1
 
 

cross-posted from: https://lemmy.ca/post/67952523

This is the first big step in the process to develop comprehensive guidelines for the Fedecan non-profit and the various platforms.

While this will mostly involve converting tacit knowledge and experience into an explicit written form, we expect that this process will inevitably bring up some points of disagreement on the best way to deal with different issues. We ask everyone participating in these discussions to please contribute constructively and in good faith. We encourage you to bring up any concerns or issues you have with the proposed structure and drafted guidelines, so that we can work together to fix them early on. However, in order to keep a productive environment for those discussions, we will be pruning any comment chains that devolve into personal attacks, slap fights, etc.

To help ground your feedback, consider these thought experiments when evaluating a potential guideline:

  • Veil of ignorance: Would it still feel fair to you if you switched places with someone else on the platform (ex. a new user, a moderator, an admin, a member of a vulnerable group, etc.)?
  • Equal Applicability: These rules will be enforced uniformly on everyone. A poorly written rule that helps "your side" today, can easily harm "your side" in the future as circumstances change.

The full guidelines, including governance details like the annual review cycle, can be found on the website: https://fedecan.ca/en/guidelines/

We plan to structure the guidelines as follows:

diagram of the tiers that are described below

Tier 1: Fedecan Rules

Internal Conduct

These rules apply to Fedecan team members (directors, officers, admins, and anyone with elevated access). They set expectations for how team members should act.

Universal Rules

These are the baseline rules that apply to every user on every Fedecan platform. They cover the things that are prohibited by Canadian law (threats, hate speech, CSAM, non-consensual intimate imagery) as well as universal policy rules (privacy/doxxing, harassment, fraud, content that could cause harm, labelling of sensitive content, etc.).

Tier 2: Platform-Specific

Each platform has different functionality and norms, so this is where we can be more specific with the rules. The threadiverse platforms (lemmy.ca, piefed.ca, sh.itjust.works) share similar rules around community creation, moderation, vote manipulation, and content labelling. Pixelfed has its own rules tailored to its platform.

Tier 3: Community-Level Rule Templates

These are optional templates that communities can link to, or use as a starting point for their own rules. The idea is that moderators can point users to a clearly written explanation of why a rule exists, and any relevant exceptions, rather than trying to fit everything into the sidebar. Additionally, if many communities are enforcing a particular rule in the same way, then users will have an easier time understanding and following them.

The post title standards template has been drafted, and we plan to add more as the need arises. I have a few others that are in the works, but they have some overlap with the other sections, so I thought that it would be better to let people discuss first.

2
 
 

Here it is, the update I've been promising you for some time.

When I first started this instance, I wanted a place where people could come together and share their experiences, knowledge and start discussions about the things that mattered to them. A place that was not driven by corporate greed but instead by its users.

In the early days of this instance, I founded the community /c/Agora to serve as a platform where users could openly discuss instance or fediverse-related matters and advocate for improvements and changes they would like to see. I want to put emphasis on the fact that this instance belongs to all of you, now and in the future.

Most of you know that since the start of this instance I've been personally funding the costs associated with it. While a lot of you have been generous enough to ask for ways to contribute over the last year, I haven't allowed it. This reason was mainly related to time and in no rush in making donations my top priority. Over the last few months I've reflected and come to understand that for this instance to truly be about its users, it also needs to be funded by them. Today I am taking the first step by sharing more details regarding the costs associated to running this instance and sharing with you all platforms that you can use to donate towards keeping this instance running.

So here it is. I've broken the rest of this post in the following sections. Feel free to jump to whichever section are most important/interesting to you:

  • Current running cost
  • Wishful 2025 budget
  • Donations platforms
  • New announcement community
  • New front-end available
  • A special thanks

Current running cost

Note: Some of these items are paid yearly however to keep things consistent I've broken it down monthly The running costs includes everything that relates to keeping the lights on. The time the admins and moderators put in keeping this instance decent is all volunteered.

