Thanks for the transparency. Was having issues with Lemmy, now seems everything back to normal. Got a question, Just to add an extra layer of security, Do i need to use ToR or VPN with Lemmy ?
Lemmy.World Announcements
This Community is intended for posts about the Lemmy.world server by the admins.
Follow us for server news π
Outages π₯
https://status.lemmy.world/
For support with issues at Lemmy.world, go to the Lemmy.world Support community.
Support e-mail
Any support requests are best sent to [email protected] e-mail.
Report contact
- DM https://lemmy.world/u/lwreport
- Email [email protected] (PGP Supported)
Donations π
If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.
If you can, please use / switch to Ko-Fi, it has the lowest fees for us
Join the team
That wouldn't have helped. Don't consider this a secure messaging platform, or use this to communicate banking details or something.
That was scary and exciting. Response seems competent and transparent. I β€οΈ this place.
Must have been jealous spez
Well that's just great it really is a shame though how some people would actively want to ruin something free like this just because they can.
Hopefully with more attention on the source code scary hacks like this doesnβt happen again.
Thank you for your work π
It seems there is no way in Lemmy to invalidate all your session cookies? Without that, how can you secure an account which has a stolen session cookie?
Pardon the ignorance, but how do I know if I was compromised? what do?
You would see an overdraft and a fee charge on your account where you had 37 dollars.
Would it be a good idea to force a login if the users IP or device suddenly changes?
Um, probably coincidence or a false posi, but malwarebytes is labeling lemmy.~~world~~today as being compromised / malicious when following external links, it's only popped up twice, but here's a slightly redacted log file:
-Log Details- Protection Event Date: 7/10/23 Protection Event Time: 1:24 PM
-Software Information- Version: 4.5.33.272 Components Version: 1.0.2069 Update Package Version: 1.0.72209 License: Premium
-System Information- OS: Windows 11 (Build 22621.1928) CPU: x64 File System: NTFS User: System
-Blocked Website Details- Malicious Website: 1 , C:\Program Files\Google\Chrome Beta\Application\chrome.exe, Blocked, -1, -1, 0.0.0, ,
-Website Data- Category: Compromised Domain: lemmy.today
(end)
Can we get another admin to sign off on this being authentic? In other words, short of a signed GPG signature how do we trust announcements after a breach where admin accounts are compromised?
Yah, I noticed my Lemmies auto-corrupted to Lemurs.
I don't care. I'm keeping it.
Lemurs are cute.