Lemmy.world is temporarily disabling open signups and moving to an application-required signup process, due to ongoing issues with malicious bot accounts.
We know this is a major step to take, but we believe that it’s the right one for both us and our community right now.
We’re working on a better long-term technical solution to these bots, but that will take time to create, test, and verify that it doesn’t cause any problems with federation and how our users use our site, and we’d rather make sure we get it right than have a site that’s broken.
We’re making this change on 28 Aug 2023, and don’t have a specific timeline for how long registrations will require an application, but we will post an update once our new anti-abuse measures are in place and working.
Take care, LW Team
You gotta do, what you gotta do!
Thanks as always for the hard work and transparency.
Thank you for the kindness!
No place is safe from this, unfortunately. I moderated 2 big brazilian subreddits, and then decided to volunteer to help a smaller one. I had a day (and to be honest, an entire week) absolutely ruined when somebody did indeed set a bot to post large amounts of CSAM to the subreddit. Luckily I was online to quickly purge it all, and Reddit’s admins did remove the accounts pretty much instantly, but I feel for every Lemmy admin that even caught a glimpse of this material and now have to purge their computers and honestly, their minds, from that. Sorry to hear it happened.
Hope it restricts the attack surface, why do people have to be such knobs
Not wanting to be too conspiratorial, but it isn’t necessarily people simply doing this out of the badness of their hearts. The fediverse is a disruptive platform and there are many parties with deep pockets that might happily funnel a little bit of cash to certain consultancies in certain countries to stop things and add friction to this platform before it really takes off. Nothing like a little bit of corporate sabotage!
That sounds exactly like the badness in people’s hearts though.
This is a very silly conspiracy theory. Big corps don’t give a shit about Lemmy, but there are plenty of script kiddies who want to hack easy targets. Contrary to your belief, there are plenty of dumb idiots with plenty of badness in their hearts.
Big corps are more sociopathic than you realise. There are so many underhanded games going on at that level it will make your head spin.
Big businesses indirectly and sometimes directly fund APT groups. They will buy things that give them anonymous access to competitor trade secrets, or fund attack campaigns against competitors. This sounds like the kind of attack campaign a competitor might launch as part of a one-two combo. This is the first part, the second part is to get editorials out there regarding how lemmy.world is full of CSAM.
Nah. The risk greatly outweighs the reward. Even if this hits the news, I doubt it’d affect numbers on here that much, especially since it’s not that big. It’s not even big enough to cause issues for “competitors” (and I use the term lightly). The fediverse is simply not really ready to compete with established actors. So the “benefit” is quite small. The risk if they’re caught includes executives getting jail time and likely irreversible harm to their brand.
Nah. The risk greatly outweighs the reward.
Does it? Standard dark web precautions are more than enough to throw any investigation into a dead end, especially for a one-off transaction with the buyer having little to no other activity.
The fediverse is simply not really ready to compete with established actors.
Yet. The Fediverse isn’t ready to compete yet. Business people aren’t looking purely at the present, they’ve got a keen eye on the foreseeable future too. If there is a growing momentum towards the fediverse, that can spell trouble for Reddit in 5 years time. The entire point of such an attack is to derail momentum on the platforms. By the time they are ready to compete, it’s much too late for this kind of attack to have any reasonable effect.
The more intelligent solution is what Meta is doing with Threads. Not something like this. There’d be a lot more money blackmailing the company than to mess with CSAM.
Big corps are a lot sneakier than something so blunt.
There’d be a lot more money blackmailing the company than to mess with CSAM.
There isn’t a company to blackmail. You can’t treat the Fediverse as a competing company because it isn’t one. You have to treat it more like a movement, like Occupy Wall Street
How do you derail a movement? You make sure the participants are slandered to the point that your accusations are the main things people on the outside remember of it. Mainstream Media did this with Occupy successfully.
However this doesn’t work if your opponent is too big, too established or too well funded. Microsoft tried to do this with the Open Source Movement, but the latter was too well established and funded for it to work.
Big corps are a lot sneakier than something so blunt.
That’s the thing, they’re not being blunt at all. Literally anybody can pay for this kind of attack to happen and not even the service provider needs to know who the buyer is.
The only thing that is needed now are media hitpieces about how federated services spread CSAM and you’ve got damage that could make the YouTube adpocalypse look small.
No way would a company risk being caught being responsible for CP. That would cause a massive backlash in the US socially, and the legal troubles would be huge. And the stock market would also very painfully punish them.
Do you really think there aren’t ways for a company to avoid having their names put against such operations? A simple anonymous darknet transaction is enough to get this done without anyone’s name being put on it or CSAM touching corporate machines.
No one cares about Lemmy. Grow up.
Which is why you’re signed in on lemmy.world? Because no one cares about Lemmy?
Lemmy is nowhere near big enough to cause any of the competitors any consternation.
Edit: to be more clear, the fediverse as a whole isn’t big enough. It’s like believing XMPP is going to cause Apple to worry about iMessage.
Obviously their comment was hyperbole, and the literal interpretation is based on the context of the conversation. Do a bit of critical thinking.
This is the internet, Steeve. We don’t do critical thinking here.
The alt right instance has been fucking with world since they were defederated…
This is something right up their alley, so the simplest solution is they’re doing it.
Come on people, Lemmy’s user base is what, a few hundred thousand? A million tops? Which “parties with deep pockets” is this disrupting? The Lemmy userbase is a rounding error on the number of users of other popular social medias.
“Don’t want to be too conspiratorial, but let me continue to drop a ridiculous conspiracy with no evidence”
And big corp wants to smother it before it’s bigger. It perfectly makes sense. It’s so much more difficult to kill a service/movement when it’s already widely adopted and popular. Identifying small, new players in the field and disrupting those takes very few resources for them, a rounding error, if you will.
