As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.

  • __hetz@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 hours ago

    There was (is, as a fork) a front-end for Lemmy called “Tesseract.” Some folks liked it because it has improved filtering options, better mod/admin controls, et cetera. At least up until it was discovered that several instances had been hard-coded to be filtered while the front end erroneously reported it as an incompatibility issue. Then it was also discovered that it retrieved an additional blacklist from the developers server (as base64 encoded data, which decoded into a gzip file, which extracted to a json file of the actual blacklist - if you’re curious about that). Aside from some filtering that most would be indifferent to, it seemed the dev was also hand-curating this blacklist to include individual users. People that must’ve “wronged” them or posted something they didn’t like at some point.

    None of this was disclosed in the project’s README.md on GitHub. To my knowledge, as I didn’t use the front-end, it wasn’t disclosed anywhere outside of having to manually review the source code and discover it for yourself. There was supposedly, somewhere in the settings, an option to enable “Toxic Mode.” That was the means of disabling some of the above (maybe the blacklist, not sure about hard-coded instances) but it doesn’t sound like it was very descript about what was happening when toxic mode was disabled.

    Sooooo, tldr:

    • Improved front-end for Lemmy
    • Dev wants Lemmy to be nice for normies
    • Decides they need to hide toxicity from them
    • Decides they’re the supreme arbiter of toxicity
    • Hides toxicity, as they defined it, from users
    • Users discover dev is making decisions for them
    • People don’t like when others make their decisions
    • Dev posts unapologetic crash out

    And we’re now at their last Huzzah: Adding spiteful and malicious code. They were just a coward before that. They might’ve saved some face in acknowledging that they should’ve been forthright in their filtering. Now they’re a coward and a heaping pile of shit whose work can never be trusted again.