this post was submitted on 10 Jul 2023
247 points (100.0% liked)

Fediverse

757 readers
1 users here now

A community dedicated to fediverse news and discussion.

Fediverse is a portmanteau of "federation" and "universe".

Getting started on Fediverse;

founded 5 years ago
MODERATORS
 

FYI!!! In case you start getting re-directed to porn sites.

Maybe the admin got hacked?


edit: lemmy.blahaj.zone has also been hacked.

you are viewing a single comment's thread
view the rest of the comments
[–] Stovetop@lemmy.ml 67 points 1 year ago (4 children)

One of the admin accounts appears to have been compromised. The owner/other admins appear to be aware now because that account had its admin access revoked and offending posts are being removed.

Definitely opens up a big question about the security of Lemmy instances that I am sure will be discussed over the next few days.

[–] hawkwind@lemmy.management 27 points 1 year ago (1 children)

I wouldn't assume reasons why or that it's fixed until that consensus has been more widely reached.

[–] Stovetop@lemmy.ml 6 points 1 year ago* (last edited 1 year ago) (1 children)

More time will definitely be needed. I'm glad they caught it and acted quickly enough to prevent more vandalism from occurring, but until we know how the account was compromised and what else they may have gotten in the process, it's still a situation to keep an eye on.

[–] hawkwind@lemmy.management 2 points 1 year ago (1 children)

They are still acting on it, seems.

[–] Stovetop@lemmy.ml 3 points 1 year ago

Yep, it's definitely not over.

[–] eerongal@ttrpg.network 15 points 1 year ago (1 children)

Definitely opens up a big question about the security of Lemmy instances that I am sure will be discussed over the next few days.

They added 2FA login to lemmy in one of the newer updates. Probably pretty pertinent for any admins to use it....

[–] ebits21@lemmy.ca 8 points 1 year ago* (last edited 1 year ago) (1 children)

It’s buggy and missing some key checks to make sure it’s working when you set it up.

Real risk of locking yourself out of your account.

[–] eerongal@ttrpg.network 3 points 1 year ago (1 children)

oh, really? maybe i'll turn mine off then.....Thanks for the heads up!

[–] ebits21@lemmy.ca 5 points 1 year ago (1 children)

Mostly a risk on initial setup.

I’ve been waiting a bit for it to stabilize and just using huge random passwords

[–] Zetaphor@zemmy.cc 4 points 1 year ago (1 children)

If you're using a password manager you'd be doing this for every site and without even having to think about it. Bitwarden is a great choice.

[–] Cube6392 3 points 1 year ago (1 children)

I like KeePass. Bitwarden currently has an nginx exposure in the Dockerfile published in their git repo (may have been fixed since a couple of days ago). That said, I used Bitwarden for many years and switched out of an abundance of paranoia, and am definitively not recommending against it. Just basically use one of the following:

  • Bitwarden
  • KeePass
  • 1password

And stay far the fuck away from LastPass

[–] delollipop 1 points 1 year ago (1 children)

my uni is currently still recommending lastpass as of now, tho I’ve heard they might be looking for alternatives …

[–] Cube6392 1 points 1 year ago

Let your classmates know that last pass has semi permanently damaged their trustworthiness by trying to hide a security breach, and then downplaying the severity of the breach, and that your University's security recommendations are intrinsically suspect as a result

[–] bigben111@lemmy.ml 7 points 1 year ago

Thanks for the context

[–] ebits21@lemmy.ca 4 points 1 year ago

They really need to improve their 2fa implementation