Hi, I have noticed for three days now not being able to post comments from my Lemmy.world account while connected via Tor (I was left waiting for a spinning wheel )! I thought at first It might be a problem with LW servers but after three days, I concluded they are banning Tor and VPN users from posting, I Have found a user post on their help community about VPN and tor ban.

then I tried signing-up to lemm.ee but was greeted with a couldflare of non ending page reload after solving captcha. so I created this account hoping to test this instance and ask Lemmy users with privacy concerns about where this is headed and should we expect the rest of Lemmy instances to go the way of reddit and entirely ban users behind proxies ?

The fact that very big instances hold the majority of the communities and discussions on lemmy and the fediverse in general is concerning. and adopting tactics like shadow banning and dark patterns is concerning as well. I dropped reddit for the same practices and I will drop Lemmy if it carries on like this.

44 points

I’d be shocked if the dbzer0 (piracy) instance blocked it.

I’d also expect that this has more to do with cloudflare than the specific instances.

permalink
report
reply
2 points
Deleted by creator
permalink
report
parent
reply
37 points

Lemmy.world had announcement a while ago that they won’t support creating content with VPN and Tor due to CSAM spam that is going on

permalink
report
reply
10 points

It’s limited to voting and commenting right?

permalink
report
parent
reply
11 points

posting and commenting.

voting should work: https://lemmy.world/post/11967676

permalink
report
parent
reply
4 points

Though I know what this is for, but I am against blocking VPNs and Tor since it prevent privacy-conscious people like me and other people such as dissents or other having high risks of like harassment online.

The instances being affected the most are those with open registration, and don’t block registration from temporary email providers, and have don’t have like automatic filter or using Fediverse softwares not providing such.

Though given Lemmy development may not support blocking registration by emails or filtering keywords or filtering federation of very new accounts/new account having no profile, manual approvement registration or applying bots filtering repeating spams may be enough without blocking VPNs or Tor I think

permalink
report
parent
reply
1 point

I’m also against blocking proxies, but we the privacy minded folks are a minority that actually uses vpn or tor for everyday internet browsing. There are lots of bots and malicious actors using our resources to spam large instances, and if I were managing a popular fediverse instance, I too would have been forced to consider blocking vpn/tor, even if I didn’t want it.

permalink
report
parent
reply
20 points

then I tried signing-up to lemm.ee but was greeted with a couldflare of non ending page reload after solving captcha.

That particular instance was very recently the source of a lot of CSAM and spam, so that’d be why. A lot of instances recently upped their security to combat that.

There’s nothing forcing anyone to use those services, but the reality is that instances that aren’t quick to respond to those kinds of incidents will get defederated.

Cloudflare is a lazy but very effective and economical solution to this. The alternative is staff to monitor everything that goes through 24/7 which for most instances isn’t easy or possible. Many can barely afford the infrastructure costs.

The fact that very big instances hold the majority of the communities and discussions on lemmy and the fediverse in general is concerning.

It’s concerning regardless of the whole proxy banning debacle. A healthy fediverse is a well spread out fediverse.

But I doubt all instances will ever be that way. You don’t need a lemmy.world account to use lemmy.world’s communities, any instance would do.

My instance for example doesn’t use Cloudflare or any CDN, although it is invite only because I really don’t have time to deal with moderation. But I can access it over Tor if I want, and you can access it over Tor and browse it (read-only) just fine.

Reddit on the other hand wants to keep the data for themselves. Their VPN, Tor and proxy block isn’t just for posting, it’s for reading too and that is a much worse problem. They want to hoard the data so they can train their own Reddit AI on it. On lemmy you’ll always have at least read access to the platform through Tor and VPNs through random instances.

At least on Lemmy, a fully featured Tor hidden service instance is entirely possible, if someone is willing to vet the account getting registered and potentially malicious uploads. And anyone can make it happen.

permalink
report
reply
7 points
*

That particular instance was very recently the source of a lot of CSAM and spam, so that’d be why. A lot of instances recently upped their security to combat that.

Just to add some more context, there was an attacker recently who created accounts on several Lemmy instances and used those accounts to spread CSAM. On lemm.ee, this attacker created 4 accounts over a 24h period, but was not able to upload any CSAM to our servers due to our stricter upload rules (we require 4 week old accounts to upload any images at all), and all of the 4 accounts were removed very shortly after creation (most of them within an hour of signing up). The attacker gave up trying to use lemm.ee very quickly, and moved on to other instances.

I just wanted to share this context to illustrate that while indeed the different measures we implement to protect the instance can have a negative impact on legitimate users, I really believe that overall, they have a net positive effect. In addition to Cloudflare DDoS protection and image upload restrictions, we also have a separate content-based alerting layer on top of Lemmy, which allows our admins to quickly notice when something suspicious is going on. As another example, this alerting has allowed us to extremely efficiently deal with a current ongoing spam attack on the Fediverse, and I bet many lemm.ee users aren’t even aware of this attack due to the quick content removal. We will continue to improve our defenses, and hopefully try to limit the impact on real users as much as possible, but some trade-offs are necessary here in order to protect the overall userbase.

permalink
report
parent
reply
18 points
*

I think using Cloudflare isn’t very Fediverse.

You probably need to find a different instance.

permalink
report
reply

You can filter out instances behind CloudFlare on my internet web site, https://lemmyverse.net 😁 Choose the tags filter, and remove CloudFlare!

permalink
report
parent
reply
14 points

I am posting on lemmy.ml and piefed.social via Tor browser without issues.

permalink
report
reply
5 points

Yes, I am exploring other instances right now, I can post from sh.itjust.works fine, but I kinda arbitrarily disconnects me from time to time, It must be a bug. will check other instances if needed.

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 4.5K

    Monthly active users

  • 2.9K

    Posts

  • 77K

    Comments