As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.
This is an important post and I appreciate the insight into the happenings on the Fediverse, but the comment chains are going off the rails and I’ve issued a number of bans from this post alone.
Locking.
I don’t think I’ve ever witnessed someone going so hard off the rails. It’s been an entertaining few days really.
It’s what happens when someone with underdeveloped empathy gets caught doing something they know is wrong, resulting in emotional overload.
It’s textbook toddler tantrum.
With stunted empathy, people seeking an explanation and apology are met with increasingly greater resistance.
And like textbook, they claim to be the victim. I wouldn’t be surprised if they are lying about receiving death threats.
What’s crazy is they could have simply:
- Apologised
- Explained the intent to reduce toxicity
- Agreed there was a lack of transparency
- Refactored their existing “enable toxicity mode” feature into a clearer, toggleable blocklist feature
But no. They were caught while they were secretly trying to play internet dictator and refused to empathise with others that were hurt and shocked to find out a tool they were using was receiving undisclosed payloads to use to censor communities and individuals.
I strongly implore everyone to leave this developer alone. Jokingly asking to be added to the list etc empowers them to continue to play the victim. They do not deserve attention.
Text book narcissistic collapse
Refactored their existing “enable toxicity mode” feature into a clearer, toggleable blocklist feature
No! The whole point of the fediverse is not to have centralised blocklists. Having blocklists baked in to the code, especially ones that get updated in a centralised manner with no accountability and without telling users they’re on it is absolutely antithetical to the platform and one of the main reasons why people are leaving reddit and coming here. If you want to curate the experience of a user in that manner, what you do is open an instance and advertise it as such. That way people can, at least on lemmy, know where they’re banned from without having to dive into the code or pull API endpoints manually. In fact how a lemmy instance federates and how it curates this experience is one of the distinguishing features among the instances. You have instances like lemmy.zip that federate all that will have them, instances like hexbear that are very quick to defederate in order to keep a safe-space and instances like blahaj that are somewhere between.
A front-end (or any piece of code that is made for being deployed on multiple instances) should be agnostic to all of this. It’s up to the admins of the instances and not the devs to curate and this is one of the main reasons why I don’t trust the piefed dev. Sure you can disable almost everything, but that still means that an admin has to do work in order to get to a neutral place from where they can then curate.
It’s up to the admins of the instances and not the devs to curate and this is one of the main reasons why I don’t trust the piefed dev.
Can you elaborate on that? Asking for curiosity, not to challenge you.
The two main lists that are implemented by default are a defederation list and huge huge listof blocked domains which includes wikileaks for instance, there are other lists (I don’t know if the “trusted instance” list comes prepopulated) and almost all can be emptied or added to. But that means that an admin that sets up the software has to go through a whole rigmarole to get the instance to neutral before being able to do what they think is best. And hope they didn’t miss anything.
In the case of the blocked domains it’s particularly grating since it has like 4000 entries that you either have to delete one-by-one or have to do a manual db transaction to empty the list and that is by design. Plus all you get as a warning that such a list exists is one line during the setup that says
Added 'No-QAnon' blocklist, see https://github.com/rimu/no-qanonbut it’s definitely not just QAnon links.FYI, next version of PieFed has an “Unban All” button for clearing all domain bans to try to make this easier.
Screenshot from my instance:

Oh that’s good to hear. It sucks that people have to constantly fight the dev to keep his opinions out of the code though, must be tiring for all involved surely…
Not every admin has the time or skill to curate. As long as the dev is open about it and there are configurable features to disable it, I don’t see what the issue is. Ultimately it creates no difference for a user if the admin creates it or the Dev does as long as it’s communicated.
The advantage of the fediverse is “don’t like it, go to another instance or build your own”, not to tell devs what they can and can’t do. Hell I never even interacted with Tesseract since I use a different client and an open instance.
