cross-posted from: https://lemmy.dbzer0.com/post/72685299

I discovered this after upgrading our instance yesterday, which also upgraded all frontends to their latest versions as well. After I did, our Tesseract frontend stopped working and I noticed immediately as it’s been my primary for a while. Initially I thought it was an API version mismatch, but no, it was much worse.

Someone pointed out that the developer of the frontend added an explicit hidden and unmodifiably blacklist which includes any and all instances to the left of Kissinger. There’s a commit which also explains their specious reasoning about our instance specifically, as it seems we’ve been on their shit list for a bit longer than that.

This instance and its admin staff encourages identity politics, groupthink, mob mentality, and extremist solutions to societal problems. Users who advocate violence are not moderated so long as the admins agree with the target. Caution and critical thinking are advised when interacting with this instance or its users.

When you use tesseract to connect to one blacklisted such instance , you just get a message informing you that Tesseract is “incompatible with that instance” which leads one to think of a technical issue, like an API mismatch, rather than the dev being an opinionated coward.

Isn’t it funny how all the software developed by turbolibs, like Piefed and Tesseract, end up with hidden control mechanisms from developers who think they know better than everyone else? That they don’t just think they deserve to tell you what you should think, but they should manipulate you to think it? Isn’t it funny how libs go on about how bad it is to support lemmy due to the ideology of the devs behind it, and yet lemmy has 0 opinions as a software? It does make one think…

Anyway, I forked - it as one does - and disabled the blacklist, but since this is a massively ideologically compromised software, I’ll doubt I’ll keep this frontend up after Lemmy 1.0. I think we’ll bring up mlmym again now that someone’s maintaining it again.

  • QuentinCallaghan@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    54
    ·
    edit-2
    1 day ago

    A frontend should be a frontend. The decisions of what to blacklist should be up to the frontend’s user. Stupid decision on the developer’s part.

  • Zak@lemmy.world
    link
    fedilink
    English
    arrow-up
    42
    ·
    1 day ago

    Opt-in denylists with pre-populated categories would be a reasonable feature. A frontend author trying to trick users into thinking there’s a technical issue with servers the author doesn’t like is presumptuous and disrespectful of the user.

    People did similar stuff with Mastodon clients when the far-right microblog service Gab migrated its backend to a Mastodon fork and I didn’t like that either.

      • Axolotl@feddit.it
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        Really? I was thinking of switching to piefied (i was already skeptical because it’s made with python) but now? Hell nah, i’il stay on lemmy or use mbin

    • Carl N. Yon@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      22 hours ago

      Every account on PieFed has a Social Credit Score, aka your Reputation. If your account has less than 100 reputation and is newly created, you are not considered “trustworthy” and there are limitations placed on what your account can do.

  • poVoq@slrpnk.net
    link
    fedilink
    English
    arrow-up
    14
    ·
    edit-2
    1 day ago

    As long as Lemmy doesn’t support password-less and revokable logins, no one should be using alternative web frontends hosted by someone other than their trusted server admin. And as this issue clearly shows, when an admin hosts it themselves the dev can’t hide it and it is easy to circumvent.

    • Axolotl@feddit.it
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      the dev can’t hide it and it is easy to circumvent.

      That’s if the Admin check the code of a famous and very used front end

      • poVoq@slrpnk.net
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        Well, in the case the OP referenced, it was impossible to miss, but I grant that the other dynamic blocklist that was found after I made the above comment is more difficult to notice as an admin.

        That said, Tesseract was forked from Photon for very unclear reasons, and that alone was a big red flag from the start that made me personally stay away from it.

  • OpenStars@discuss.online
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    27
    ·
    edit-2
    1 day ago

    When asked about this HARD-CODED feature that was barely announced when it was slipped into the code, the authors’ response was:

    If you dont like it, fork it. Stop bothering us about it, we will never fully remove the slur filter.

