this post was submitted on 27 Jul 2026
1282 points (99.2% liked)
Fediverse
43154 readers
1134 users here now
A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, Mbin, etc).
If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!
Rules
- Posts must be on topic.
- Be respectful of others.
- Cite the sources used for graphs and other statistics.
- Follow the general Lemmy.world rules.
Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Can someone explain what the hell this whole situation is? I didn’t really even know what tesseract even was before this happened.
There was (is, as a fork) a front-end for Lemmy called "Tesseract." Some folks liked it because it has improved filtering options, better mod/admin controls, et cetera. At least up until it was discovered that several instances had been hard-coded to be filtered while the front end erroneously reported it as an incompatibility issue. Then it was also discovered that it retrieved an additional blacklist from the developers server (as base64 encoded data, which decoded into a gzip file, which extracted to a json file of the actual blacklist - if you're curious about that). Aside from some filtering that most would be indifferent to, it seemed the dev was also hand-curating this blacklist to include individual users. People that must've "wronged" them or posted something they didn't like at some point.
None of this was disclosed in the project's README.md on GitHub. To my knowledge, as I didn't use the front-end, it wasn't disclosed anywhere outside of having to manually review the source code and discover it for yourself. There was supposedly, somewhere in the settings, an option to enable "Toxic Mode." That was the means of disabling some of the above (maybe the blacklist, not sure about hard-coded instances) but it doesn't sound like it was very descript about what was happening when toxic mode was disabled.
Sooooo, tldr:
And we're now at their last Huzzah: Adding spiteful and malicious code. They were just a coward before that. They might've saved some face in acknowledging that they should've been forthright in their filtering. Now they're a coward and a heaping pile of shit whose work can never be trusted again.
Some guy made a UI for Lemmy, called tesseract. Then he hid secret blacklists within that UI which automatically blocked a bunch of leftist and trans content, as well as some generic spam stuff. Someone noticed that a trans community was blocked when accessed through tesseract, and so they did some digging and published the blocklists.
Guy that made tesseract calmly and reasonably wrote a rambling "farewell" letter where he basically said we're all insane and he's done trying to make Lemmy a "better" place, and included ddos code within the farewell letter targeting the instance that first identified the blacklists.
Now they've spent the last 2-3 days arguing how great the tesseract blacklist was under various alt accounts.
if he kept quiet and let it unravel no one wouldve been wiser, and kept speculating, but conservatives are loudmouths.
Some guy made a customized lemmy frontend.
He decided to be a fascist justice warrior and secretly embed filters that blocked users he didn't like personally.
Someone noticed and said wtf?
He framed it as protecting lemmy and new users - anyone asking why a frontend should even be doing this, let alone in an obfuscated, default enabled manner, were met with his whinging.
Instead of accepting the unpopularity of his extremely poor choices, he instead decided to commit the crimes of disturbing malicious software.