The issue is that it’s one person shadowbanning people without their knowledge for any arbitrary reason across instances. Like even if it’s opt-out, that’s still problematic since it makes the default experience whatever that one person thinks it should be. Why should one guy get to decide across the entire fediverse whether your posts are opt-in? That is antithetical to the very concept of the fediverse.
Except one guy isn’t. You have to choose to install the software. It’s not included by default. I’m running a local client (Voyager) and never dealt with any of that because the admins of my instance don’t use it either.
And every user that uses that software for whatever reason, superior features, easier on the eyes, more popular it’s what everyone recommended will get their curation from that one dev.
Which is why it’s ultimately the decision of the admin. Don’t like what the admin of your instance is doing. Go make your own. That’s the beauty of the fediverse. It’s choice all the way down. It’s not like Reddit where you’d be stuck.
What’s crazy is they could have simply:
- Apologised
- Explained the intent to reduce toxicity
- Agreed there was a lack of transparency
- Refactored their existing “enable toxicity mode” feature into a clearer, toggleable blocklist feature
Yes, I think there is genuinely an audience for what he was doing (or something akin to it), and it would genuinely have been a useful onboarding tool for getting a certain type of person to consider dipping their toes in the Fediverse.
But first of all it absolutely has to be separated from the safety/anti-spam filters. Bundling it with those is very malicious.
Second it must be opt-in.
Third, it must clearly say somewhere that “this anti-toxic setting is a curated block list based on my personal preferences”. There should then have been an option to use a personal blocklist instead of the developer default.
And fourth, I guess ideally this type of filter should maybe have been maintained by a somewhat more… well-balanced individual.
Anyone who thinks “yeah lgbt stuff should be hidden because we want to attract people who don’t want to see LGBT stuff” is someone I don’t want anywhere near the fediverse.
Yes, agreed. Wholesome Yuri being banned might be the most outrageous decision of them all on the banlist, for me.
Tbh for me it was more outrageous how it interferes with moderation. There are admins from big instances who weren’t blocked themself and mods from big active communities on that list. If they write warning comments, users of this frontend will simply not see them
And tho user and comment regex is a mess, partially containing very random things. Lot’s of possible wrong matches. This whole thing is from no viewpoint a good idea
Also from the other end, because of how the filter works, mods using couldn’t see messages the user put, so they’d have been free to do whatever, until caught by either a bot, or moderators not using the frontend.
One of the reasons it was found to begin with was because the db-zer0 instance was on it, and the admin, who was using tesseract, suddenly couldn’t load any posts from the instance at all. As Tesseract presents it as a compatibility issue, they were trying to track down the fault at the time.
I agree, I’m almost sad it’s (presumably) over now.
Then again, he already “left” once before (and came back), so who’s to say? We might be clowning on him on and off the rest of the year if he keeps it up.
I saw a vaguely similar situation a long time ago where someone was a positive, contributing member of the community and then they fell from grace somehow and basically no one was thankful enough so they were banned and they just kept evading the bans and posting smut in the forums for weeks.
The way this guy has really thrown his weight into this but still obviously feels like the victim is really reminiscent, I wouldn’t be surprised if there’s some more to come.
That’s weirdly sort of how I got my job.
Apparently my predecessor was a nice guy with low boundaries that (at the time) lacked managerial support. When he painted himself into a corner on his commitments, didn’t get the accolades or raises he thought he should get, he got bitter, started to act out, stopped doing work he should have done, and finally, when management started pressing him to clean up some messes he had created over a year+ of neglecting his responsibilities, he left an unsigned resignation letter on his desk and didn’t come to work for a few days.
He called to discuss the terms of his return, expecting a raise, and they just told him they accepted his resignation.LOL. Sounds like an idiot. Even if the guy was really needed, you can’t have someone like that on your team.
It’s okay, they are a measured and non-violent individual that just wants Lemmy to be friendly for the “normies.”
They’re a good guy™︎!
so true
I have received a constant stream of harassing messages, death threats, and threats of doxxing over DM, Matrix, Github, and Codeberg. All of it instigated and eggged on by another instance’s top admin.
you’re the good guys wooooooo!
go fediverse!!
