this post was submitted on 20 Feb 2025
82 points (80.6% liked)
Fediverse
32259 readers
751 users here now
A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).
If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!
Rules
- Posts must be on topic.
- Be respectful of others.
- Cite the sources used for graphs and other statistics.
- Follow the general Lemmy.world rules.
Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Current platforms like Lemmy are NOT ready for massive amounts of users. They have very poor moderation controls, no effective strategy to combat bots, and no money to pay people for it.
The only reason Lemmy is usable right now is because it has nerdy people using it in good faith. If it were to gain critical mass it would collapse under the deluge of trolls and bots.
It's a quaint little place, and I like it for being that.
And it has enthusiasts running and moderating things that are just about able to keep up with the userbase.
It wouldn't take much more to be overwhelming.
I'm actually not sure how federated lemmy hasn't already been destroyed. Wouldn't it just take one bad actor to start spamming all the other instances with nonsence? If you deferate with the instance the bots are coming from they can just open another, right? Like a DDOS attack
In principle yes, one bad actor could start spamming a lot. But they usually get banned pretty quickly.
Well, you'd need a new domain so at least you're forcing the spammer to spend money on a new domain, which probably breaks most of these attempts. Also if the spammers are really bad or posting illegal stuff and they're registering domains, you could maybe report them to their domain registrar and possibly get them to shut them out or maybe even get law enforcement involved to figure out who registered the domains.
As a last resort, you could go to allowlist federation, where you are by default not federated with an unknown domain.
Thanks for the explanation. Yeah, many domains being required probably is annoying / prohibitive enough to stop distributed botnet attacks.