    - source

    Oh wait… my bad, that was Nutomic, speaking about Lemmy. Tbf, after a huge outcry, they did later relent.

    I guess software having ideology injected right into it is par for the course these days. It takes an ENORMOUS amount of effort to find any workable solutions otherwise. Compromise is an art, and all the purity testing among leftists works against it (which btw is why conservatism and fascism is winning across the globe right now, at least initially, bc they are willing to set aside their differences in order to achieve a common objective).

    Fwiw I would suggest removing this particular feature from a front-end UI alternative and leave such matters to the back-end. Being able to personally block instances is superb, and offering a visual guide to which ones that someone might want to block would also be great, but hard-coding a dedicated list is ineffective at best, especially when the instance admins simply remove it from the code as they run the software without it.

    • Cowbee [he/they]@lemmy.ml
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      1
      ·
      22 hours ago

      You’re equating Lemmy’s now disabled slur-filter to a hard-coded censor list of queer and leftist instances and users. Are you aware of how that comes across?

    • FleetwoodLinux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      24 hours ago

      Ah yes, a slur filter to prevent people from saying particularly messed up stuff, definitely the same as “I’ll block all of my enemies for everyone”

      • OpenStars@discuss.online
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        10 hours ago

        I happen to disagree - they are not the same thing at all, especially given the time differential. It’s a good thing I never said that they were.

        There are similarities though. See if you can spot them. Hint: their both having been HARD-CODED is one of them…

        • FleetwoodLinux@lemmy.zip
          link
          fedilink
          English
          arrow-up
          4
          ·
          3 hours ago

          But OpenStars! You’re commenting using the HARD-CODED frontend that talks to the HARD-CODED backend!!!

          How disingenuous can you be?? People are clearly upset about the combination of it being a personal blocklist/vendetta/whatever and it being forced on all users, not solely the fact that omg it’s HARD-CODED. While some people may have disagreed with the slur filter it didn’t ultimately prevent interaction, enabled or not; unlike this.

          • OpenStars@discuss.online
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            45 minutes ago

            “it being forced on all users” and it being “HARD-CODED” are one and the same thing, that’s what hard-coding means.

            Hard-coding is the least transparent, least friendly, least documented, and least simple-to-understand form of putting something into computer program code. If instead there had been a variable like if(yes_filter_toxic_mode) then (implement these policies) then people would not be upset anywhere remotely close to the same degree, as when that feature is unable to be turned off (readily) due to its having been hard-coded.

            Edit: the accuracy of the OP has now been called into question - apparently this issue is NOT hard-coded after all (reportedly, though I have not confirmed this directly myself). People can still be upset that a “toxicity” filter exists, and how it was implemented, but the fact that it is not shadow-filtering without the express consent of the instance admin makes this a much different discussion than if that filter was forced (via hard-coding) upon people unawares. Consent makes all the difference in the world!!! (The jury is still out whether this rose to the level of “informed consent”, but at least that is a documentation issue, not like the dev acting with nefarious intentions as people have been claiming.)

            The facts truly do matter here, and it seems that unless someone is willing to do a deep dive into the code, everything said about this issue is pure speculation. Which so far I’ve only seen one person willing to do, which yielded this (from link I mentioned above):

            from src/lib/policies/system.ts:

            export async function updateSystemFilterPolicy() {  
                if (SBDisabled && get(userSettings).enableToxicMode) {  
                    SYSTEM_POLICY.set(BLANK_SYSTEM_FILTER_POLICY)  
                    return  
                }  
               // auto-update of blocklist continues below  
            
            • FleetwoodLinux@lemmy.zip
              link
              fedilink
              English
              arrow-up
              1
              ·
              39 minutes ago

              “it being forced on all users” and it being “HARD-CODED” are one and the same thing, that’s what hard-coding means.

              That’s what I was saying after I was being a little hyperbolic, I used a definition and your exaggerated capitalization of hard-coded interchangeably