this post was submitted on 28 Aug 2023
1092 points (97.5% liked)

Lemmy.World Announcements

29048 readers
5 users here now

This Community is intended for posts about the Lemmy.world server by the admins.

Follow us for server news 🐘

Outages πŸ”₯

https://status.lemmy.world/

For support with issues at Lemmy.world, go to the Lemmy.world Support community.

Support e-mail

Any support requests are best sent to info@lemmy.world e-mail.

Report contact

Donations πŸ’—

If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.

If you can, please use / switch to Ko-Fi, it has the lowest fees for us

Ko-Fi (Donate)

Bunq (Donate)

Open Collective backers and sponsors

Patreon

Join the team

founded 1 year ago
MODERATORS
 

Lemmy.world is temporarily disabling open signups and moving to an application-required signup process, due to ongoing issues with malicious bot accounts.

We know this is a major step to take, but we believe that it’s the right one for both us and our community right now.

We’re working on a better long-term technical solution to these bots, but that will take time to create, test, and verify that it doesn’t cause any problems with federation and how our users use our site, and we’d rather make sure we get it right than have a site that’s broken.

We’re making this change on 28 Aug 2023, and don’t have a specific timeline for how long registrations will require an application, but we will post an update once our new anti-abuse measures are in place and working.

Take care, LW Team

top 50 comments
sorted by: hot top controversial new old
[–] devious@lemmy.world 193 points 1 year ago (1 children)

You gotta do, what you gotta do!

Thanks as always for the hard work and transparency.

[–] lwadmin@lemmy.world 79 points 1 year ago

Thank you for the kindness!

[–] kadu@lemmy.world 93 points 1 year ago* (last edited 1 year ago)

No place is safe from this, unfortunately. I moderated 2 big brazilian subreddits, and then decided to volunteer to help a smaller one. I had a day (and to be honest, an entire week) absolutely ruined when somebody did indeed set a bot to post large amounts of CSAM to the subreddit. Luckily I was online to quickly purge it all, and Reddit's admins did remove the accounts pretty much instantly, but I feel for every Lemmy admin that even caught a glimpse of this material and now have to purge their computers and honestly, their minds, from that. Sorry to hear it happened.

[–] input@lemmy.world 91 points 1 year ago (1 children)

Hope it restricts the attack surface, why do people have to be such knobs

[–] pretzelz@lemmy.world 82 points 1 year ago* (last edited 1 year ago) (10 children)

Not wanting to be too conspiratorial, but it isn't necessarily people simply doing this out of the badness of their hearts. The fediverse is a disruptive platform and there are many parties with deep pockets that might happily funnel a little bit of cash to certain consultancies in certain countries to stop things and add friction to this platform before it really takes off. Nothing like a little bit of corporate sabotage!

[–] Pregnenolone@lemmy.world 38 points 1 year ago

That sounds exactly like the badness in people’s hearts though.

[–] Aux@lemmy.world 34 points 1 year ago (1 children)

This is a very silly conspiracy theory. Big corps don't give a shit about Lemmy, but there are plenty of script kiddies who want to hack easy targets. Contrary to your belief, there are plenty of dumb idiots with plenty of badness in their hearts.

[–] 520@kbin.social 8 points 1 year ago* (last edited 1 year ago) (8 children)

Big corps are more sociopathic than you realise. There are so many underhanded games going on at that level it will make your head spin.

Big businesses indirectly and sometimes directly fund APT groups. They will buy things that give them anonymous access to competitor trade secrets, or fund attack campaigns against competitors. This sounds like the kind of attack campaign a competitor might launch as part of a one-two combo. This is the first part, the second part is to get editorials out there regarding how lemmy.world is full of CSAM.

[–] pjhenry1216@kbin.social 19 points 1 year ago (5 children)

Nah. The risk greatly outweighs the reward. Even if this hits the news, I doubt it'd affect numbers on here that much, especially since it's not that big. It's not even big enough to cause issues for "competitors" (and I use the term lightly). The fediverse is simply not really ready to compete with established actors. So the "benefit" is quite small. The risk if they're caught includes executives getting jail time and likely irreversible harm to their brand.

load more comments (5 replies)
load more comments (7 replies)
[–] givesomefucks@lemmy.world 23 points 1 year ago

The alt right instance has been fucking with world since they were defederated...

This is something right up their alley, so the simplest solution is they're doing it.

[–] Steeve@lemmy.ca 21 points 1 year ago (2 children)

Come on people, Lemmy's user base is what, a few hundred thousand? A million tops? Which "parties with deep pockets" is this disrupting? The Lemmy userbase is a rounding error on the number of users of other popular social medias.

"Don't want to be too conspiratorial, but let me continue to drop a ridiculous conspiracy with no evidence"

[–] Grabbels@lemmy.world 8 points 1 year ago* (last edited 1 year ago) (1 children)

And big corp wants to smother it before it’s bigger. It perfectly makes sense. It’s so much more difficult to kill a service/movement when it’s already widely adopted and popular. Identifying small, new players in the field and disrupting those takes very few resources for them, a rounding error, if you will.

The fediverse has the potential to be a threat to some big corps out there, and Lemmy is just one speck in a sea of a lot of specks. Together those specks are growing the fediverse, and the only way to disrupt it is to get rid of those specks.

load more comments (1 replies)
load more comments (1 replies)
load more comments (6 replies)
[–] CookieJarObserver@sh.itjust.works 53 points 1 year ago (2 children)

Good hope the child porn posting stops with that.

