cross-posted from: https://lemmy.dbzer0.com/post/72685299
I discovered this after upgrading our instance yesterday, which also upgraded all frontends to their latest versions as well. After I did, our Tesseract frontend stopped working and I noticed immediately as it’s been my primary for a while. Initially I thought it was an API version mismatch, but no, it was much worse.
Someone pointed out that the developer of the frontend added an explicit hidden and unmodifiably blacklist which includes any and all instances to the left of Kissinger. There’s a commit which also explains their specious reasoning about our instance specifically, as it seems we’ve been on their shit list for a bit longer than that.
This instance and its admin staff encourages identity politics, groupthink, mob mentality, and extremist solutions to societal problems. Users who advocate violence are not moderated so long as the admins agree with the target. Caution and critical thinking are advised when interacting with this instance or its users.
When you use tesseract to connect to one blacklisted such instance , you just get a message informing you that Tesseract is “incompatible with that instance” which leads one to think of a technical issue, like an API mismatch, rather than the dev being an opinionated coward.
Isn’t it funny how all the software developed by turbolibs, like Piefed and Tesseract, end up with hidden control mechanisms from developers who think they know better than everyone else? That they don’t just think they deserve to tell you what you should think, but they should manipulate you to think it? Isn’t it funny how libs go on about how bad it is to support lemmy due to the ideology of the devs behind it, and yet lemmy has 0 opinions as a software? It does make one think…
Anyway, I forked - it as one does - and disabled the blacklist, but since this is a massively ideologically compromised software, I’ll doubt I’ll keep this frontend up after Lemmy 1.0. I think we’ll bring up mlmym again now that someone’s maintaining it again.
For the folks happening to see this here, there’s been more uncovered, in the form of a large external community, user, and verbiage shadow-ban list from the developer. This is separate from the hard-coded lists, as it is remotely downloaded by the front-end from their site. Again, this is all without your knowledge or consent, and intentionally obfuscates itself because the developer surely knows the users wouldn’t want to hand over that sort of control to someone else.
It genuinely does not matter what is being censored, this should not be happening under the remote control of a developer unrelated to the instance the software is being hosted on. This is malware, and acts as such because it knows you wouldn’t deploy the code as-is willingly. A developer willing to do this shows that the software is compromised, and cannot be trusted. Anyone running Tesseract should immediately remove it from their site, not simply for violating your consent here, but also for what could potentially happen in the future. An actively adversarial developer is not something you should need to concern yourself with in your server stack, and the trust in Tesseract is all but vaporized now.
Update #2: As an added bonus, the developer has decided to brazenly and mockingly double down on their actions.
Update #2: As an added bonus, the developer has decided to brazenly and mockingly double down on their actions.
Not only has his credibility as a developer been destroyed but so has his credibility as a person. That is the most disgusting response I’ve seen from a developer who knowingly did wrong and was caught. It’s funny he used the presence of spam on the list to justify its entire existence. Completely ignoring that he blocked a trans instance and trans people. And that, he doesn’t have the right to be the voice of moderation on servers which aren’t his own. He also claimed he could’ve done far worse, which doesn’t make him look better but more like the malware author he is.
trust in Tesseract is
all butvaporized now.Fixed that for you.
To be fair, it’s a stand in for [effectively/basically/pretty much] vaporized. I obviously have zero trust in Tesseract now, but whether that sentiment persists into Lemmy as a whole is still up in the air. I’d consider it truly vaporized if zero instances host Tesseract in any form outside of the developer.
Of the two instances I know hosted the software, Blahaj removed it effectively immediately. That’s despite trying to resolve a software exploit in another service they host at the same time. Db0 still hosts Tesseract, albeit a forked version they modified, with intentions to swap it to something else down the line. I’m sure there are others hosting it too, and it’d be great if they all were indeed removed and replaced, ASAP.
I think outside a few accounts which might be sockpuppets anyway, no one is really happy about what Admiral Patrick (the dev behind this) did. The fact he shuttered his instance replacing it with a picture and momentarily hid the repository shows that he’s getting more pushback than not.
That’s not to say there aren’t reasons people would still want to use Tesseract, it has the most robust mod tools than any other frontend out there. I feel like that should change but it probably won’t any time soon (and if it does it’ll probably be something vibecoded by someone with the motivation but lacking the skill to do it completely or themselves at all).
Irrespective of it’s apparent tooling, Tesseract is fundamentally compromised as software and cannot be trusted. When someone gets caught shipping malware in their project, you now have to start with the assumption of guilty until proven innocent. Anything less than a full audit of Tesseract, along with a hard fork and rebranding, is a liability risk for server hosts and users alike. Until such time that this occurs, it should be purged from every server ASAP. I’ve seen several threads of Tesseract being removed from instances, so hopefully this continues as others discover this absurdity.
Full audit is 100% necessary at this point, and no commits should ever be accepted from the original author again. He can’t ever be trusted.
Yiiiikes. I can’t even.
– Frost
Yeah, this is something I am worrying about in overall open source projects. There are going to be increasing number of protest-ware and that is going to suck.




