Lately we have been dealing with a few abusive members from Feddit.nl and we were unable to get in touch with the instance administrator.

Part of the problem is the instance’s open registrations which do not require you to enter an e-mail address during signup. This in combination with an inactive admin is a recipe for abuse.

We hope this is only temporary but we have to do this to protect our users.

Edit: we use fediseer, have a look https://gui.fediseer.com/instances/detail/lemmy.world

Edit 2: We got in touch with the Feddit.nl admin. Email requirements were added to the sign-up process and we’re setting up a communication channel. So that means we are federating with Feddit.nl again!

      • PriorProject@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        10 months ago

        With the refrigeration, which do you consider the canonical community to follow now? You mod both, right? Are you going to keep the bit posting to both?

        • freamon@endlesstalk.org
          link
          fedilink
          English
          arrow-up
          4
          ·
          10 months ago

          Love what re-federation got auto-corrected to.

          The canonical community is the one at feddit.nl, since it has all the history and I don’t really think it’s .nl’s fault that someone used it to attack .world.

          The bot’s due to make one more post at endlesstalk (to announce that the problem is over) and then I’ll think about what to do with the community (probably delete it)

    • jarfil@lemmy.world
      link
      fedilink
      arrow-up
      28
      ·
      10 months ago

      You can still go to the instance and read it, subscribe to it from a non-defederated instance, or even create an account there directly.

      • Draconic NEO@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        10 months ago

        That assumes that it’s not abandoned like rammy.site was, if you don’t know rammy.site was a general purpose Lemmy instance a while back which was abandoned by its admin and then some right-wing grifters decided to hijack it and use it to spread hatred. Similarly to this situation they also got defederated, though much more widely then in this case.

        The biggest problem is that because they were abandoned eventually the server crashed or the VPS got discontinued or something and now it’s gone. If you go to the URL now you get SSL errors and for a while it was showing up as 410 gone. So with Feddit.nl even though you can go and view the contents on it right now if it’s abandoned it will likely meet a very similar fate in the near future. Meaning that the community is on it are doomed and will either die or have to migrate elsewhere.

  • nero@lemmy.world
    link
    fedilink
    arrow-up
    132
    arrow-down
    1
    ·
    10 months ago

    Sucks to see my home countries instance isn’t being moderated properly

  • Bleeping Lobster@lemmy.world
    link
    fedilink
    English
    arrow-up
    66
    arrow-down
    2
    ·
    10 months ago

    Maybe it’s just a coincidence, but it seems like everytime .world defeds from a problematic instance, it’s almost immediately smashed with DDOS attacks.

    The beauty of lemmy as I see it though IS the federation, if .world is down no worries, I’ll just browse on sopuli.xyz or any of the multitude of other instances :) we are like a sexy hydra of positivity.

      • Quacksalber@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        ·
        10 months ago

        Nope, in order to not overload lemmy servers, the lemmy software does not federate pre-(re)federation content. That is one reason why I find it a bit ridiculous to wield the biggest stick you have, defederation, so freely.

        • antik@lemmy.world@feddit.nl
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          9 months ago

          I think in the case of an instance being spammed with csa material we are allowed to use all the sticks at our disposal - and in this case it was actually the only stick we had. And once we got in touch with TedVDB we refederated.

          He’s now also in the chat room where most Lemmy instance admins hang out. I’d say that’s a positive for everyone in the end.

  • freamon@lemmy.world
    link
    fedilink
    English
    arrow-up
    52
    arrow-down
    1
    ·
    edit-2
    10 months ago

    They’ve already replied with the reasons, but - for future reference - if you want to see specifics of things like this, a censure is often posted to https://fediseer.com. .world’s censure of .nl is here

  • Zombiepirate@lemmy.world
    link
    fedilink
    English
    arrow-up
    45
    arrow-down
    3
    ·
    edit-2
    10 months ago

    Thanks for all you do!

    Somewhat related: any word on re-enabling image uploads? I understand completely why you had to do it, just wondering if there’s a roadmap?

  • Haru@lemmy.world
    link
    fedilink
    English
    arrow-up
    42
    arrow-down
    2
    ·
    edit-2
    10 months ago

    Well that’s disappointing, but glad the lemmy.world team are making sure they are on top of it and keeping transparency with all that you do. Thank you.

  • stevedidWHAT@lemmy.world
    link
    fedilink
    arrow-up
    47
    arrow-down
    10
    ·
    edit-2
    10 months ago

    Hiya! Question, is there a way we can see this sort of information ourselves as well? Namely, reports and admin activity logs.

    What’s to stop an instance, then a collection of instances and so on from claiming others aren’t being actively moderated in order to censor?

    Not making any accusations obviously, just a thought I had while reading.

  • BitingChaos@lemmy.world
    link
    fedilink
    English
    arrow-up
    63
    arrow-down
    26
    ·
    10 months ago

    Part of the problem is the instance’s open registrations which do not require you to enter an e-mail address during signup.

    How is this even a thing? Why would the Lemmy software even allow operation like this?

    • tpyo@lemmy.world
      link
      fedilink
      arrow-up
      124
      arrow-down
      3
      ·
      10 months ago

      Back when I signed up for reddit, you didn’t need an email and they warned you if you lost your password you’d be locked out of your account until you regained it and they would not offer support to reset it

      I liked that. I don’t want to have to submit my email for everything just to interact

          • Zoolander@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            10 months ago

            It annoys the shit out of me how many developers don’t allow for sub-addressing. Google has supported it on Gmail since inception and it follows the damn spec! Don’t use your crappy form validator if it doesn’t allow valid emails!