Service Description Monthly Cost
1U Server Colocation Bandwidth, Power and Space $99
Domain Name The just.works domain $4.66
Image Hosting Object storage used for the images $8.25
Email Account Used by me solely for instance related communication via email (ProtonMail) $7
External Backups Remote Backups of the entire instance $20
Hardware Repairs For the eventual drive failures. (This might need to be adjusted in the in future) $15
Total $153.91
*All amounts are in Canadian Dollars

This break down is quite conservative but as this instance continues to grows, so will its costs. I've already had to replace a drive and a power supply since switching to the new server. The current breakdown doesn't leave much room for improvements. If we get enough donations, here's what I'd do with the extra money throughout 2025. The focus is around speed, stability and general site availability. I look to do this by implementing a more robust disaster recovery strategy, add extra resources for new future hosted services and switch to a proper external email sending service to address some delivery issues during waves of new accounts.

2025 Budget

Service Description Monthly Cost Yearly Cost
1U Server Colocation Location 1 $99 $1200
1U Server Colocation Location 2 $99 $1200
Remote PBS Backup Location 3 $20 $240
Domain Name The just.works domain $4.66 $55.92
Image Hosting Object storage used for the Images $8.25 $99
External Email Sending Service Email Delivery Service $15 $180
Email Account Used by me solely for instance related communication (ProtonMail) $7 $84
Hardware Repairs For the eventual hardware failures $30 $360
Total $282.91 $3,418.92
*All amounts are in Canadian Dollars

Donations

Its taken far longer than anticipated, but it’s finally here! 🚀 For now, I’m launching with two donation platforms: Liberapay and Ko-fi. If there’s demand for additional options, I’ll gladly expand in the future.

Where your donations go:

  • 💻 Keeping this instance running smoothly (see Current running costs)
  • 🔧 Funding improvements and new features

Community-driven priorities:
You can shape how extra funds are used. Join the discussion in the /c/Agora community—your input matters!

My commitment:
I’ll personally cover any funding shortfalls to ensure this project thrives, no matter what.

Thank you for your support!

New Announcements Community 📢

As this was posted we came across a bug related to local only communities. We will circle back on this once a fix has been implemented.

We'll be moving away from the /c/main community for posting future announcements moving forward. Instead we'll be using the /c/announcements community. The community has been restricted to only allow posts from admins. Be sure to subscribe!

New Tesseract front end available

One of our members @CaptDust@sh.itjust.works raised a discussion in the /c/Agora to introduce a new lemmy front end called Tesseract. I've went ahead and added this front end for all to use. You can access it from here: https://tesh.itjust.works/

A special thanks ❤️

It wouldn't feel right if I ended this post without taking a minute to thank and appreciate the admins for all that they do on this instance and the fediverse. @InEnduringGrowStrong@sh.itjust.works @kersploosh@sh.itjust.works @imaqtpie@sh.itjust.works thank you for your support, volunteering your precious time and continued dedication in keeping this a place running smoothly for many that call it their home. I'll always be in your debt!

3
submitted 4 days ago* (last edited 4 days ago) by to c/main@sh.itjust.works
 
 

cross-posted from: https://sh.itjust.works/post/63880645

Issue: Tesseract has a hardcoded hidden instance blacklist, and an even more obfuscated censorship list of various users, instances, communities, and general regex matches.

Also /c/modabuse. Also /c/yepowertrippinbastards. Also lemmy.ml/c/worldnews, comrade, ACAB, and 552 individual accounts across 67 instances, about half of them on lemmy.world.

None of this is in the source code. It's downloaded at runtime from a file nobody has ever looked at.

If you're just tuning in

Tesseract is a third-party web frontend for Lemmy, maintained by asimons04 and licensed AGPL-3.0. Admins deploy it on their own servers alongside or instead of lemmy-ui, and there are public instances of it people use to browse Lemmy generally. If you've used a Lemmy site that didn't look like stock Lemmy, there's a fair chance it was this.

Last week db0 posted a PSA: Tesseract contains a blacklist of instance domains compiled directly into the application. 32 of them. Admins can't see it, can't configure it, and aren't told it's there. Connect to a listed instance and the app tells you it's "incompatible," which is not true.

I went through the code to see how that was implemented. The hardcoded list turns out to be the small half of the system.

