cross-posted from: https://jamie.moe/post/113630

There have been users spamming CSAM content in [email protected] causing it to federate to other instances. If your instance is subscribed to this community, you should take action to rectify it immediately. I recommend performing a hard delete via command line on the server.

I deleted every image from the past 24 hours personally, using the following command: sudo find /srv/lemmy/example.com/volumes/pictrs/files -type f -ctime -1 -exec shred {} \;

Note: Your local jurisdiction may impose a duty to report or other obligations. Check with these, but always prioritize ensuring that the content does not continue to be served.

Update

Apparently the Lemmy Shitpost community is shut down as of now.

  • @[email protected]M
    link
    fedilink
    English
    42 years ago

    Locking the thread. Information relevant to self-hosters has already been shared. Too many reports of off-topic comments to leave this open.

      • regalia
        link
        fedilink
        English
        702 years ago

        This isn’t trolling, this is just disgusting crime.

        • @[email protected]
          link
          fedilink
          English
          1
          edit-2
          2 years ago

          The crime happened in the past when the children were abused. This is some weird amalgam of criminal trolling.

          Edit: yeah yeah I get that csam is criminal, that’s why I called it an amalgam. It’s both trolling and criminal.

          • chiisana
            link
            fedilink
            English
            112 years ago

            Depending on jurisdiction, I am not a lawyer, etc etc, but I’d imagine with fairly high degree of probability that re-distribution of CSAM is also a crime.

          • Dark Arc
            link
            fedilink
            English
            182 years ago

            It’s still a crime. Taking the pictures is a crime. Sharing the pictures is also a crime.

          • @[email protected]
            link
            fedilink
            English
            22 years ago

            The crime happened in the past when the children were abused.

            That’s true. You could look at it that way and stop right there and remain absolutely correct. Or, you could also look at it from the eventual viewpoint of that victim as a human being: as long as that picture exists, they are being victimized by every new use of it, even if the act itself was done decades ago.

            Not trying to pile on, but anyone who has suffered that kind of violation as a child suffers for life to some extent. There are many who kill themselves, and even more that cannot escape addiction because the addiction is the only safe mental haven they have where life itself is bearable. Even more have PTSD and other mental difficulties that are beyond understanding for those who have not had their childhood development shattered by that, or worse, had that kind of abuse be a regular occurrence for them growing up.

            So to me, adding a visual record of that original violating act to the public domain that anyone can find and use for sick pleasure is an extension of the original violation and not very different from it, IMO.

            The visual records are kind of a sick gift that never stop giving, and worse still if the victim knows the pics or videos are out there somewhere.

            I am well aware not everyone sees it this way, but an extra bit of understanding for the victims would not go amiss. Imagine being an adult and browsing the web, thinking it’s all in the past and maybe you’re safe now, and stumbling across a picture of yourself being raped at the age of five, or whatever, or worse still, having friends or family or spouse or children stumble across it.

            So speaking only for myself, I think CSAM is a moral crime whenever it is accessed, one of the most hellish that can be committed against another human being, regardless of the specificities of the law.

            I don’t have a problem with much else that people share, but goddamn I do have a problem with that.

      • @[email protected]
        link
        fedilink
        English
        172 years ago

        I’d think most trolls would pass up on doing something that can easily get them imprisoned if ever found out …

  • @[email protected]
    link
    fedilink
    English
    282 years ago

    i’d love for a good tech journalist to look into how and why this is happening and do a full write-up on it. come on ars, verge, vice

  • @[email protected]
    link
    fedilink
    English
    1652 years ago

    Someone is trying really hard to hurt Lemmy by continually attacking the most popular instance. Is this all coming from right-wingers upset that their nazi instances were defederated across basically the whole fediverse?

    • @[email protected]
      link
      fedilink
      English
      452 years ago

      I wouldn’t put it past the hexbear crazies throwing a tantrum. They claim to be left wing… Sure seem more like fascist trumper types though. Maybe it’s just that they’re all incels and incels all seem about the same.

      • @[email protected]
        link
        fedilink
        English
        432 years ago

        Throwing a tantrum about what exactly? They’re one of the oldest-running Lemmy instances. Until now they were running a fork based on a pre-Federation version of the codebase.

        You believe they did a bunch of work migrating their database only to then negate that work by destroying the community they wanted to Federate with?

        • Rentlar
          link
          fedilink
          English
          152 years ago

          At least a handful of users on hexbear had made their intention clear during the first week of re-federation, they were looking to cause chaos on Lemmy for there own pleasure. I don’t know if they were banned and/or their comments deleted.

