The featureful Photon fork Tesseract is now available to use at tes.leminal.space. It has significantly advanced upon Photon’s already excellent interface and really come into its own. As such, the list of features is extensive, so I encourage you to check out the repo for a full description if you’re interested. Tesseract also works well on mobile, especially when installed as a PWA, so give that a try, too.
If all goes well, it’s likely Photon will be retired in the next couple of weeks with Tesseract taking its place. (EDIT: This has now been implemented.)
EDIT: Tesseract is no longer hosted here due to shenanigans
Also /c/modabuse. Also /c/yepowertrippinbastards. Also lemmy.ml/c/worldnews,
comrade, ACAB, and 552 individual accounts across 67 instances, about half of
them on lemmy.world. None of this is in the source code. It’s downloaded at
runtime from a file nobody has ever looked at. ## If you’re just tuning in
Tesseract is a third-party web frontend for Lemmy, maintained by asimons04 and
licensed AGPL-3.0. Admins deploy it on their own servers alongside or instead of
lemmy-ui, and there are public instances of it people use to browse Lemmy
generally. If you’ve used a Lemmy site that didn’t look like stock Lemmy,
there’s a fair chance it was this. Last week db0 posted a PSA
[https://lemmy.dbzer0.com/post/72685299]: Tesseract contains a blacklist of
instance domains compiled directly into the application. 32 of them. Admins
can’t see it, can’t configure it, and aren’t told it’s there. Connect to a
listed instance and the app tells you it’s “incompatible,” which is not true. I
went through the code to see how that was implemented. The hardcoded list turns
out to be the small half of the system. There’s a second filter policy fetched
over HTTP every time the app loads. It isn’t in the git repository. It’s
unauthenticated and world-readable, so anyone can pull it. Right now it carries
552 user accounts, 2,275 username patterns, 54 instances, 97 communities, 289
keyword patterns and 351 domains, with every category set to hide matches rather
than flag them. Not collapsed behind a click. Simply absent, with no indication
anything was removed. ## Verify all of it in ten seconds curl -s
https://tesseract.dubvee.org/tesseract/api/system/policy
[https://tesseract.dubvee.org/tesseract/api/system/policy]
| base64 -d | gunzip > policy.json That’s the live policy, base64-wrapped gzip,
111KB of JSON when it unpacks. There’s a stale fallback copy at /data/policy.dat
as well. ## It filters criticism of moderators - lemmy.sdf.org/c/modabuse —
listed - lemmy.dbzer0.com/c/yepowertrippinbastards — listed -
lemmy.dbzer0.com/c/YPTBcirclejerk — listed - community regex power ?tripping? -
keyword censoring me Call the rest of it whatever you like. This part is not
spam defence. ## It filters words The 32 community name patterns include
Communis(t|m), Conservativ(e|es|ism), Leftis(t|m), Libertarian(ism)?, ^Green
Part(y|ies), Zionis(t|m), (Police|Cops), guillotine and billionaire. Keywords
include comrade, ACAB, neoliberal, proletaria(n|t) and death to. Filtered
communities on instances that aren’t blocked: lemmy.ml/c/worldnews,
lemmy.today/c/news, lemmy.ca/c/politicalnewscanada, lemmy.ca/c/usa,
infosec.pub/c/strategic_unions. ## The 552 users aren’t bots 67 instances. 272
on lemmy.world alone, 40 on sh.itjust.works, 19 on lemmy.ca [http://lemmy.ca],
and 28 instances contributing exactly one person each. 355 of the 552 usernames
are plain alphabetic, twelve characters or under, median length eight. Only 36
look like spam registrations. A bot list looks like the opposite of that. Seven
of them aren’t even Lemmy. There are Mastodon and Friendica accounts in there:
people who have never used Lemmy, hidden by a Lemmy frontend, with no possible
way of finding out. I have the list and I’m not posting it. Most of these are
ordinary people who got pattern-matched, and 552 names on this comm is a
harassment target inside an hour. Run the command above and grep for yourself.
## And it lies about it When the instance block fires you get: “Incompatible
Instance. Not Supported. $instance is not compatible with Tesseract.” Nothing is
incompatible. It’s a policy decision dressed as an API error, and it’s what had
db0 chasing a version mismatch that never existed. For the hidden users,
communities and keywords, you get no message at all. ## Admins can’t switch it
off Tesseract has env vars for PUBLIC_DOMAIN_BLACKLIST,
PUBLIC_FAKE_NEWS_BLACKLIST and the shortener lists. There is none for either
blocklist. enableToxicMode bypasses the other filters and explicitly not this
one. Self-host it and you cannot disable this, nothing in your config admits it
exists, and the contents can change without you pulling a commit. ## Before
someone says it A lot of that domain list is real spam defence. It filters
conservatism as well as communism. “It targets the left” doesn’t survive the
data and I’m not going to pretend it does. The problem is that spam filtering
and political editorial got welded into one undocumented, remotely-updatable
blob, shipped hidden, to admins who’ve never read it and users who don’t know
it’s there. The spam work is what makes the rest unauditable: “it’s a spam list”
answers every individual question and none of the whole. And /c/modabuse is not
spam. ## Asks 1. Publish the runtime policy in the repo, or kill the endpoint.
2. Stop reporting a policy block as a technical incompatibility. 3. Tell users
when something’s been hidden. One line. 4. Give operators an off switch, like
every other blacklist in the codebase has. It’s AGPL-3.0 and db0 already forked
it [https://github.com/db0/tesseract]. That’s the licence working as designed.
But forking isn’t disclosure, and the admins who need this are precisely the
ones with no reason to go looking. If you run Tesseract, you are relaying a
111KB moderation policy you have never read, under your instance’s name, to
users who don’t know it exists. Full contents of every list, unedited, in the
comments.