TheSaneWriter

joined 2 years ago
MODERATOR OF
[–] TheSaneWriter@lemm.ee 0 points 2 years ago (1 children)

Discord isn't a good alternative, it's not the same type of social media site. Discord is more of a chatroom aggregator, while Reddit is more of a forum aggregator. While Reddit technically supports chats and Discord technically supports threads, in both cases they're clunky and not the main point of the site.

[–] TheSaneWriter@lemm.ee 2 points 2 years ago

As much as any other app I've seen, but I would still recommend using unique credentials for Lemmy.

[–] TheSaneWriter@lemm.ee 3 points 2 years ago

I'll make sure to let you know if I see it anywhere.

[–] TheSaneWriter@lemm.ee 1 points 2 years ago (1 children)

All of the apps have you enter your credentials into their page because Lemmy doesn't support OAuth2. I don't think it's fair to criticize Voyager for a problem that is currently inherent to all Lemmy apps.

[–] TheSaneWriter@lemm.ee 2 points 2 years ago

You're correct, but by maintaining distinct passwords with a password manager you make sure only the one account is compromised. 2FA also helps, you may have the username and password, but the 2FA code that you were given needs to be used immediately or else it will expire, and an expired 2FA code won't allow you to successfully breach the account you're trying to break into to.

[–] TheSaneWriter@lemm.ee 1 points 2 years ago

That's fair, but sometimes a malicious actor will attempt to covertly contribute code that introduces a security vulnerability.

[–] TheSaneWriter@lemm.ee 6 points 2 years ago

Indeed, this is a real weak spot with Lemmy's security. I honestly think we need to place more emphasis on implementing OAuth2, when I have the time I'll have to take a look at that again to see if I'm able to.

[–] TheSaneWriter@lemm.ee 1 points 2 years ago

This is why a paper trail is so important. When shit hits the fan they will always try to blame you, so you need written or audio proof that they issued the order.

[–] TheSaneWriter@lemm.ee 4 points 2 years ago

The past few hours, it was recent.

[–] TheSaneWriter@lemm.ee 24 points 2 years ago (2 children)

For the best. Knowing that this hacking technique is a vulnerability with the Lemmy project as a whole, I think it's reasonable for instances to temporarily close while a fix is implemented.

[–] TheSaneWriter@lemm.ee 28 points 2 years ago (6 children)

Deeply unfortunate that something like this could happen, you always hope that code injection vulnerabilities are found before someone is hacked. With that in mind, this shows the importance of two security principles: always parse and clean user input and don't click links (including images) before checking where they are going to send you.

[–] TheSaneWriter@lemm.ee 8 points 2 years ago (2 children)

Deeply unfortunate that something like this could happen, you always hope that code injection vulnerabilities are found before someone is hacked. With that in mind, this shows the importance of two security principles: always parse and clean user input and don't click links (including images) before checking where they are going to send you.

view more: next ›