        • @[email protected]
          link
          fedilink
          English
          22 years ago

          Big difference between a few users who did a bunch of work and the toxic goonsquad the majority of the userbase turned into.

        • maegul (he/they)
          link
          fedilink
          English
          132 years ago

          Well something to keep in mind is that hexbear isn’t one person … it’s a whole community that’s developed independently for a while. So it’s reasonable to expect that there’d be variation in the behaviours of members in the same way there’s variation on the rest of lemmy. From what I’ve gathered, not all hexbear members are keen on the re-federation, and some aren’t too keen on being “well-behaved” around politically opposed users (ie “libs”), though hexbear admins and other users have promised moderation and that such isn’t part of the core hexbear values.

          It’s social media, afterall … and people can be rather shit and ruin it for the rest of us. In the end, the core service provided a social media platform isn’t the hardware, sys-admin-work or software (however necessary they are) … it’s the moderation work.

          The moderation keeps the place sanitary enough for people to actually want to be here … however much we may have problems with particular actions of our moderators, we should really support and praise them at every turn.

      • maegul (he/they)
        link
        fedilink
        English
        512 years ago

        they’re all incels and incels all seem about the same.

        Downvote from me there. I’ve seen plenty of examples of hexbear people being nice, interesting and good sports. They definitely seem to have more of shitposting culture than is normal on mainstream lemmy. But all in all it’s seemed fun to me from what I’ve seen.

        Beyond all that, this is just superficial and prejudicial. If you had some examples to link to or more substantial insights to share as to why it’d be “them”, that’d be worth reading.

        Otherwise, they’re an instance. Not one person, I’m sure some on hexbear are assholes and some awesome.

        • @[email protected]
          link
          fedilink
          English
          92 years ago

          So, so shocked someone it’s from lemmygrad that is defending the notoriously toxic “communist” tanky trollfest instance.

          • maegul (he/they)
            link
            fedilink
            English
            462 years ago

            Sorry, not from lemmygrad. And I’m on lemmy.ml because I joined before the Reddit migration and “Privacy and FOSS” (the focus of lemmy.ml) made a lot of sense for a lemmy instance/community.

            Beyond that … more superficial, prejudicial hate mongering without any description of why or for what purpose. Sorry, I don’t think it’s worth reading … a downvote from me … and, just being real for a moment … at the moment it’s more likely that you’re a member of a “notoriously toxic … trollfest”.

            Ironically, IME, I’ve seen significantly more troll-like tankie hate than I do tankie-trolling. I keep asking for receipts/links to tankie trolling here, as I’m genuinely curious to see it and understand what people are so upset about (please don’t explain to me what’s so upsetting unless it’s culturally thorough or coupled with some links+descriptions) … but no one has been able to do so.

            • @[email protected]
              link
              fedilink
              English
              82 years ago

              Most people from hexbear provide sources, which is better than can be said for all the tankie hate.

    • @[email protected]
      link
      fedilink
      English
      92 years ago

      Considering all the alt-right garbage that was popping up there the last couple of days this seems at least plausible. I sometimes envy their ability to utterly destroy anything they touch.

      • @[email protected]
        link
        fedilink
        English
        32 years ago

        I’m sure you’d love to link to some examples

        See people claim this constantly with no proof

        • @[email protected]
          link
          fedilink
          English
          2
          edit-2
          2 years ago

          You want me to link posts that the mods removed? That seems like an unrealistic expectation. You could always check the post pinned to the top of lemmyshitpost where they describe the recent problems, but I suspect you didn’t ask for proof in good faith

          • @[email protected]
            link
            fedilink
            English
            32 years ago

            Ah that’s actually my bad, I thought you were replying to a different comment in reference to hexbear

    • @[email protected]
      link
      fedilink
      English
      732 years ago

      My tin foil hat is telling me it’s one of the other social media companies funding a hacking group to do it. They stand to have the most to lose, and they’ve seemingly decided to enjoy changing the narrative regarding multiple topics. Lemmy stands directly against what the bigger social medias stand for.

      I have no evidence to back this though. As a business owner I just know that things become very consistent when people are being paid, and very inconsistent when they aren’t. These attacks are seemingly very consistent/organized.

      • The Picard Maneuver
        link
        fedilink
        English
        212 years ago

        There must be room under that tinfoil hat for the both of us, because this was my first thought too.

        • GONADS125
          link
          fedilink
          English
          152 years ago

          The longer it continues, the more likely that scenario is IMO. Bitter alt-right extremists would probably start losing interest after a short while, whereas social media competitors would stand to gain from long-term interference.

