this post was submitted on 23 Jul 2026
103 points (99.0% liked)

sh.itjust.works Main Community

8504 readers
2 users here now

Home of the sh.itjust.works instance.

Matrix

founded 3 years ago
MODERATORS
 

cross-posted from: https://sh.itjust.works/post/63880645

Issue: Tesseract has a hardcoded hidden instance blacklist, and an even more obfuscated censorship list of various users, instances, communities, and general regex matches.

Also /c/modabuse. Also /c/yepowertrippinbastards. Also lemmy.ml/c/worldnews, comrade, ACAB, and 552 individual accounts across 67 instances, about half of them on lemmy.world.

None of this is in the source code. It's downloaded at runtime from a file nobody has ever looked at.

If you're just tuning in

Tesseract is a third-party web frontend for Lemmy, maintained by asimons04 and licensed AGPL-3.0. Admins deploy it on their own servers alongside or instead of lemmy-ui, and there are public instances of it people use to browse Lemmy generally. If you've used a Lemmy site that didn't look like stock Lemmy, there's a fair chance it was this.

Last week db0 posted a PSA: Tesseract contains a blacklist of instance domains compiled directly into the application. 32 of them. Admins can't see it, can't configure it, and aren't told it's there. Connect to a listed instance and the app tells you it's "incompatible," which is not true.

I went through the code to see how that was implemented. The hardcoded list turns out to be the small half of the system.

There's a second filter policy fetched over HTTP every time the app loads. It isn't in the git repository. It's unauthenticated and world-readable, so anyone can pull it. Right now it carries 552 user accounts, 2,275 username patterns, 54 instances, 97 communities, 289 keyword patterns and 351 domains, with every category set to hide matches rather than flag them. Not collapsed behind a click. Simply absent, with no indication anything was removed.

Verify all of it in ten seconds

curl -s https://tesseract.dubvee.org/tesseract/api/system/policy \
  | base64 -d | gunzip > policy.json

That's the live policy, base64-wrapped gzip, 111KB of JSON when it unpacks. There's a stale fallback copy at /data/policy.dat as well.

It filters criticism of moderators

  • lemmy.sdf.org/c/modabuse — listed
  • lemmy.dbzer0.com/c/yepowertrippinbastards — listed
  • lemmy.dbzer0.com/c/YPTBcirclejerk — listed
  • community regex power ?tripping?
  • keyword censoring me

Call the rest of it whatever you like. This part is not spam defence.

It filters words

The 32 community name patterns include Communis(t|m), Conservativ(e|es|ism), Leftis(t|m), Libertarian(ism)?, ^Green Part(y|ies), Zionis(t|m), (Police|Cops), guillotine and billionaire.

Keywords include comrade, ACAB, neoliberal, proletaria(n|t) and death to.

Filtered communities on instances that aren't blocked: lemmy.ml/c/worldnews, lemmy.today/c/news, lemmy.ca/c/politicalnewscanada, lemmy.ca/c/usa, infosec.pub/c/strategic_unions.

The 552 users aren't bots

67 instances. 272 on lemmy.world alone, 40 on sh.itjust.works, 19 on lemmy.ca, and 28 instances contributing exactly one person each.

355 of the 552 usernames are plain alphabetic, twelve characters or under, median length eight. Only 36 look like spam registrations. A bot list looks like the opposite of that.

Seven of them aren't even Lemmy. There are Mastodon and Friendica accounts in there: people who have never used Lemmy, hidden by a Lemmy frontend, with no possible way of finding out.

I have the list and I'm not posting it. Most of these are ordinary people who got pattern-matched, and 552 names on this comm is a harassment target inside an hour. Run the command above and grep for yourself.

And it lies about it

When the instance block fires you get: "Incompatible Instance. Not Supported. $instance is not compatible with Tesseract."

Nothing is incompatible. It's a policy decision dressed as an API error, and it's what had db0 chasing a version mismatch that never existed.

For the hidden users, communities and keywords, you get no message at all.

Admins can't switch it off

Tesseract has env vars for PUBLIC_DOMAIN_BLACKLIST, PUBLIC_FAKE_NEWS_BLACKLIST and the shortener lists. There is none for either blocklist. enableToxicMode bypasses the other filters and explicitly not this one.

Self-host it and you cannot disable this, nothing in your config admits it exists, and the contents can change without you pulling a commit.

Before someone says it

A lot of that domain list is real spam defence. It filters conservatism as well as communism. "It targets the left" doesn't survive the data and I'm not going to pretend it does.

The problem is that spam filtering and political editorial got welded into one undocumented, remotely-updatable blob, shipped hidden, to admins who've never read it and users who don't know it's there. The spam work is what makes the rest unauditable: "it's a spam list" answers every individual question and none of the whole.

And /c/modabuse is not spam.

Asks

  1. Publish the runtime policy in the repo, or kill the endpoint.
  2. Stop reporting a policy block as a technical incompatibility.
  3. Tell users when something's been hidden. One line.
  4. Give operators an off switch, like every other blacklist in the codebase has.