          • IdleSheep@lemmy.blahaj.zone
            link
            fedilink
            arrow-up
            2
            ·
            edit-2
            10 months ago

            If you have catch all enabled for your custom domain there’s no overhead.

            Signing up for reddit? Just put reddit@example.com and that address will be automatically created and start receiving reddit’s emails. Don’t have to fiddle with anything.

          • jcg@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            10 months ago

            I do this as well but there’s been quite a few times when the email input wouldn’t accept it and it’s usually on the sites you really wanna have it on.

            • Duamerthrax@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              10 months ago

              I was dumb founded to find out that vrchat doesn’t except ProtonMail. I had to use my mothballed gmail account.

            • Dopeness@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              10 months ago

              Got a domain? Setup ‘catch all’ and you are all set. If not consider a cheap one. It’s unlimited disposable email addresses for few buck a year.

          • cyberpunk007@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            10 months ago

            Interesting. How does this work? I’ve never used it. I either add manual aliases or distribution groups. It’s a pain in the ass but it works and is safer than using the same email for everything.

            One thing I like is also how you can tell who sold your email to spammers 🤣

        • Dopeness@lemmy.world
          link
          fedilink
          arrow-up
          5
          ·
          10 months ago

          Catch all? I love it so damn much since I got it. Bitwarden added it on the fly and now I got disposable email addresses for anything I can think of, it’s so, so perfect!

          • palitu@aussie.zone
            link
            fedilink
            arrow-up
            2
            ·
            10 months ago

            hmmm… i may need to buy bitwarden… i currently self-host, but that sounds very tempting!

            • Dopeness@lemmy.world
              link
              fedilink
              arrow-up
              3
              ·
              9 months ago

              No need. Even selfhost is free. The catch all feature is also included in the free plan. Bitwarden free is amazingly packed with pretty much all the features you need. Tip: Make a ‘non-profit’ organisation and invite your family to it. You can share passwords for streaming service etc using this.

      • ttmrichter@lemmy.world
        link
        fedilink
        arrow-up
        3
        arrow-down
        1
        ·
        10 months ago

        And then there’s those of us who don’t use email for all practical purposes. I haven’t sent an email in anger for a donkey’s age; the only reason I have an email at all is because of all the people in North America who think email is the wave of the future.

    • SpliceVW@lemmy.world
      link
      fedilink
      English
      arrow-up
      59
      arrow-down
      3
      ·
      10 months ago

      Let’s be real - an email address doesn’t really stop much of anything. Anyone can really easily spin up new email addresses freely.

      • Corkyskog@sh.itjust.works
        link
        fedilink
        arrow-up
        17
        ·
        10 months ago

        Yeah I still don’t have an email associated with my reddit account. Which shocks people… although I haven’t logged on in months, so maybe it’s now required for legacy accounts

        • MakeItCount@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          10 months ago

          it’s not required globally but some subs require it to be able to post

          So far only /r/formula1 does for me

        • tpyo@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          10 months ago

          Hah, I replied higher up in the comments that when I signed up for reddit, I also didn’t need an email address and I think that particular one never required setting one

          Newer accounts definitely did and I used different emails for those accounts

      • CoderKat@lemm.ee
        link
        fedilink
        English
        arrow-up
        17
        arrow-down
        1
        ·
        10 months ago

        Sadly yeah. We absolutely should use email signup because it filters our the absolute lowest effort bots, but it does nothing against higher quality bots or humans. Not only can you easily spin up new emails on the fly, but many emails allow ways to make the email appear unique (eg, Gmail ignores dots and anything after the + sign), there’s plenty of temporary email services with a variety of domains, and if you own a domain, you can trivially create unlimited emails until they catch on and ban the entire domain.

        Inactive admins are also an issue, but if malicious users are determined enough, it doesn’t matter that much how active an admin is. An active admin can mostly help by making IP banning an option (imperfect, but will work on many humans) and can temporarily turn on approvals to make it easier to weed out low hanging fruit. Nothing will work against someone determined enough, but could at least reduce how many instances they can turn to.

        • itsdavetho@lemmy.world
          link
          fedilink
          arrow-up
          3
          arrow-down
          2
          ·
          10 months ago

          Personally I don’t think anything will stop anyone determined to bring this type of harm to the community, there’s an endless list of workarounds. These communities need a larger network of moderators across timezones

          • sab@lemmy.world
            link
            fedilink
            arrow-up
            7
            ·
            10 months ago

            Nope, but it will stop the less determined ones.

            With no email verification, you can pretty much create dozens of fake accounts per second - as fast as the API can handle.

    • cley_faye@lemmy.world
      link
      fedilink
      arrow-up
      27
      ·
      10 months ago

      Because anyone running it can decide to do it this way. That’s how code works; you can edit it. Even if the option wasn’t there, if any instance admin wants that to happen it’s easy to do.

  • eee@lemm.ee
    link
    fedilink
    arrow-up
    30
    arrow-down
    1
    ·
    10 months ago

    It seems like the user who posted the csam has been banned, does that mean the admin/mod is active again?

  • GONADS125@lemmy.world
    link
    fedilink
    arrow-up
    28
    ·
    10 months ago

    With the nature of the recent attacks I think it makes perfect sense to take strong precautions necessary to protect the community. Can always refederate when/if the admin gets ahold of the situation.

  • Squander@lemmy.world
    link
    fedilink
    arrow-up
    55
    arrow-down
    45
    ·
    10 months ago

    I feel your frustration with “unable to get in touch with the instance administrator”. I’m waiting for a response from @ruud and @MichelleG from 9 days ago regarding abusive members.