End Networked Harassment
A California 501(c)3 non-profit started by @lizthegrey.com, @binaryvixen899.bsky.social, and @remembrancermx.bsky.social to stop networked harassment groups from targeting vulnerable individuals.
EIN 99-4544633 / CA reg no 6351204, IRS DLN 26053720002634
- [Not loaded yet]
- Thanks! -ACL
- Our 501(c)3 determination letter came through, so we can finally say that we are tax-exempt and eligible to receive charitable contributions (although our present financial needs are covered by @lizthegrey.com). You'll see the details updated in our bio as well. drive.google.com/file/d/1-otV...
- [Not loaded yet]
- [Not loaded yet]
- Thanks! Atm it is suspended :) -ACL
- Curious why our blocklist often shows as empty? It's because @safety.bsky.app is doing their job. Suspended accounts are removed from the list, and sometimes removal-flagged but not yet fully suspended accounts cause list rendering to choke partway through displaying the list.
- I know people are ragging on @safety.bsky.app but they're doing 1 thing right: KF accounts are often being suspended within minutes of creation; sometimes by the time I go to add one to @endharassment.net's blocklist it's already been suspended. Or I'll check back 30 min after adding and it's gone.
- Thank you! That account has since been suspended. -ACL
- So, let's talk about why a bunch of KF accounts are popping up on Bluesky to begin with. What they're doing is target hunting, and the signal they're looking for is reactions. They're looking for reactions because, spoiler alert, there are not as many of them as they would like you to think. -ACL
- [Not loaded yet]
- Thanks! That account has since been suspended. :)
- [Not loaded yet]
- This is because Bluesky's Moderation team is very good at banning the accounts. When banned they drop off the list. -ACL
- FYI: I would not read this if you're in a good mood. en.wikipedia.org/wiki/Kiwi_Fa... -ACL
- But yeah, KF is abbreviation for Kiwifarms, Kiwifarmer, etc. Takes less characters. -ACL
- [Not loaded yet]
- "Hunter-Killers. Patrol machines built in automated factories. Most of us were rounded up, put in camps for orderly disposal." -ACL
- [Not loaded yet]
- Got it! Thanks!
- [Not loaded yet]
- Just block them, and if you'd like to be helpful, privately report to your local labeller or blocklist operator (using the reporting or DM functionality) if they're not already appropriately tagged. -LF
- Why you don't give bad actors ideas for things to do: en.wikipedia.org/wiki/WP:BEANS Yes, there is now a false flag operation going on, it's by the same group of people operating the original KF bots, just keep blocking and reporting them. -LF
- We've now seen our first one, but believe they started using the OF name in response to @skysentry.bsky.social's thread rather than because it was happening before. Username is 3qhaghg similar to other accounts starting with 3... that were KF branded before. DID: did:plc:cgdonyyvdutfshmnnbeti2js -LF
- [This user deactivated their account]
- Listed already. -LF
- [Not loaded yet]
-
View full threadWe've now seen our first one, but believe they started using the OF name in response to @skysentry.bsky.social's thread rather than because it was happening before. Username is 3qhaghg similar to other accounts starting with 3... that were KF branded before. DID: did:plc:cgdonyyvdutfshmnnbeti2js -LF
- We saw the profile update go live in our monitoring at 12:45pm Pacific & internect found it at :47; moderately confident it's a false flag by the same party that was creating the 3... accounts with 7 characters in name previously that said "you are being watched" or "like = you're on the list". -LF
- [Not loaded yet]
- You can always use the API or browser devtools to look at the list of returned accounts that come back via the REST API, but yeah, it's not great that blocklist contents are harder to audit and inspect for the moment. -LF
- [Not loaded yet]
- It chokes as soon as it encounters the first suspended account in the list, from most recently added to least, and then fails to show any further accounts. I know, it's painful and sucks! -LF
- [Not loaded yet]
- [Not loaded yet]
- Obviously we'd rather there not be bugs, but we can see the silver lining that it's happening frequently because it means the reports we're filing are being actioned, and quickly! -LF
- [Not loaded yet]
- Yes, it's partially suspended but not deleted yet accounts. -LF bsky.app/profile/endh...
- (wva..pu6 is the account you had posted the screenshot of, and we believe it to be a parody account mocking onionfarms claiming all-genders welcome) If you are happening to see a wave of OF profiles being created, please let us know the DIDs so that we can fix the bug in our monitoring scripts! -LF
- Meanwhile, we believe the attack continues under the previous pattern, obviously referencing KF. see for instance recent addition to our blocklist: did:plc:rb3lo3robspgbb7u44rteaip
- [Not loaded yet]
- Oh, sorry! Yup, will update advice if we put out a further honeypot. -LF
- With respect, we do not appear to see a wave of OF account profile creations/changes; did:plc:wvapc4ldgjh24paaotnvtpu6 is now suspended. our profile changelog says other than the pre-existing @/onionfarms.bsky.social account there are no accounts on the site named onionfarms or being created. -LF
- [Not loaded yet]
- [Not loaded yet]
- This is a test/honeypot, do not interact with it unless you are from kiwifarms. We are incredibly trans and incredibly gay and incredibly proud.