It's AGPL-3.0 and db0 already forked it. That's the licence working as designed. But forking isn't disclosure, and the admins who need this are precisely the ones with no reason to go looking.

If you run Tesseract, you are relaying a 111KB moderation policy you have never read, under your instance's name, to users who don't know it exists.

I disagree with some of the assertions put forth above about it not targeting the left, etc. And I don't think the asks is relevant, because we should no longer be trusting anything from this person.

Policy file here, for archival purposes: https://file.garden/amIRhTctI0qld2r5/policy.json

top 24 comments
sorted by: hot top controversial new old
[–] TheDude@sh.itjust.works 9 points 1 month ago* (last edited 1 month ago)

The Tesseract frontend has been pulled.

For those interested you can see the announcement here: https://sh.itjust.works/post/64232628

[–] clee89@lemmy.world 1 points 1 day ago

hidden blocklists are a pretty big deal for federated software. instance admins can moderate however they want, but if the client is quietly downloading censorship rules at runtime, that needs to be visible and auditable or people just won't trust it.

[–] clee89@lemmy.world 1 points 1 day ago

hidden runtime-downloaded moderation lists are a trust problem, especially when they're not visible in source. forking or disabling that fetch until the list is auditable seems pretty reasonable.

[–] clee89@lemmy.world 1 points 1 day ago

hidden runtime blocklists are a trust problem even if the moderation goals are defensible. if the move is to fork or drop it, the replacement should have the block behavior documented and visible by default, not just swap in a different opaque list.

[–] clee89@lemmy.world 1 points 1 day ago

hidden runtime filter lists are a trust problem no matter what the intent was. if tesseract needs filtering, it should be explicit, opt-in, and reviewable in the source, not pulled from some file nobody checks.

[–] clee89@lemmy.world 1 points 2 days ago (1 children)

hidden runtime blocklists are a pretty serious trust problem. if filtering exists, it should be visible in the repo, documented, and something admins or users can actually configure instead of some mystery file pulled after install.

Fully agreed. Luckily, all major instances have now dropped Tesseract, AFAIK, and the dev has moved on to his next alt account.

[–] magnetosphere@fedia.io 38 points 1 month ago (1 children)

I support the right of Tesseract maintainers to have their own opinions. I do NOT support their choices to be opaque, misleading, and deceptive about it, though.

Even if they backtracked and got rid of the blocklist, I would’t trust them.

[–] AwesomeLowlander@sh.itjust.works 28 points 1 month ago (1 children)

Even if they backtracked and got rid of the blocklist, I would’t trust them.

Agreed. They're worse than an unknown party, they're a known malicious one.

[–] mindbleach@sh.itjust.works 18 points 1 month ago (3 children)
[–] ZombiFrancis@sh.itjust.works 9 points 1 month ago

but some of you all are just sick in the head.

immediately cites blahaj

Oof.

[–] ggtdbz@lemmy.dbzer0.com 5 points 1 month ago (1 children)

I wonder what set him off to block me. Did he see a comment of mine complaining about living under bombardment in Lebanon and think I must deserve it?

That implies blocking people one by one and probably cooking up functionality into the client that lets him add users on the fly to a blocklist. That’s so much work if he reached me unless he had some sort of auto blocking of individual users by keyword.

[–] mindbleach@sh.itjust.works 5 points 1 month ago

Anyone or anything that's ever annoyed him goes on his double-secret shitlist. Dude is Elon Musk without a budget.

Man, the double talk is insane.

[–] AwesomeLowlander@sh.itjust.works 21 points 1 month ago (1 children)

Pinging @thedude@sh.itjust.works @imaqtpie@sh.itjust.works @kersploosh@sh.itjust.works @inenduringgrowstrong@sh.itjust.works

Thanks for the ping

[–] ZombiFrancis@sh.itjust.works 20 points 1 month ago

I disagree with some of the assertions put forth above about it not targeting the left, etc. And I don't think the asks is relevant, because we should no longer be trusting anything from this person.

Exactly. Adding instances like maga.place doesn't mean adding blahaj is somehow unbiased or untargeted. In fact, maga.place actually serves to act as a screen for the deliberate targeting of instances, communities, and users.

[–] eutampieri@feddit.it 14 points 1 month ago* (last edited 1 month ago) (1 children)

Tesseract is a frontend, not the famous open source OCR software

[–] pastermil@sh.itjust.works 1 points 1 month ago

Yes, I've come to notice that after reading tbru.

[–] SatansMaggotyCumFart@piefed.world 3 points 1 month ago (2 children)

Are we allowed to post the plain text file?

[–] AwesomeLowlander@sh.itjust.works 6 points 1 month ago (1 children)

I already linked it at the end of my post. It's too long to post in a single comment.

That said, I don't think it's against any rules if you want to post some text.

[–] Widdershins@lemmy.world 3 points 1 month ago (1 children)

Try https://file.garden/amIRhTctI0qld2r5/policy.json

I fixed the link hours ago, but apparently it's not federating to some people.

[–] VitoRobles@lemmy.today 2 points 1 month ago

What do you mean?

I mean by definition, this is a public repo. And it has end users that the main developer has targeted directly.