      • @[email protected]
        link
        fedilink
        English
        162 years ago

        I’d go with state actors first.

        When a particular social media platform is centralized, you can buy yourself a say percentage of stock and have sway over it (cough tencent), or have a useful idiot ruin the platform (cough musk), or another useful idiot to run propaganda you like anyway (cough truth social, cough fox news, cough newsmax…), or yet another that will sell out it’s host country’s citizens for cold hard cash (cough facebook).

        But when that social media platform is decentralized? Well, then you’d need to figure out how to poison the well early on to stave off adoption. The Saudi Arabias, UAEs, Chinas definitely don’t like the idea of lemmy, and it’ll be way harder for them to control if critical mass is hit.

        • @[email protected]
          link
          fedilink
          English
          52 years ago

          Yep, that’s a great point.

          Add to that the fact that mainstream social media companies wouldn’t touch DDoS and CSAM attacks with a 100-foot pole, even if they contracted with a third party. Both of these attacks are highly illegal and would surely ruin a publicly traded company (or one that’s trying to go public, like Reddit).

          And don’t forget Russia in your list of state actors who are threatened by the unrestricted flow of information. They definitely don’t want their citizenry to be informed of how disastrously their invasion of Ukraine is going, or what a murderous scumbag Putin is.

        • @[email protected]
          link
          fedilink
          English
          32 years ago

          You don’t get a lot of upvotes and sure we don’t know but it isn’t like the NSA infiltrated (in person) left wing groups and more.

          It’s definitely a possibility that someone doesn’t like decentralised content enough to put some meager efforts against it.

      • phillaholic
        link
        fedilink
        English
        502 years ago

        You think a company that is posed to go public is going to attack a competitor with a minuscule amount of traffic with extremely illegal material that could put them in prison for even having?

        • Norah (pup/it/she)
          link
          fedilink
          English
          72 years ago

          See, I don’t believe this was done by a large corp. But all the DDoSing that’s happened? I can see u/spez orchestrating that.

        • @[email protected]
          link
          fedilink
          English
          172 years ago

          Reddit? No. I was thinking moreso Meta. They have the deeper pockets and a proven track record of breaking privacy laws to their own benefit.

          • phillaholic
            link
            fedilink
            English
            222 years ago

            That’s even worse. Meta probably doesn’t even know what Lemmy is.

            • @[email protected]
              link
              fedilink
              English
              42 years ago

              So then why was Meta trying to get Threads to be on the Fediverse? Of course they’re aware of any potential threats, no matter how small.

              • phillaholic
                link
                fedilink
                English
                32 years ago

                Why reinvent the wheel if someone’s just going to hand you the backend? Lemmy is no threat to them.

                • @[email protected]
                  link
                  fedilink
                  English
                  12 years ago

                  The threat is a new sustainable community that’s sheltered from advertising that people could leave Factbook/Instagram/whatever and go to.

          • @[email protected]
            link
            fedilink
            English
            92 years ago

            Meta was talking about adding Mastodon federation to their Threads app. So I very much doubt it.

            They’d probably take an Embrace, Expand, Extinguish approach.

        • @[email protected]
          link
          fedilink
          English
          02 years ago

          You would pay a third party to do it. And keep details extremely vague so you have plausible deniability.

      • t�m
        link
        fedilink
        English
        152 years ago

        Could be, I’m surprised /g/ didn’t create an instance

    • @[email protected]
      link
      fedilink
      English
      5
      edit-2
      2 years ago

      This makes the most sense to me. It’s a pretty vitriolic attack, therefore I don’t think it’s simply a troll while at the same time I don’t believe it’s any corporate social media.

  • Neuromancer
    link
    fedilink
    English
    142 years ago

    If the source deletes the post. Won’t that remove it from all the instances ?

  • CrimeDad
    link
    fedilink
    English
    112 years ago

    I’m not subscribed to that community, but I guess I’m glad Pictrs doesn’t work for me, since I am using the Yunohost version of Lemmy. The creators of the Yunohost package couldn’t get it to work. I haven’t really missed it honestly.

    • Dandroid
      link
      fedilink
      English
      82 years ago

      Can you run lemmy without pictrs? What behavior is different?

      • CrimeDad
        link
        fedilink
        English
        32 years ago

        It just means that you can’t upload pictures, including banners or avatars. However, when I want to create an image post, I just make the post on Pixelfed and then mention the Lemmy community I want to post to at the bottom of the post body. Supposedly there’s a way to reference a remote image for a banner or an avatar, but I haven’t figured that out yet.

