The attacker seems to be the admin of those two instances. Both instances have their registrations closed.
Edit: It is now open for both of them, or was already. I checked the Fediseer page for both instances and it still says that their registrations are closed.
Though it is suspicious that no captcha, email confirmation or manual approval is required for both of these instances. The admin of lemmy.doesnotexist.club seems to be inactive since their account creation yet this instance is still running. If the admin is the attacker, it could also be that they are the one behind the recent nicole spam.
https://gui.fediseer.com/instances/detail/chinese.lol
https://gui.fediseer.com/instances/detail/lemmy.doesnotexist.club
cross-posted from: https://hackertalks.com/post/8713785
The instances being used are
- lemmy.doesnotexist.club
- chinese.lol
Here is an example of the coordinated downvoting https://hackertalks.com/post/8692093
Of course its a controversial user who got someone angry enough to automated downvoting @[email protected]
But you can see every post they make gets 53ish downvotes from these two instances, plus some organic ones after a few hours.
Current downvoting Accounts
bot-list
[email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]
A individual user airing their personal biases and manipulating lemmy isn’t good for the community, regardless of how you feel about their target. This is a really bad thing ™
Can your detection method be automated and federated?
I’m asking because this is probably the thin end of the wedge and is likely to increase exponentially, especially since anyone can set up an instance and do whatever they like with it.
Wdym. Do you mean how I found out that the attacker was the admin? Yeah sure, you definitely can automate that.
I know one of these instances.
Fuck you, Nicole!
What? She lied to us? 😱
The Liar Who Spammed Me
How could it be!? I could have sworn Discord was end to end encrypted, federated and open source!
/s
How could it be!? I could have sworn Discord was end to end encrypted, federated and open source!
/s
What? Your favorite spammer betrayed you? I’m soooo sowwy :3
Stumblechat Room: HELL
What app are you using?
Sync, at least to Lemmy 1.0. Then, probably Raccoon.
Why switching?
Lemmy 1.0 will mess up with every single client, as long as they won’t update. Sync seems abandoned, so it will simply stop working.
The dev hasn’t updated the app in a while. I think they were actually planning to last month then 1.0 API changes were announced and I never heard back :/
Don’t you besmirch my fediwife’s good name!
Welp, too late ¯\(ツ)/¯
deleted by creator
Make sure to click all of those links
I tried, the Discord link never work. So I’m kind of mad…
You… actually clicked the links? Brother do not do that.
Yeah, deanonymization and shit… Seeing how Nicole became a massive meme and no one gives two shits about that (fediwife 🙄), this appears to be harmless.
Warned about this 11 days ago. https://lemmy.world/post/27449126
This is still a weakness of the current federation model imo
deleted by creator
Which person? OP? The guy you are replying to? Or the spam voter?
Seems relatively painless to chop those two instances off - chinese.lol has less than 200 users, and I can’t even find instance info for doesnotexist.club (coincidence? i think NOT).
I do personally wonder how difficult it is to spin up new instances though. How much effort would it be for them to create a new one and do it again?
I’m actually most concerned with the IP leaking of the fediverse chick posts - hopefully some progress has been made with the IP leaking in auto-loaded external media through DM’s
Some instances enable the image proxy, which should prevent this.
I checked the images and so far every image I’ve encountered linked to the users’s lemmy instance’s pictrs instance, none were hosted through a custom trackable image host.
fairly low effort but annoying like one click with yunohost
The attacker seems to be the admin of those two instances. Both instances have their registrations closed.
The alternative theory would be that these instances had open registrations, but rightly closed registration down after the admins noticed the bots. chinese.lol is on 0.18.4 with an admin with a 2 year old account, lemmy.doesnotexist.club has an admin with a 1 year account, and it was also that instance that the ‘nicole’ person has used before. This downvote attack would need to be a long time in the planning for what you’re suggesting to be true.
Upon inspecting the actual websites, the registrations seem to be actually open for both instances with no email confirmation, captcha or manual approval as one user pointed out. I checked the Fediseer page for these instances. What is the update delay for Fediseer?
Should be 12 hours, unless they explicitly prevent us from accessing their nodeinfo. Which now that I think about it, I should probably notify on.
What is the update delay for Fediseer?
I don’t know. It’s not something I’m familiar with - it might just default to saying ‘closed’ if it doesn’t have the data.
It’s interesting that the obvious bot accounts on those instances were set up in mid-March last year, so I’m guessing that these are somebody’s army that they’ve used before, but overplayed their hand when they turned it on the DonaldJMusk person. The admins can reasonably be blamed for setting up instances with open registrations and no protections and then forgetting about them, but I’d be wary of blaming them for being behind the attack directly. The ‘nicole’ person is unlikely to have used their own instance - it’s probably just someone with the same MO as whoever owns the bots, finding and exploiting vulnerable instances.
it might just default to saying ‘closed’ if it doesn’t have the data.
Nope. Fediseer displays unknown fields as
N/A
.The admins can reasonably be blamed for setting up instances with open registrations and no protections and then forgetting about them
No, I don’t think they forgot. Would you forget about something you regularly pay for?
People forget about subscriptions all the time when they are cheap enough. The admin might even have some kind of grouped payment for multiple domains/sites and doesn’t bother cleaning them out to shut them down.
We need public voting or this will only get worse. It’s currently way too easy to manipulate everyone’s feed.
Edit: It is now open for both of them, or was already. I checked the Fediseer page for both instances and it still says that their registrations are closed.
Fediseer doesn’t check constantly btw.