The fediverse has the potential to be a threat to some big corps out there, and Lemmy is just one speck in a sea of a lot of specks. Together those specks are growing the fediverse, and the only way to disrupt it is to get rid of those specks.
You’re delusional if you think the Fediverse, a totally open protocol that “competitors” can (and plan to) join instead of having to “defeat”, poses a threat big enough to corporations with hundreds of millions or even billions of users to warrant the spamming of child porn.
IIRC there was a post a few weeks ago that had the total number of active accounts somewhere around 60,000. Yeah, we’re definitely not big enough to attract that kind of directed attack
I like conspiracy theories as much as the next person. But let’s be real for a moment … this is shitty people doing shitty things. In part because Lemmy is a vulnerable and maybe relatively easy target by being indie software with indie instance management and relatively young. They might have a general purpose, such as being alt-right and defederated. But at it’s core, I think it’s gotta be just the “pleasure” they get out of breaking someone else’s shit … these people exist, we know they exist.
deleted by creator
Eh. It’s a new platform with new instances and a lot of potential attack vectors. With new users it’s becoming a valid target for them.
Nothing like a little bit of corporate sabotage!
The software developers who created Lemmy openly criticize systems of government and economics. These are nation-state battlegrounds too. The barrier to entrance is very low, as Lemmy doesn’t even do routine tracking of account creation, rate-limiting alone isn’t really defensive. 15 years ago sites like Reddit had major vote manipulation detection logic behind the scenes. This is pretty much unleashed playground for a lot of known tactics.
Could also be political sabotage by people trying to pass the evil Kids Online Safety Act by amplifying the problem. I actually saw a TV ad for that bill recently.
https://arstechnica.com/tech-policy/2023/08/the-kids-online-safety-act-isnt-all-right-critics-say/
With the American election next year and all the chaos on sXitter, no unlikely.
Good hope the child porn posting stops with that.
I’m so glad I somehow have completely avoided that so far. I’ve heard about, sure but that’s it
I have not seen any of that and I sort by All.
With nsfw on? I do as well, but I usually have nsfw off
It wasn’t marked NSFW…
Oh yeah, that’d be a problem…
Not long after joining Lemmy, I was on the less fortunate side of things and ran into a troll post. I haven’t seen any of that horrid stuff on Lemmy since then, I assume the admins and mods have been dealing with it first hand… ☹️ hope they are OK, it isn’t good for anyone mentally.
Same, and I’m on all the time.
Oh Christ, really? That’s just sickening. I often sort by new, sounds like I’ve been very lucky to miss it entirely…
Yeah i had the unpleasant encounter several times by now…
I’m guessing they’re not even flagging that shit as NSFW? I’ve been using liftoff and have the NSFW stuff hidden. I haven’t run into of it yet but that’s fucked up, hopefully it gets under control with this.
Maybe mods of each section can turn on manual approvals of submissions?
Manually approving submissions would be even more work. And shits being posted everywhere.
And no, the ones i had a unpleasant encounter with weren’t flaired nsfw.
Isn’t there a tool (possible free) by Google I think that detects abusive material like this?
Eh… I don’t think we should give up our privacy because one or two bastards are doing that shit…
deleted by creator
Looks like even this place couldn’t keep it up. Unfortunate. Thanks admins for the transparency though.
Good call. Thank you for doing what you need to do to support the site and protect the users as necessary. And as always, the honesty and transparency is appreciated.
deleted by creator
I think it’s the right call honestly. We’ve grown so quick that it must be hard to manage by now.
Hope it helps with the recent abuse.
If you could give me the numbers of new accounts monthly I would look into CloudFlare. If I can afford it I will even pay for it.
https://github.com/bumble-tech/private-detector
Do you guys think this could help? I remembered reading bumble open sourced their image detection system.
Thanks for all the work you do! It isn’t unappreciated.
I guess I’m out of the loop, perhaps because I mostly browse communities I subscribed to, but…
What happened? Lots of spammy bots signing up and spamming the site? I guess I didn’t notice where I was looking
Also, what does application based sign up mean?
Anyhow, Lemmy.World and Lemmy (in general) are growing nicely, so what’s needed to defend them is cool.
Edit: fixed grammar
Troll / spam accounts posted CSAM in !lemmyshitpost@lemmy.world. That spread with federation and every admin ended up involuntarily hosting such content.
Application based sign up means that if a user wants to subscribe they have to fill out a form and a .world admin gets to review it and approve or reject their sign up. It’s a measure of controlling who gets in and limiting the amount of bots and possibly troll that join an instance.
To make it clear, the form is virtually the same as before with one additional question. It just asks you to state you read the note that is the same as the note in the post above. The application is virtually identical beyond that. But, the biggest difference, is like you said, an admin needs to approve it.
I don’t blame you for taking that decision. But it’s sad that this will deter legitimate users away, some of whom would’ve signed up otherwise.
deleted by creator
Detered != Unable
For me at least, lack of open sign ups immediately makes me not join an instance. It’s why I didn’t join lemmy the first few times I saw it talked about on reddit, when the main instance was lemmy.ml.
It’s simply a delay in activation. The signups are virtually identical with one added question stating you read the note which is the same as the one above in the post.
Is image posting temporarily turned off for lemmy.world users too?
Since last night, I’ve been unable to post (tested in memes@lemmy.world, memes@lemmy.ml, and lemmyshitpost@lemmy.world). Switched to an alt account on a different instance and had no issue.
Im getting this same error roughly a day later from your post. On both mobile and desktop.
Yeah, I know they’re busy trying to figure out how to deal with the attacks, so no pressure on them to restore it immediately. I just made an alt account yesterday and will post from there for a bit until this gets sorted.