There's a second filter policy fetched over HTTP every time the app loads. It isn't in the git repository. It's unauthenticated and world-readable, so anyone can pull it. Right now it carries 552 user accounts, 2,275 username patterns, 54 instances, 97 communities, 289 keyword patterns and 351 domains, with every category set to hide matches rather than flag them. Not collapsed behind a click. Simply absent, with no indication anything was removed.

Verify all of it in ten seconds

curl -s https://tesseract.dubvee.org/tesseract/api/system/policy \
  | base64 -d | gunzip > policy.json

That's the live policy, base64-wrapped gzip, 111KB of JSON when it unpacks. There's a stale fallback copy at /data/policy.dat as well.

It filters criticism of moderators

  • lemmy.sdf.org/c/modabuse — listed
  • lemmy.dbzer0.com/c/yepowertrippinbastards — listed
  • lemmy.dbzer0.com/c/YPTBcirclejerk — listed
  • community regex power ?tripping?
  • keyword censoring me

Call the rest of it whatever you like. This part is not spam defence.

It filters words

The 32 community name patterns include Communis(t|m), Conservativ(e|es|ism), Leftis(t|m), Libertarian(ism)?, ^Green Part(y|ies), Zionis(t|m), (Police|Cops), guillotine and billionaire.

Keywords include comrade, ACAB, neoliberal, proletaria(n|t) and death to.

Filtered communities on instances that aren't blocked: lemmy.ml/c/worldnews, lemmy.today/c/news, lemmy.ca/c/politicalnewscanada, lemmy.ca/c/usa, infosec.pub/c/strategic_unions.

The 552 users aren't bots

67 instances. 272 on lemmy.world alone, 40 on sh.itjust.works, 19 on lemmy.ca, and 28 instances contributing exactly one person each.

355 of the 552 usernames are plain alphabetic, twelve characters or under, median length eight. Only 36 look like spam registrations. A bot list looks like the opposite of that.

Seven of them aren't even Lemmy. There are Mastodon and Friendica accounts in there: people who have never used Lemmy, hidden by a Lemmy frontend, with no possible way of finding out.

I have the list and I'm not posting it. Most of these are ordinary people who got pattern-matched, and 552 names on this comm is a harassment target inside an hour. Run the command above and grep for yourself.

And it lies about it

When the instance block fires you get: "Incompatible Instance. Not Supported. $instance is not compatible with Tesseract."

Nothing is incompatible. It's a policy decision dressed as an API error, and it's what had db0 chasing a version mismatch that never existed.

For the hidden users, communities and keywords, you get no message at all.

Admins can't switch it off

Tesseract has env vars for PUBLIC_DOMAIN_BLACKLIST, PUBLIC_FAKE_NEWS_BLACKLIST and the shortener lists. There is none for either blocklist. enableToxicMode bypasses the other filters and explicitly not this one.

Self-host it and you cannot disable this, nothing in your config admits it exists, and the contents can change without you pulling a commit.

Before someone says it

A lot of that domain list is real spam defence. It filters conservatism as well as communism. "It targets the left" doesn't survive the data and I'm not going to pretend it does.

The problem is that spam filtering and political editorial got welded into one undocumented, remotely-updatable blob, shipped hidden, to admins who've never read it and users who don't know it's there. The spam work is what makes the rest unauditable: "it's a spam list" answers every individual question and none of the whole.

And /c/modabuse is not spam.

Asks

  1. Publish the runtime policy in the repo, or kill the endpoint.
  2. Stop reporting a policy block as a technical incompatibility.
  3. Tell users when something's been hidden. One line.
  4. Give operators an off switch, like every other blacklist in the codebase has.

It's AGPL-3.0 and db0 already forked it. That's the licence working as designed. But forking isn't disclosure, and the admins who need this are precisely the ones with no reason to go looking.

If you run Tesseract, you are relaying a 111KB moderation policy you have never read, under your instance's name, to users who don't know it exists.

I disagree with some of the assertions put forth above about it not targeting the left, etc. And I don't think the asks is relevant, because we should no longer be trusting anything from this person.