Thank you for this.
I know I’m viewed as controversial, but I legit want Lemmy to grow so I post a lot of content.
But it’s always community-specific and community-appropriate. The conservative news articles that people despise me for, actually only get posted to a few conservative communities. People are free to check my post/comment history to verify.
If people block those communities or even just block me, then they never have to see my conservative stuff. Not sure why they don’t just do that and ignore me.
So the downvote brigading/manipulation was def out of line and goes against the spirit of Lemmy. It’s something that’s more in line with Reddit than Lemmy.
You guys are rockstars for bringing this up. I know I’m not liked, but Lemmy is open to diverse opinions.
YOU guys are the ones who make Lemmy awesome.
Being able to disable downvoting is one of the best features Lemmy has and I wish more instances would do it.
Voting here doesn’t influence your feed and downvoting largely serves to spread negativity. Turning it off has a negligible impact on usability and an undeniable advantage when people decide their feelings matter more than someone else’s, like whatever this is.
We’ve de-federated from both the instances being used for manipulative voting.
Voting here doesn’t influence your feed
It does when you use sorting algorithms that depend on it.
Not with downvotes disabled 😉
I disagree. Downvoting is essential for Lemmy. I often disagree with something and it’s right to have a democratic vote on topics.
Also helps identify trolls and bad actors at a glance if you don’t already have them tagged as such.
Also helps identify trolls and bad actors at a glance if you don’t already have them tagged as such.
Unless there’s been a bunch of downvote manipulation going on, as in the case of OP’s example (and which I’m the target of).
Oh, don’t play the victim. Everyone knows who you really are.
Not playing the victim. I’m merely stating that vote manipulation is bad, regardless who is on the receiving end. (I didn’t start this thread, I just happen to be an example used in it.)
Organic downvoting me is fine–I get plenty of those. Setting up bots/instances to manipulate downvotes aimed at me isn’t fine though, because it hurts Lemmy as a whole.
They won’t just stop at me, they can start using it against other users as well; even you. Not cool.
Which is the topic of the thread.
That’s fine, but removing downvoting doesn’t prevent the discussion. It curbs drive-by negativity which is a good thing IMO.
Obviously everyone is free to disagree with things. It should be more than absentmindedly hitting a down arrow though. Others obviously feel differently. Thankfully both exist on Lemmy.
You shouldn’t downvote just because you disagree. You should vote based on whether it’s productive content.
How is downvoting essential? It doesn’t do shit.
I want to see it per-community. We use voting for actually decision making in my instance, so we can’t disable it instance-wide.
That would be a useful feature. Maybe something to roll out alongside private communities and things coming in the future.
I fully disagree, in your scenario people wouldn’t realize how fucktastically bad your idea is
Look at what removing downvotes did to youtube, you seriously want that here?
I’ve seen this several times on Reddit, lemmy, etc.: people see something suspicious (valid), jump to one of the less likely conclusions, and then make the pieces fit that support that theory. It’s not malicious, I think some of you just get tunnel vision when a potential (and exciting) conspiracy emerges
I think you are right that there is something that maybe needs to be done about these two instances, but vote manipulation coordination? Nothing here remotely points to that.
The bots are from those two instances as you can see in the screenshot. Furthermore, lemmy.doesnotexist.club has had dozens of bots since at least 2023 (2 years after domain creation. found via the web archive). Since at least 2023, the admin hasn’t been doing anything, or even interacting with anyone. That account seems pretty much dead. But they keep hosting the instance for some reason. It is also a possibility that someone else indeed is using these two instances because they are “abandoned”, but it is highly likely that it is the admin. It is very suspicious that the registrations have been open unguarded against bots since at least 2023. These two instances have been invaded with bots long ago, so defederation is still the right thing to do.
I also don’t want to jump to conclusions, but I think the chances are pretty high that it indeed is the admin. It might lead us to whoever is behind the recent nicole spam.
I guess I wasn’t clear here. I am not saying these bots and issues aren’t coming from these instances or that all these things you are documenting aren’t happening. They clearly are.
But: “coordinated vote manipulation between the admins of these two specific instances“ was the original claim here, right? You are definitely seeing something that is bad happening, but the conclusion you are coming to is conspiratorial and I don’t see evidence to support it.
Unfortunately when Admins don’t take care of their instances this kind of stuff happens. We saw it with Kbin.social (basically all of kbin). It was spam central before it completely went dark.
Well yeah, there is no concrete evidence that it is the admin (or the admins). But the hints I found seem to be pointing that they are the one behind this. Of course there is a possibility that it is someone else, but it baffles me why anyone would leave the registrations open for 2 years, keep the instance running, but never interact with the fediverse through it themselves. And this isn’t exactly like kbin.social, the admin eventually did respond and close down the instance (not to mention, the admin was still communicating with the people). This instance and its bots have been going on for over 2 years, with not even a single sign of activity from the admin(s).
Nevertheless, defederation is the right thing to do right now. Unless concrete evidence is found, we could put this aside.
FWIW:
- Around then, captchas were turned off by default for a short period of time (very stupidly, IMO), if I remember correctly, and a lot of bots were registered on a good number of instances. It was also when a lot of new instances were sprouting up because Lemmy was just gaining momentum.
- I have personally let certain things I host go on for years without checking them, because developers have ADHD more often than not, and autopay will keep your zombie in service for a long time if it’s not making a dent big enough to make you shut it down (hosting a low-activity anything is not usually very expensive).
Not impossible that it’s just an absent admin.