[–] NPC@lemmy.world 55 points 1 year ago (3 children)

I'm so glad I somehow have completely avoided that so far. I've heard about, sure but that's it

[–] hemmes@lemmy.world 20 points 1 year ago (3 children)

I have not seen any of that and I sort by All.

load more comments (3 replies)
[–] lemann@lemmy.one 15 points 1 year ago

Not long after joining Lemmy, I was on the less fortunate side of things and ran into a troll post. I haven't seen any of that horrid stuff on Lemmy since then, I assume the admins and mods have been dealing with it first hand... ☹️ hope they are OK, it isn't good for anyone mentally.

load more comments (1 replies)
[–] Axisential@lemmy.nz 36 points 1 year ago (1 children)

Oh Christ, really? That's just sickening. I often sort by new, sounds like I've been very lucky to miss it entirely...

[–] CookieJarObserver@sh.itjust.works 12 points 1 year ago (6 children)

Yeah i had the unpleasant encounter several times by now...

load more comments (6 replies)
[–] Astrealix@lemmy.world 51 points 1 year ago

Looks like even this place couldn't keep it up. Unfortunate. Thanks admins for the transparency though.

[–] DelvianSeek@lemmy.world 48 points 1 year ago

Good call. Thank you for doing what you need to do to support the site and protect the users as necessary. And as always, the honesty and transparency is appreciated.

I think it's the right call honestly. We've grown so quick that it must be hard to manage by now.

[–] GlitzyArmrest@lemmy.world 40 points 1 year ago

Hope it helps with the recent abuse.

[–] scarabic@lemmy.world 35 points 1 year ago

If you could give me the numbers of new accounts monthly I would look into CloudFlare. If I can afford it I will even pay for it.

[–] Dark_Arc@social.packetloss.gg 30 points 1 year ago* (last edited 1 year ago)

https://github.com/bumble-tech/private-detector

Do you guys think this could help? I remembered reading bumble open sourced their image detection system.

[–] 007v2@lemmy.world 29 points 1 year ago

Thanks for all the work you do! It isn’t unappreciated.

[–] ConstipatedWatson@lemmy.world 28 points 1 year ago* (last edited 1 year ago) (1 children)

I guess I'm out of the loop, perhaps because I mostly browse communities I subscribed to, but...

What happened? Lots of spammy bots signing up and spamming the site? I guess I didn't notice where I was looking

Also, what does application based sign up mean?

Anyhow, Lemmy.World and Lemmy (in general) are growing nicely, so what's needed to defend them is cool.

Edit: fixed grammar

[–] Nerd02@lemmy.basedcount.com 41 points 1 year ago* (last edited 1 year ago) (1 children)

Troll / spam accounts posted CSAM in !lemmyshitpost@lemmy.world. That spread with federation and every admin ended up involuntarily hosting such content.

Application based sign up means that if a user wants to subscribe they have to fill out a form and a .world admin gets to review it and approve or reject their sign up. It's a measure of controlling who gets in and limiting the amount of bots and possibly troll that join an instance.

[–] pjhenry1216@kbin.social 19 points 1 year ago

To make it clear, the form is virtually the same as before with one additional question. It just asks you to state you read the note that is the same as the note in the post above. The application is virtually identical beyond that. But, the biggest difference, is like you said, an admin needs to approve it.

[–] pm_boobs_send_nudes@lemmy.world 26 points 1 year ago (1 children)

I don't blame you for taking that decision. But it's sad that this will deter legitimate users away, some of whom would've signed up otherwise.

[–] TropicalDingdong@lemmy.world 18 points 1 year ago (1 children)
load more comments (1 replies)
[–] The_Picard_Maneuver@lemmy.world 18 points 1 year ago (2 children)

Is image posting temporarily turned off for lemmy.world users too?

Since last night, I've been unable to post (tested in memes@lemmy.world, memes@lemmy.ml, and lemmyshitpost@lemmy.world). Switched to an alt account on a different instance and had no issue.

load more comments (2 replies)
[–] Candelestine@lemmy.world 14 points 1 year ago

Glad to hear. Obviously this is less than ideal, but working towards solutions is what's important.

[–] teruma@lemmy.world 13 points 1 year ago (1 children)

Will this make it easier to reopen federation with instances that were concerned about abuse of our open sign up policy? (or was the issue with beehaw resolved while I wasn't looking?)

[–] KairuByte@lemmy.dbzer0.com 16 points 1 year ago

If it's temporary, likely not. The concern from most of the instances is that open subs mean literally anyone and anything can join, including bots which create account after account, just moving on when the original is banned. "We are closing open signups for now" is non committal, I'm betting the only way things get refederated is if World commits to this change for the long term.

[–] amenotef@lemmy.world 12 points 1 year ago* (last edited 1 year ago) (1 children)

Beep Beep. Thank you for the update.

load more comments (1 replies)
[–] NekoKamiGuru@ttrpg.network 10 points 1 year ago

As long as users from allied instances can still post it is all good.

[–] nantsuu@kbin.social 10 points 1 year ago (2 children)

Does this mean Beehaw will refederate?

[–] gk99@lemmy.world 23 points 1 year ago

Considering this is a temporary measure, I imagine not. Lemmy.world has been under constant attacks as the #1 Lemmy instance and it's not going to stop just because bots can't get in automatically anymore.

load more comments (1 replies)
load more comments
view more: next β€Ί