Skip Navigation
hexbear @hexbear.net

we fucked up

If any users have purchased domain names they can transfer to us now, or share the account credentials for the domain host please message me so i can add the domain you have to the list of options for a domain change.

Hello users of hexbear, or shall i say chapo.chat, we fucked up, and i fucked up like three times making this post.

Yes, hexbear.net has expired. Yes, we were aware of this possibility. We have gradually lost contact with the access owner (prior admin) for the domain registration. We attempted to make a migration plan, but we were disarmed by the reappearance of the party in question in September 2024 and repeated assurances that they would a) transfer credentials and b) continue payments until they were able to do the former.

We accept full responsibility for this. We should have been more aggressive about this and continued our alternative despite these reassurances. This is our fuck up, and we can't offer anything besides our continued apologies and our plan of action going forward and an explanation of what happened:

Over the time of chapo.chat and hexbear.net the admins that purchased the domain, established the donation accounts, and the server accounts have left. One of the primary admins has gone inactive and returned many times, over a year ago some of the newer admins began asking the older admins to give full access to the domain, servers, and donations. These requests were not met, despite warnings of this exact event.

At the moment we do not have access to hexbear.net and there is a strong chance we will not get it back without participating in the auction, which is already over $300. Choosing to abandon the hexbear.net domain will cause federation problems and considerable technical issues which would lead to potential extended downtime.

During this downtime we would be reestablishing access to the new domain (or hexbear.net if we win the auction), access to server ownership, and donation accounts. This would be distributed among a number of admins so that we can prevent this from happening again.

Chapo.chat has the same access problem that led to the current state of hexbear.net so it is to be considered temporary.

I will do my best to answer questions

1.1K comments
  • Pinning @piggy@hexbear.net comment:

    True Hexbear Fedayeen have hexbear hard coded in their hosts file and are currently enjoying their

    On OSX/Linux just add 37.187.73.130 hexbear.net to the bottom of /etc/hosts and you'll get your

    back.

    On Windows its at C:\Windows\System32\drivers\etc\hosts

    On Phones it's much harder so all your

    are lost.

  • Please reply to this comment with name suggestions in the event we have to change from hexbear.net

    We will make a new thread to vote on names shortly.

    The main options are:

    Use a name similar to hexbear.net (like hexbear.chat, h.exbear.net, etc.) while we look at options for recovering hexbear.net

    or

    change to a new name.

    For ease of transfer we cannot accept domain-names that are currently available to purchase, or ones that cannot be transferred or ones where the owner wanting to donate cannot give the credentials for the domain-host account.

  • Call me silly, tell me to touch grass, but hexbear has been a big part of my life for a few years now.

    I don't want to see anyone go away, and i have faith we'll be back up in whatever form before long. Yall have given me so much over the years, and been by my side as I grow, through all my ups and downs.

    Idk, feels like i had more to say, but lost my train of thought. Outside hangin with the corgi rn.

    I love you all, and can't wait until we're back in whatever form.

  • Please don't spend a single cent recovering the domain. The closing bid is probably going to be >$1000, which most of you probably couldn't afford anyways. What's done is done.

    The way forward is to accept the lost of the domain name, come up with internal processes to make sure that retiring admins have to fork over the credentials, and either come up with another site name or reuse chapochat. Please don't try to attempt to outbid these libs and definitely do not make some humiliating backroom deal with those libs over the administration of this site for the sake of getting the domain back.

  • I know things are bad and all. but while chugging apple juice right now I swallowed a big bunch of air, and it hurt my stummy for a moment before I had to do a big burp, and I want people to acknowledge I was in some very mild discomfort for several seconds back there.

  • 🚨 Comment found elsewhere:

    So this is a man-in-the-middle attack waiting to happen isn’t it? Buy the domain, setup a reverse proxy that points to the original hexbear server IP and start logging all requests.

  • Make sure to invalidate all the jwt tokens. Whoever buys the domain might be able to grab them from people still visiting the old site

  • Thank you so much for this thread that legitimately slowed my heart rate down compared to the rest of the news. A real human level problem, nice and relaxing. No genocide happening or even hinted at.

    • firmly against anything referencing beans or poop
    • probably against overtly left nomenclature. I think some amount of mystery serves well towards various audiences
    • probably against "tankie" because it'll be an irrelevant meme eventually
    • very quietly suggest something with javelina.. but there are already better options being sat on
  • Hexbear over $2000. That's so fucking funn- I mean oh no, we're so owned. PLEASE DO NOT CONTINUE THIS BIDDING WAR, WE'RE GOING TO BE SO OWNED

    Should we tell them about our reserve of Xi Bucks waiting to be used? I hear we have $10k.

  • Okay so losing the domain is actually very funny to me. I am not personally invested in us getting the domain back so long as measures are taken to ensure security (comments on MITM and the need for invalidating JWT, at minimum, are reasonable concerns).

    I'll make one quick note about the donations issue. I would recommend that in the future, you distribute funds so that if someone goes AWOL you only lose, say, 20% or 40% (let's say someone else leaves with them) rather than 100%. This is how many orgs maintain funds for organizing without needing all of it to go to a legal entity or just one person.

    In terms of domain registration and access, I can give a couple tips for whatever domain the site settles on.

    • Have all emails go to a forwarding email address that pings multiple admins' emails with domain messages. You can set up a regular ping to that address so that everyone knows it is still working every 2 weeks or so. e.g. "Subject: hexbear.net email is working". You should also make a note if when the registration expires. Domains tend to be renewed yearly and on a particular date, so you can set calendar reminders and alarms and so on to each verify that the domain has been renewed.
    • With some registrar services you can have multiple domain admins. There is still just one legal entity that owns the domain but you can set up multiple accounts to have access to change DNS settings, get expiry emails, etc.
    • This is an InfoSec risk, but you can share ownership by making a shared legal entity the owner, like a business or non-profit. The problem with this is that two people need to register the business and this effectively reveals your names and that you are associated with one another. But depending on your risk tolerance and existing social connections, it might be possible for 2 people to do this kind of thing.

    Obviously there is no perfect solution. The ability of one person to change the password on any shared account (e.g. forwarded email address) would still pose a disruption risk. But doing at least the first two steps would give you a heads up on something going wrong and if you did the third you could pay on behalf of the owner (the legal entity) even if one of you goes AWOL.

    Anyways, thanks again for picking up the pieces here. I'm sorry, I am sure it is very stressful. We are all comrades here. Let us know if there are ways for us to support you all.

  • When I'm in a making sure that the most basic public-facing aspects of the community identity are functional contest and my opponent is a volunteer commie sysadmin:

1075 comments