cross-posted from: https://lemmy.dbzer0.com/post/72685299

I discovered this after upgrading our instance yesterday, which also upgraded all frontends to their latest versions as well. After I did, our Tesseract frontend stopped working and I noticed immediately as it’s been my primary for a while. Initially I thought it was an API version mismatch, but no, it was much worse.

Someone pointed out that the developer of the frontend added an explicit hidden and unmodifiably blacklist which includes any and all instances to the left of Kissinger. There’s a commit which also explains their specious reasoning about our instance specifically, as it seems we’ve been on their shit list for a bit longer than that.

This instance and its admin staff encourages identity politics, groupthink, mob mentality, and extremist solutions to societal problems. Users who advocate violence are not moderated so long as the admins agree with the target. Caution and critical thinking are advised when interacting with this instance or its users.

When you use tesseract to connect to one blacklisted such instance , you just get a message informing you that Tesseract is “incompatible with that instance” which leads one to think of a technical issue, like an API mismatch, rather than the dev being an opinionated coward.

Isn’t it funny how all the software developed by turbolibs, like Piefed and Tesseract, end up with hidden control mechanisms from developers who think they know better than everyone else? That they don’t just think they deserve to tell you what you should think, but they should manipulate you to think it? Isn’t it funny how libs go on about how bad it is to support lemmy due to the ideology of the devs behind it, and yet lemmy has 0 opinions as a software? It does make one think…

Anyway, I forked - it as one does - and disabled the blacklist, but since this is a massively ideologically compromised software, I’ll doubt I’ll keep this frontend up after Lemmy 1.0. I think we’ll bring up mlmym again now that someone’s maintaining it again.

  • Foxfire@pawb.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    15 days ago

    Guess what? The site had hidden js which attempts to effectively DDoS Db0 with its visitors. I edited the link above to be the Lemmy post about it instead, but what a disgrace. Apparently it doesn’t work too well (thankfully), but the malware dev making more malware seems pretty par for the course.

    • Draconic NEO@pawb.socialOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      15 days ago

      That’s even worse. What a piece of shit. Hopefully they actually try him for it as the crime it is, though unfortunately I know from experience that people who commit felonies online often get shunned for it and told it was bad and that they could go to jail but rarely does anything actually come of it.

      • Foxfire@pawb.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        15 days ago

        I also expect exactly zero legal repercussions, but the relevant parties are aware, abuse reports have been filed, and apparently the site is down now? I don’t want to check for obvious reasons, but I think the bare minimum should be him being blacklisted from his hosting provider, and potentially having his info noted to other hosting services, so he’s unable to easily spin up another remote server to do more malicious, and illegal antics.

        • Draconic NEO@pawb.socialOP
          link
          fedilink
          English
          arrow-up
          3
          ·
          14 days ago

          Also it seems like he’s either part of the team at Startrek.website or owns that instance as well because they just defederated dbzer0 using almost the same verbiage AP used in his going away post. Might be worth investigating the Startrek.website domain too if they’re run by the same person.