- This is where our name comes from: we are survivors who aim to end the phenomenon of morally motivated networked harassment through education of the general public and of the service provider ecosystem. We're here to serve those communities impacted by networked harassment however we can. -LF
- And they introduce the concept of "Continuous Narrative Escalation", whereby a group of harassers craft a story together about why someone deserves to be harassed. This builds on the great work by @alicetiara.bsky.social on morally motivated network harassment (journals.sagepub.com/doi/full/10....)
- [Not loaded yet]
- They're being suspended by bsky after being tagged and reported. -LF bsky.app/profile/endh...
- [Not loaded yet]
- Kiwi Farms. A networked harassment site. -LF
- [Not loaded yet]
- The list shows empty sometimes when an account has been soft-suspended (but not yet removed/deleted) by bsky and thus its profile information cannot be displayed. It is indeed a bug. -LF
- [Not loaded yet]
- Thanks, the former was suspended already, the latter we just added. -LF
- [Not loaded yet]
- In this context, it's a bot account whose display name or banner has the name of a particular networked harassment site whose initials are K.F. in it, causing people who see the account to potentially believe the site is personally watching or targeting them for further harassment. -LF
- We've compiled a blocklist in case you'd rather not see them at all*. But you don't need to use the blocklist to be safe (if they wanted to screenshot you, they could anyway). Ignoring them denies them attention and they'll get bored. -LF *a few may slip through between creation/detection/listing
- It's natural to feel afraid or worried from such an interaction. If you are, process those feelings with a friend or trusted person in private, rather than in public view where your misery can become grist for someone's sadistic pleasure or, worse, an excuse to further harass and abuse you. -LF
- The best way to not end up on their radar is to deny them the satisfaction of them knowing that you've noticed them, or that their automated bot is making you feel unsafe. It has liked 100s of posts in an hour; they can't & won't focus on you specifically unless you tell them the attack worked. -ACL
- Either: it's just a bot trying to jumpscare you, or you've already been screenshotted/archived. The correct action is the same for both: block and move on. You may be tempted to lock down and delete your profile, but if you do they're likely to take the clawback as an indication to push further. -LF
- They're also not as good at what they do as they would like you to think. The vast majority are lazy. They ARE dangerous, but they are opportunistic. The best thing you can do is to not publicly freak out or react if a KF account likes your tweets, follows you, or DMs you. Block them, move on. -ACL
- Now this doesn't apply to everyone they target, unfortunately. It is sadly true that for some folks, they can ignore KF and "keep their heads down" all they want and KF will still go after them just as doggedly, if not more so. But those folks have a higher risk of being targeted to begin with. -ACL
- [Not loaded yet]
- [Not loaded yet]
- Our blocklist is a list of folks affiliated with KF or using their shibboleths in connection with harassment. While I sympathize deeply with what you're saying, after speaking to her we determined having her on the list would be inaccurate and inappropriate as she is not affiliated with KF. -ACL
- [Not loaded yet]
- Listed already, thanks. -LF
- [Not loaded yet]
- [Not loaded yet]
- Not if you only want to follow and like but not post. That's the loophole that means they can supply non-existent email addresses and still jumpscare people. -LF
- [Not loaded yet]
- [Not loaded yet]
- It's an impersonator (you can tell by account age / having made 0 posts). They rename to an existing account and reskin once caught. -LF
- [Not loaded yet]
- They renamed _because_ we caught them and added to blocklist. Already listed, but thanks for reporting! -LF
- [Not loaded yet]
- [Not loaded yet]
- They're impersonating you now, having renamed to @/u1veon.bsky.social (still did:plc:lpxqy4prynl34j33ei62yrit). Seems they copy the profile of the first person they interacted with. -LF
- [Not loaded yet]
- it also shows all brand new accounts as having recently changed, which is technically true but not helpful wrt FP rate for malicious changes. -LF
- [Not loaded yet]
- [Not loaded yet]
- You'd be surprised how far our automation has gotten since a few days ago. -LF
- [Not loaded yet]
- [Not loaded yet]
- internect.info works well in the meanwhile.
- [Not loaded yet]
- They also have a habit of renaming/reskinning to impersonate an existing legitimate account (per our pinned post) the instant they're detected. -LF
- [Not loaded yet]
- The earlier one is already suspended, bsky team is fast (when their detection works correctly)! -LF