  • The Picard Maneuver
    link
    fedilink
    English
    116
    edit-2
    2 years ago

    So, from memory there has been:

    • This recent attack
    • Regular DDOS attacks
    • Frequent attempts to spam community creation
    • That one time the instance got hacked and set to redirect to shock sites

    Am I missing anything?

    This seems like more than just a few trolls. Maybe someone really doesn’t want to see user-owned social media take off.

    • Scrubbles
      link
      fedilink
      English
      852 years ago

      I see where you’re going with this, but no, people really are just absolutely horrible. The fact is that with other social media they’re just already very set up in managing this so we never see it. Lemmy wants to be open, this is the flipside of that openness.

      • @[email protected]
        link
        fedilink
        English
        192 years ago

        It’s generally easy to crap on what’s ‘bad’ about big players, while underestimating or undervaluing what they are doing right for product market fit.

        A company like Meta puts hundreds of people in foreign nations through PTSD causing hell in order to moderate and keep clean their own networks.

        While I hope that’s not the solution that a community driven effort ends up with, it shows the breadth of the problems that can crop up with the product as it grows.

        I think the community will overcome these issues and grow beyond it, but jerks trying to ruin things for everyone will always exist, and will always need to be protected against.

        To say nothing for the far worse sorts behind the production and more typical distribution of such material, whom Lemmy will also likely eventually need to deal with more and more as the platform grows.

        It’s going to take time, and I wouldn’t be surprised if the only way a federated social network eventually can exist is within onion routing or something, as at a certain point the difference in resources to protect against content litigation between a Meta and someone hosting a Lemmy server is impossible to equalize, and the privacy of hosts may need to be front and center.

        • @[email protected]
          link
          fedilink
          English
          15
          edit-2
          2 years ago

          The solution in this case is absolutely AI filters. Unfortunately you won’t find many people willing to build robust model for that. Because they’d be those getting the ptsd you mention.

          • @[email protected]
            link
            fedilink
            English
            52 years ago

            Iirc, ptsd is something only certain characters get. We should probably focus on finding people who really have no problem watching rough content. I have ptsd so I probably am not the right person for the job.

            • @[email protected]
              link
              fedilink
              English
              11
              edit-2
              2 years ago

              I don’t want to try. I have pretty low barrier. I set up NSFW filter on lemmy because I found disturbing the furry content that was common some time ago… I don’t want even to try anything worst than that

  • @[email protected]
    link
    fedilink
    English
    192 years ago

    I went ahead and just deleted my entire pictrs cache and will definitely disable caching other servers images when it becomes available.

  • @[email protected]
    link
    fedilink
    English
    192 years ago

    To be clear, if no one on a given instance sub to that particular /c, the content won’t federate to said instance, correct?

    • JamieOP
      link
      fedilink
      English
      172 years ago

      At this point, the community is clean. So unless more is posted, then you should be good. If someone searched for the community and caused a preview to load while the content was active though, then it could be an issue.

      • @[email protected]
        link
        fedilink
        English
        52 years ago

        Cool. Thanks. I cleaned up anything from the past 2 days, to be safe, and blocked that community.

  • @[email protected]
    link
    fedilink
    English
    202 years ago

    I checked and there shouldn’t be any images stored on the server when running lemmy 1.18.4. The post was made in high emotional distress and shouldn’t be taken at a face value. If the posts are bothering you I advise purging the posts in question. (I have already done that)

    • hitagi
      link
      fedilink
      English
      92 years ago

      How did you check this? From my understanding, images from external servers are copied (and transcoded) over locally. At least in my server (running 0.18.4), they do.

      • @[email protected]
        link
        fedilink
        English
        32 years ago

        It depends on how the image posted, the thumbnails might get federated. If the image is used in a post/comment body, usually the thumbnails are not federated.

        • hitagi
          link
          fedilink
          English
          42 years ago

          You can refer to this post. The full image is copied to my instance (and transcoded). Not just the thumbnail.

      • @[email protected]
        link
        fedilink
        English
        2
        edit-2
        2 years ago

        I shut down the pictrs or whatever docker container on my instance so all I host is containers and the database. All the images that I see on my instance are external links. I can check by just looking at the rendered HTML.

        https://files.catbox.moe/vm4yxl.png

      • @[email protected]
        link
        fedilink
        English
        42 years ago

        There is a possibility that my instance is buggy and it isn’t caching images even though it should.

