TheSaneWriter

joined 1 year ago
MODERATOR OF
[–] TheSaneWriter@lemm.ee 2 points 1 year ago

As much as any other app I've seen, but I would still recommend using unique credentials for Lemmy.

[–] TheSaneWriter@lemm.ee 3 points 1 year ago

I'll make sure to let you know if I see it anywhere.

[–] TheSaneWriter@lemm.ee 1 points 1 year ago (1 children)

All of the apps have you enter your credentials into their page because Lemmy doesn't support OAuth2. I don't think it's fair to criticize Voyager for a problem that is currently inherent to all Lemmy apps.

[–] TheSaneWriter@lemm.ee 2 points 1 year ago

You're correct, but by maintaining distinct passwords with a password manager you make sure only the one account is compromised. 2FA also helps, you may have the username and password, but the 2FA code that you were given needs to be used immediately or else it will expire, and an expired 2FA code won't allow you to successfully breach the account you're trying to break into to.

[–] TheSaneWriter@lemm.ee 1 points 1 year ago

That's fair, but sometimes a malicious actor will attempt to covertly contribute code that introduces a security vulnerability.

[–] TheSaneWriter@lemm.ee 6 points 1 year ago

Indeed, this is a real weak spot with Lemmy's security. I honestly think we need to place more emphasis on implementing OAuth2, when I have the time I'll have to take a look at that again to see if I'm able to.

[–] TheSaneWriter@lemm.ee 4 points 1 year ago

The past few hours, it was recent.

[–] TheSaneWriter@lemm.ee 24 points 1 year ago (2 children)

For the best. Knowing that this hacking technique is a vulnerability with the Lemmy project as a whole, I think it's reasonable for instances to temporarily close while a fix is implemented.

[–] TheSaneWriter@lemm.ee 28 points 1 year ago (6 children)

Deeply unfortunate that something like this could happen, you always hope that code injection vulnerabilities are found before someone is hacked. With that in mind, this shows the importance of two security principles: always parse and clean user input and don't click links (including images) before checking where they are going to send you.

[–] TheSaneWriter@lemm.ee 8 points 1 year ago (2 children)

Deeply unfortunate that something like this could happen, you always hope that code injection vulnerabilities are found before someone is hacked. With that in mind, this shows the importance of two security principles: always parse and clean user input and don't click links (including images) before checking where they are going to send you.

[–] TheSaneWriter@lemm.ee 2 points 1 year ago

It's no problem! I really like helping build new communities, and I was having a really good time participating on VLemmy. I'll continue participating using lemm.ee and continue enjoying the platform and community, but I really hope that VLemmy comes back because I was happy with what we were building there.

[–] TheSaneWriter@lemm.ee 3 points 1 year ago (2 children)

I was not on the Admin team, I did moderate the Chat community and I was active in Support but I wasn't technically an admin. I had applied to be an admin, as pyarra the day before yesterday put out a post asking for admin applications, but then the server died and I'm not sure what happened.

view more: next ›