Policy file here, for archival purposes: https://file.garden/amIRhTctI0qld2r5/policy.json

4
 
 

If so, what are the coords? I can't find it on the mega-template.

5
 
 

I just posted my first band interview with a bunch of pics.
https://sh.itjust.works/post/63544454

I'm pretty sure my graphics, while definitely not hi-rez, are too big. I'm choking the system when I upload them, and they don't render during page view very well either.

I'm just taking pics with my crappy cell phone.
I upload them by opening the pic in MS Paint, select all, copy, and then paste it directly into the post.

Just given the results I've had so far, and my intent to post a LOT more pics, perhaps I should tune this process up.

How would you do it?

6
submitted 1 week ago* (last edited 1 week ago) by to c/main@sh.itjust.works
 
 

My app (Thunder) has been having issues connecting for the past few hours, while the website has been up and running. Just wondering if anybody else is having issues.

Also not having any trouble connecting to other instances, just this one.

Edit: Seems to be back

7
submitted 1 week ago* (last edited 1 week ago) by to c/main@sh.itjust.works
 
 

What's the detail with YouTube videos on this instance?
If I'm on this instance, videos in a post don't render. Instead I see a big black window with this error text.

Watch video on YouTube
Error 153
Video player configuration error

You can just right click the link and go to youtube to see it, its not a complete disaster.
I do sort of need to figure this out tho. I'm doing my best to mod a music comm, so the videos are pretty important.

I've tried testing from other instances ... and there's no problem. I have accounts on eviltoast.org (regular lemmy) and moist.catsweat.com (mbin). No problem viewing those same posts from either of those instances. I didn't even notice the issue until I started using my sh.itjust.works account regularly.

It doesn't seem to matter who made the post or how old it is. When I'm logged into my sh.itjust.works account, all of the youtube posts show the black window.

I normally use firefox+adblockers, but I have sh.itjust.works whitelisted in ublock. I've also tested in my completely clean Vivaldi.

I've tested from various machines. I consistently see the empty black window only when I'm viewing these posts through the sh.itjust.works instance.

I'm a newbie mod, but this is not even a mod thing. I'm just reading a post here. Basic internet stuff. Got any help for me?

8
 
 

This is the first time I'm experiencing downtime for this instance, so I appreciate that a lot. Is anyone else currently experiencing troubles? Anyone know what is going on?

9
 
 

I like posting to stoner_rock@sh.itjust.works.
It has subscribers, I'm not the only one there, but it's been a bit stagnant. I think it could use a cleanup, maybe people might be more interested in it if there was more going on.
I'd like to adopt the com and do a few things with it.

The mod is niladmirari@sh.itjust.works. They last logged into lemmy 2024 and only ever posted a few things.
I messaged them, and was unsurprised to get no reply.

Do I need to have a sh.itjust.works account? I could sign up for one if that's the case. I have 2 lemmy accounts already, and didn't really want a 3rd, but if those are the rules, that's fine.

I expect this to be an uncontroversial request. I clearly use the comm, and its clearly abandoned.
Give me some feedback here, and I'll take whatever next steps are needed.

10
11
 
 

All the image files on there are down. It says they'd be shutting down on July 2nd... it's not even June and nothing submitted to them shows up on any other end. I swear, every time I think I have more time to do something, someone unprovokedly immediately reveals this to be untrue.

12
 
 

since about yesterday I can't see my own posts on lemmy.world or lemmy.blahaj.zone subs when I go to my accounts on those instances. Is this happening for anyone else?

I don't see an announcement for maintenance or anything 🤷‍♀️

post for example:
https://sh.itjust.works/post/59231797 (lemmy.world)
https://sh.itjust.works/post/59232374 (lemmy.blahaj.zone)

13
browse all (sh.itjust.works)
 
 

>by default blasted with bot copies of porn subs from leddit, including pedobait ones like barelylegalteens

what did the instance admins mean by this

14
delete comm (sh.itjust.works)
submitted 4 months ago by to c/main@sh.itjust.works
 
 

Howdy are you able to delete this comm:

https://sh.itjust.works/c/usgreenlandwar

thanks

15
 
 

not sure if this is an issue just with this instance, or a general lemmy problem.

