this post was submitted on 02 Sep 2023
7 points (100.0% liked)
Announcements and Meta
100 readers
1 users here now
A community reserved for communications from the Based Count admin team to its users.
Occasionally we will also hold community polling in here. Make sure to subscribe to not miss any updates.
Everyone is welcome to join the discussion! We accept suggestions on how to run the instance from everybody, including users from other instances.
Posting to this community is restricted to the admin team to avoid spam, however feel free to speak your mind about the status of the instance and how you'd improve it in our [email protected] community.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Yeah I remember that. We lost our first instance to that XSS attack (this one we are writing on is the second one).
And I get why some people might not like Cloudflare, but to my knowledge that's quite literally the only tool at our disposal. These constant attack can be stressing to some admins, it's illegal stuff after all. Even if we are doing everything right and reporting it to the authorities, as soon as I got notice of this I had to drop anything I was doing, jump on SSH and start fixing stuff. This isn't really sustainable in the long run.
I understand. You could roll your own HA proxy but it would be more expensive and wouldnt be able to provide you the inappropriate content inspect CF provides.
If someone is really concerned about privacy they shouldnt be using lemmy to begin with.
I don't really care about caching or load balancing, the only reason I'm considering Cloudflare is that CSAM filter.
That's correct, actually. On one hand, the devs seem so focused on the privacy of users that they often prioritize that over improving the safety of the software (for instance the Lemmy server has next to no logs, apparently for that reason). On the other hand, it's crazy how much data is transferred over federation. For instance, I have already developed a script that allows me to view EVERY post or comment someone has upvoted. The data is all there, wouldn't take much for someone to harvest it en masse and start profiling users.
Us. We hoover-in-mass and profile users.
Next post on [email protected] : Political Compass of every user on the instance according to the AI model we've trained with the data they've unconsciously given to us.
DOWN WITH THE AI! SMASH IT WITH A FUCKING HAMMER!