Right, because all of us personally sent harrassing messages, death threats, etc.
See I don’t doubt that he received harrassment, hell I can even believe he got death threats. And that really sucks, I’m sorry he experienced that.
Isn’t it convenient how there are no receipts of them though? Or any trace of the supposed dude egging people on to do it? It’s a diversion tactic that’s honestly becoming quite old.
he is probably still reading these discussions lol
People like him have multiple accounts.
here’s a running list.
Another sus account is @Teacrumble@lemmy.world. Dormant account that suddenly woke up to defend Patrick right after the drama happened.
Another sleeper cell has awakened!
Some people just don’t post much, I’m not defending anyone. I’m attacking/critizing you, dick
Yeah thats definitely another one. Keep 'em coming! Dont be shy now!
Another what? What are you even trying to accomplish?
Im trying to be the first person with 2 mentions on your shitty block list. Pretty please?
I could understand hardcoded blacklists if Tesseract was meant as a frontend for a Lemmy instance tailored for a specific purpose, and not intended for general use. But this, to DDOS a website because the developer is a whiny baby who can’t take criticism? This is a new low. This is disgusting, and damaging for the Lemmyverse as whole.
Good riddance then, I guess.
I doubt he’s gone, just hiding under an alt.
I sincerely hope for his mental wellbeing that he doesn’t.
He absolutely is. He was trying to defend himself under his Kirk@ startrek.website account constantly these past few days.
Tesseract is officially malware. What a petulant child Patrick is.
i miss ernest and kbin; it was great software that vibed with the rest of the fediverse and he was just nice.
I was suspecting this guy might be a fed just because of their actions, but this crashout has proven me wrong, he was doing it for free.
This person is most likely mentally ill. I tried to point out a bunch of weird shit that the dubvee instance was doing two or three years ago. I was mostly ignored and made to feel like I was crazy. So I just dropped it and tried to block and ignore anything from Dubvee on my own clients. So it’s quite vindicating to see this asshole get totally blown up for days now all over the fediverse. But also kind of tiring, like we’re reverting back to bean memes just to get a break from this drama.
we at the fringes are fated to share space with the mentally ill forever i guess
I mean, us mentally ill people aren’t all authoritarian assholes

In case somebody wanted confirmation. Maybe don’t visit the page with Javascript enabled.
Expert dev. Doesn’t even know the attribute for setting the language in the script tag is
type, notlang. Not to mention that you are encouraged to omit the attribute altogether if the script tag contains JavaScript…Petty, and a bad dev. Big yikes.
Well the
scripttag has a deprecated attribute calledlanguage, so in older code and media you will see<script language="javascript">a bunch. The weird thing is they instead used thelangattribute which just doesn’t exist.To be fair, it’s not as if it supports languages other than fucking Javascript anyway, so it mostly doesn’t matter.
Edit: I don’t want to split hairs about modules or json or whatever; I just want to be salty about how we could’ve had Scheme or Python in the browser.
Actually some sites do. Instagram uses
type=application/jsonto store preloaded data.
The random strikes me as curious too. I don’t see the point in doing
(100 - 1 + 1), you could express a random number between 1 and 100 in a simpler manner. Then he gets another random number and reuses that three times, for whatever reason.Then again, none of his other decisions make much sense to me so why would this?
There are a lot of these sorts of things. Look at the RegEx used in the block list. The author will likely be surprised that RegEx supports * and +.
It’d be hilarious if this dude went to prison over this, because it seems like he finally crossed from “annoying and unethical but legal” to straight up illegal.
Enforcement is for inconvenienced rich tech companies.
Can someone please ELI5?
Basically, every time you visit the page, it has code that sends 500 * 4 queries to one particular instance, making it load a page from the modlog, do a search, etc.
So everyone visiting the page would suddenly be sending 2000 queries each, and in theory, enough users would DoS the server by overloading it with those requests, rendering it unusable.





