I have the options "Open links in a new tab" checked, but nothing ever opens in a new tab. this has been a problem for me for almost 3 years on this instance. i just assumed it would be fixed in an update some day.

using firefox on debian, if that makes a difference

16
submitted 5 months ago* (last edited 5 months ago) by to c/main@sh.itjust.works
 
 

I'm new to Lemmy, days not weeks. Liking it so far and I'm trying to contribute in a positive way to the instance.

I have one usability issue, trying to figure out which replies in a post are new since I last read it. I see the number like (4 New) telling me how many, but not which.

Sorting by "New" hardly helps because of the threaded display. Threading is a good thing, IMO, since it preserves the flow of the conversation. But new replies to older replies get buried with a "New" sort. When the post has only a few replies total, I can keep up simply by re-scanning the whole thread. On more popular posts that becomes infeasible.

Please don't beat me up too bad if I'm missing an obvious thing! I saw the user settings, "Show Read Posts", but that seems to be post level, not reply level.

Editing because I am an idiot: I use the web interface through https://sh.itjust.works/.

17
 
 

Do SJW and Fedecan have an explicit commitment not to store user data in the United States? If not, is that technically feasible given the hosting available? Just to be clear, I’m not asking about data that’s obviously published (e.g. posts), but data that’s private (email addresses, IP address logs, etc). Thanks!

18
 
 

Hello - I am wondering if there are any alternative frontends for sh.itjust.works on desktop.

Sorry if there is a list available somewhere already!

19
 
 

seems to be a lot of them on this instance lately, saw one earlier as well (now banned)

20
 
 

The latest upgrade has a ton of features I would love to use on lemmy. There must be a reason we backtracked, I was wondering what it was and if there was hope for an upgrade in the near future?

21
 
 

For me at least, for months now, this instance is unavailable for multiple hours a day. Given the recent posts about the lemmy eco system being on a slight downwards trend, I don't think this additional load is caused by more users using this instance. Rather, I think that AI scrapers are using this instance to scrape lemmy. If I am correct, though only someone with access to the logs can check, I'd like to kindly ask for some sort of protection from AI scrapers. Both because I like being able to actually browse the instance and because I hate AI companies.

22
 
 

We will be closing the census this week, on January 15th, 2026.

Link: https://survey.fedecan.ca//s/cmjcnqzgd0002th01dh6naqm6

A lot has changed since our last census in 2023! We would like to take another opportunity to learn about our growing community.

Everyone is welcome to fill out this survey! While this census is being run by the admins of lemmy.ca, sh.itjust.works, piefed.ca, and pixelfed.ca, you do not need to have an account on these instances, and you do not need to be located in Canada. If you do have an account on one of our instances, you can indicate that on the census to be included in those separate graphs/visualizations.

No question is mandatory. You may skip any question by either selecting “no answer (skip this question)”, or by leaving the question blank.

Some questions will be hidden depending on your selections. For example, the Pixelfed specific questions will be hidden if you don't select that as one of the platforms you use.

Sections:

  • Section 1: Location
  • Section 2: Demographics
  • Section 3a: Instance Usage (Forum/Threadiverse)
  • Section 3b: Instance Usage (Pixelfed)
  • Section 4: Feedback / Closing questions

When results are ready, we will share them on our website and with posts on the main/meta communities in our instances.

The questions were created with help from @Dave@lemmy.nz, based on the questions from their census this year. The banner image was made with icons from flaticon.com.


Due to some issues with the survey platform, you won't be able to click on external URLs while completing the census. You can access those links here:

23
 
 

Piefed is starting to look more attractive in comparison with lemmy. While it's missing some features I'd like, it's also got a lot of new stuff that lemmy doesn't have, and it's progressing a lot faster. I know several major lemmy instances have set up a piefed as well, do we have any plans to do so?

24
like as green umbrella (sh.itjust.works)
submitted 6 months ago by to c/main@sh.itjust.works
 
 
25
happy-happy new years ya (sh.itjust.works)
submitted 6 months ago by to c/main@sh.itjust.works
 
 

selamat menjalani kehidupan baru.

view more: next ›