As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.

  • AbidanYre@lemmy.world
    link
    fedilink
    English
    arrow-up
    54
    ·
    edit-2
    1 day ago

    My favorite part of this was in the “elephant in the room” post.

    One of his faq questions was something about if the list is a perma-ban. His answer was somewhat incoherent but basically if you stop being toxic you can get off it. But nothing about how. So either he’s actively monitoring thousands of accounts that he’s also secretly hiding from everyone else, or we were supposed to, I don’t know petition him with our last 50 comments to prove we had changed and ask nicely to not be on a list we weren’t supposed to know existed in the first place.

    • pcouy@lemmy.pierre-couy.fr
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 day ago

      I did not follow this drama, and I don’t know about this list everyone is mentioning. Is this something that hides specific users posts and comments from the Tesseract UI ?

      • BluescreenOfDeath@lemmy.world
        link
        fedilink
        English
        arrow-up
        16
        ·
        23 hours ago

        Basically, yes.

        Tesseract was downloading at runtime an obfuscated blocklist of users and instances. One that the dev didn’t tell anyone about, and didn’t give an option to disable/modify.

        db0 was trying to update Tesseract and was unaware that the whole dbzer0 instance was blocked in this way. And because the Tesseract dev is a spherical bastard, rather than saying “this is blocked”, it said there was an API mismatch, which sent db0 down a troubleshooting rabbit hole that ended with him blowing the whistle on the whole thing.

        And you can see how mature and wise the developer is for how he responded.

        • JackbyDev@programming.dev
          link
          fedilink
          English
          arrow-up
          1
          ·
          10 hours ago

          Small point of order, there was an option to disable it, but it was extremely hidden and buried in the advanced settings area and called “enabling toxic mode”. Also, this only disabled the runtime policy. There was no way for end users to disable the instance list that was in the source code itself.

            • zarkanian@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              15 hours ago

              If you fork it, the fork doesn’t belong to them. You can do what you want with it.

              Besides, if they don’t want to maintain it, why don’t they stop maintaining it right now? What does Lemmy 1.0 have to do with it?

              • GreenKnight23@lemmy.world
                link
                fedilink
                English
                arrow-up
                3
                ·
                14 hours ago

                just because we found two things he did doesn’t mean there aren’t other surprises.

                for all we know at this point, he’s implemented a backdoor into instances that use it.

                if you’re an instance admin using tesseract and you’re reading this right now, you should probably drop it asap.

      • AbidanYre@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        21 hours ago

        I only learned out about it when someone posted an stl badge of honor to the 3d printing community and during my “what is this even about” investigation found that I was on it.

        But yeah, BSOD summed it up pretty well.