2 Instances are being used for coordinated vote manipulation, and should be defederated. chinese.lol lemmy.doesnotexist.club
The attacker seems to be the admin of those two instances. Both instances have their registrations closed.
Edit: It is now open for both of them, or was already. I checked the Fediseer page for both instances and it still says that their registrations are closed.
Though it is suspicious that no captcha, email confirmation or manual approval is required for both of these instances. The admin of lemmy.doesnotexist.club seems to be inactive since their account creation yet this instance is still running. If the admin is the attacker, it could also be that they are the one behind the recent nicole spam.
A individual user airing their personal biases and manipulating lemmy isn't good for the community, regardless of how you feel about their target. This is a really bad thing (tm)
Can your detection method be automated and federated?
I'm asking because this is probably the thin end of the wedge and is likely to increase exponentially, especially since anyone can set up an instance and do whatever they like with it.
Seems relatively painless to chop those two instances off - chinese.lol has less than 200 users, and I can't even find instance info for doesnotexist.club (coincidence? i think NOT).
I do personally wonder how difficult it is to spin up new instances though. How much effort would it be for them to create a new one and do it again?
I'm actually most concerned with the IP leaking of the fediverse chick posts - hopefully some progress has been made with the IP leaking in auto-loaded external media through DM's
I checked the images and so far every image I've encountered linked to the users's lemmy instance's pictrs instance, none were hosted through a custom trackable image host.
That's what I'm afraid of. Once some bad actors realize Lemmy is as defenseless as it is, it'll be carnage for a while. The only tool we have is defederation and it's slow and borderline useless against spam or worse.
The attacker seems to be the admin of those two instances. Both instances have their registrations closed.
The alternative theory would be that these instances had open registrations, but rightly closed registration down after the admins noticed the bots. chinese.lol is on 0.18.4 with an admin with a 2 year old account, lemmy.doesnotexist.club has an admin with a 1 year account, and it was also that instance that the 'nicole' person has used before. This downvote attack would need to be a long time in the planning for what you're suggesting to be true.
Upon inspecting the actual websites, the registrations seem to be actually open for both instances with no email confirmation, captcha or manual approval as one user pointed out. I checked the Fediseer page for these instances. What is the update delay for Fediseer?
I don't know. It's not something I'm familiar with - it might just default to saying 'closed' if it doesn't have the data.
It's interesting that the obvious bot accounts on those instances were set up in mid-March last year, so I'm guessing that these are somebody's army that they've used before, but overplayed their hand when they turned it on the DonaldJMusk person. The admins can reasonably be blamed for setting up instances with open registrations and no protections and then forgetting about them, but I'd be wary of blaming them for being behind the attack directly. The 'nicole' person is unlikely to have used their own instance - it's probably just someone with the same MO as whoever owns the bots, finding and exploiting vulnerable instances.
What do you mean public voting? Everything in the Fediverse is public. Spin up a server and you can see all votes, even in the UI as an admin. Do you mean for users?
Being able to disable downvoting is one of the best features Lemmy has and I wish more instances would do it.
Voting here doesn't influence your feed and downvoting largely serves to spread negativity. Turning it off has a negligible impact on usability and an undeniable advantage when people decide their feelings matter more than someone else's, like whatever this is.
We've de-federated from both the instances being used for manipulative voting.
That's fine, but removing downvoting doesn't prevent the discussion. It curbs drive-by negativity which is a good thing IMO.
Obviously everyone is free to disagree with things. It should be more than absentmindedly hitting a down arrow though. Others obviously feel differently. Thankfully both exist on Lemmy.
Edit: It is now open for both of them, or was already. I checked the Fediseer page for both instances and it still says that their registrations are closed.