did a shitty job that should be shunned.
Oh my God, I swear some people will just never get it.
No dude, this isn’t just someone trying to block spam, this is ideologically targeted to silently remove specific viewpoints from people who use the stylesheet without disclosing that they’re doing that.
This obviously has nothing to do with spam. Keep giving people like this the benefit of the doubt, and see where it leads us.
Edit: I just saw your pfp… Were you aware that this blocked the entirety of Blahaj? The de facto trans instance?
Try justifying that as anti-spam.
Oh, whoa, I did not see that. From what I had seen I could have sworn that it had general political blocking. That’s my bad!
Truth nuke
I’m on the list and I’ve never even posted anything. I do comment a decent amount, though, but I wouldn’t consider any of it to be spam.
Did you ever talk shit about billionaires or crypto? Make any anti-AI posts?
Yeah, I’m pretty unabashedly anti-capitalist, so I’m not surprised I ruffled some feathers. I was just pointing out that the idea that this was just a spam filter taken too far doesn’t really hold up.
I comment exclusively, and I’m on it.
I don’t think it’s anti-spam. It looks pretty much like a personal blocklist, it blocks a lot of users that have political views that the tess dev doesn’t agree with. It blocks political keywords often used by certain ideologies that I guess the dev doesn’t agree with, for example, no ones blocking “neoliberal” as a keyword because of spam.
This looks entirely like a personal blocklist which is completely fine, but secretly adding it to the frontend is v dubious…
It’s a shame I think the dev is a good person from the convos I’ve had with them, but this crosses a bit of a line…