          • Rentlar
            link
            fedilink
            English
            22 years ago

            Let me try to figure this out. The first is a photo uploaded to lemmy.world, the second is a photo originally uploaded to lemmy.nz, both posts are in a federated version of lemmy.world’s shitpost community.

            This is just a theory, but perhaps images hosted on the same server as the federated community will directly link, whereas images uploaded somewhere other than the federated community will be copied into cache, presumably in case the original host shuts down unexpectedly? See if this is the case?

            • hitagi
              link
              fedilink
              English
              32 years ago

              images hosted on the same server as the federated community will directly link

              https://ani.social/post/288601 - This image is uploaded from a user on the same instance as the federated community (lemmy.world) but the image is cached.

              images uploaded somewhere other than the federated community will be copied into cache

              https://ani.social/post/285354 - This image is uploaded from a user on a different instance (lemm.ee) from the federated community (lemmy.world) but the image is not cached.

              The behaviour is pretty weird. Hopefully we can disable image caching/copying-over-locally so we don’t have to deal with problematic images hosted by other instances.

    • JamieOP
      link
      fedilink
      English
      17
      edit-2
      2 years ago

      I’m on 1.18.4, once I deleted the most recent images, the former CSAM posts(among others) became broken images. So yes, it was pulling from local disk cache. Then I took care of the posts themselves after the content was invalidated.

  • Ebby
    link
    fedilink
    English
    92 years ago

    Could someone please ELI5 that script. I’m all for keeping things clean, but old enough to remember the days of console based trolling.

    • UnlimitedRumination [he/him]
      link
      fedilink
      English
      9
      edit-2
      2 years ago

      sudo

      As root

      find /srv/lemmy/example.com/volumes/pictrs/files

      Find files in /srv/lemmy... that:

      -type f

      Are plain files (not directories, symlinks, etc; includes images)

      -ctime -1

      And were created within an amount of time (probably last day, haven’t used this flag in a while)

      -exec rm {} \\;

      For each matching file found execute rm on it (delete it).

    • @[email protected]
      link
      fedilink
      English
      132 years ago

      Looks fairly sane, finds every file in the given directory that was created in the last 24 hours and deletes them. Personally if you are dealing with CSAM I’d be using shred instead of just rm

    • @[email protected]
      link
      fedilink
      English
      72 years ago

      sudo find /srv/lemmy/example.com/volumes/pictrs/files -type f -ctime -1 -exec rm {} \;

      • sudo: run as root
      • find /srv/lemmy/example.com/volumes/pictrs/files -type f: find files (f) in directory
      • -ctime -1: which have been created in the last day
      • -exec rm {} ; execute the command rm (remove) on each of them
      • HTTP_404_NotFound
        link
        fedilink
        English
        6
        edit-2
        2 years ago

        Yup.

        So far, mostly everything appears to work still. But, trying to upload an image, just throws an error.

        SyntaxError: Unexpected token ‘R’, “Request er”… is not valid JSON

        I don’t see a way to actually “gracefully” disable it, but, this works.

        Edit- don’t just stop pictrs.

        Lemmy gets very pissy… and b reaks.

    • PastThePixels
      link
      fedilink
      English
      122 years ago

      Yeah… Just wow. I disabled pictrs and deleted all its images, which also means all my community images/uploaded images are gone, and it’s more of a hassle to see other people’s images, but in the end I think it’s worth it.

      Through caching every image pictrs was also taking up a massive amount of space on my Pi, which I also use for Nextcloud. So that’s another plus!

      • HTTP_404_NotFound
        link
        fedilink
        English
        4
        edit-2
        2 years ago

        Note, apparently, lemmy will get pretty pissy if pictrs isn’t working… and the “primary” lemmy GUI will straight-up stop working.

        Although, https://old.lemmyonline.com/ will still work.

        And- I am with you. My pictrs storage, has ended up taking up quite a bit of room.

      • @[email protected]
        link
        fedilink
        English
        2
        edit-2
        2 years ago

        There has to be a more elegant way of dealing with this in the future, like de-coupling between Lemmy-account hosting (which effectively means acitivypub-fediverse account) and Lemmy-communities hosting.

    • @[email protected]
      link
      fedilink
      English
      172 years ago

      Is this why I couldn’t upload a meme to the Lemmy World servers earlier today?

      Fuck…

      • HTTP_404_NotFound
        link
        fedilink
        English
        82 years ago

        Yup.

        I sent a step further, and commented out the pictrs related configuration from the lemmy.hjson too.

  • krolden
    link
    fedilink
    English
    52 years ago

    That’s it, I’m defederating from lemmy.world. the admins let their users make death threats against users of other instances on top of this.