this post was submitted on 10 Jul 2023
64 points (100.0% liked)

Lemmy.ca's Main Community

45 readers
1 users here now

Welcome to lemmy.ca's c/main!

Since everyone on lemmy.ca gets subscribed here, this is the place to chat about the goings on at lemmy.ca, support-type items, suggestions, etc.

Announcements can be found at https://lemmy.ca/c/meta

For support related to this instance, use https://lemmy.ca/c/lemmy_ca_support

founded 3 years ago
MODERATORS
 

They been redirecting to lemon party and some weird video. Do not go to the website. This is the admin that been hacked:

top 28 comments
sorted by: hot top controversial new old
[–] TruckBC@lemmy.ca 40 points 1 year ago* (last edited 1 year ago) (4 children)

Out of precaution we will defederate from lemmy.world until this is resolved.

Edit: Lemmy.world has resolved the issue

[–] dampfnudel@lemmy.zip 15 points 1 year ago* (last edited 1 year ago) (2 children)

This seems unnecessary. The other Admins already removed the offending account as an admin.

Although requiring 2FA, for all admins on your instance seems appropriate. 

Edit: The instance is completely down after they briefly reinstated the compromised Admin's account.

Please disregard my earlier comment. It's a clown-show over there at lemmy.world right now.

[–] TruckBC@lemmy.ca 7 points 1 year ago

Thank you for the heads up that it's fixed.

[–] TruckBC@lemmy.ca 2 points 1 year ago

Although requiring 2FA, for all admins on your instance seems appropriate.

To my knowledge we all have 2FA enabled. Will confirm.

[–] durablenapkin@lemmy.ca 2 points 1 year ago

I appreciate the proactivity/precaution!

[–] Roggie@lemmy.zip 2 points 1 year ago

It is once again comprised

[–] hawkwind@lemmy.management 1 points 1 year ago

It's unresolved.

[–] Tugboater203@kbin.social 6 points 1 year ago (1 children)

It's still compromised, right now it's showing text that says site seized by reddit for copyright infringement. Lol. Jerboa is just showing Lemmy World heads

[–] Vampiric_Luma@lemmy.ca 1 points 1 year ago

*infringment

[–] solarzones@kbin.social 5 points 1 year ago

I am glad I’m on programming.dev for lemmy, but this could’ve happened to anyone. Hope nothing catastrophic happens

[–] bioemerl@kbin.social 5 points 1 year ago

And this is why you use a password manager whenever you make new accounts on the internet.

If you had an account on the Lemmy.world website you need to change your password.

[–] Anon819450514@lemmy.ca 5 points 1 year ago

The page redirects is named Israel and it redirects to blank page with "This site was seized by Reddit for copyright infringement". So no, they don't have control yet.

[–] AnonymousLlama@kbin.social 5 points 1 year ago

Lemonparty! Now that's a name I haven't heard in ages 🍋🍋🍋👴

[–] thundercunt@lemm.ee 4 points 1 year ago (1 children)

First vlemmy now this? what the fuck is going on?

[–] thundercunt@lemm.ee 9 points 1 year ago* (last edited 1 year ago)

this feels too intentional with two big servers in this short time frame icl

[–] Izzy@lemmy.one 3 points 1 year ago

I was about to make a thread. Quite the bummer.

[–] ihavenopeopleskills@kbin.social 2 points 1 year ago* (last edited 1 year ago)

Thanks for the heads-up. Password changed.

[–] V699@kbin.social 2 points 1 year ago

I logged on and was like wtf because the site still works. Thought my phone was hacked heh

[–] takina_soldpairtm@kbin.social 1 points 1 year ago

Man, after all that commenting and stuff I did... :(

[–] mutant@kbin.social 1 points 1 year ago (1 children)

pretty damn funny lmfao, lemmy world is about to lose a lot of users permanently

[–] Dio@hell.social 0 points 1 year ago (1 children)
[–] Niello@kbin.social 3 points 1 year ago* (last edited 1 year ago)

That's .ml admins

[–] hawkwind@lemmy.management 1 points 1 year ago

Guys, the new Israel lemmy instance has a lot of content I like, but some images I don't agree with. should we defederate?

[–] PenguinTD@lemmy.ca 1 points 1 year ago (2 children)

Is there a way to not do email verification but still using 2FA? That way, even if a user's account is somehow phished/compromised, it won't compromise their other accounts.

[–] elscallr@kbin.social 1 points 1 year ago

Absolutely you can do no phone/email and MFA. It's a TOTP thing like Google or Microsoft authenticator. The service doing the authentication has no idea how it's done on the other side, it just makes sure the codes match.

[–] TruckBC@lemmy.ca 1 points 1 year ago

I just successfully set up 2FA for an account on another instance that doesn't have a verified email without any issues, so there's no need to have done email verification to use 2FA.

[–] mintiefresh@lemmy.ca 1 points 1 year ago

Yeah... I caught all that. Glad to see that they fixed it already though. Rough day for Rudd.

[–] sykccc@lemmy.ca 1 points 1 year ago

Looks like it’s gonna be a bit really put a lid on this, but I guess another sign why this is a good system?

load more comments
view more: next ›