Comment on
lemmy instances be going down
Reply in thread
- I keep seeing Vlemmy mentioned but I guess I missed the drama. Did the server admin unexpectedly shut the server down?
Comment on
lemmy instances be going down
Reply in thread
Comment on
It seems like lemmy.world is completely down following the breach.
Reply in thread
This seems to be a front-end JavaScript exploit, so theres's a good chance that this is a Lemmy problem, not a Lemmy[dot]world problem. Don't be surprised if the issue starts spreading to other instances.
If I were running a server, I would take it offline until a patch is released (Beehaw did this, to be proactive).
Comment on
Beehaw is also down, but they elected to do it
Smart move. I'm surprised more instances aren't doing this.
Comment on
Microsoft announces new $350, 1 TB Carbon Black Xbox Series S
I'm shocked this isn't replacing the original Series S at $300.
Comment on
It seems like lemmy.world is completely down following the breach.
Reply in thread
FWIW, right now it seems unlikely that your password was accessible to anyone. Your login cookie may have been taken if you accessed Lemmy on a web browser (apps are likely fine), so you would want to clear your Lemmy cookies and cache once this is over.
But I'm speculating, and changing your password will definitely help!
Comment on
I'm going to assume the admins here all have 2FA on their accounts, right?
Reply in thread
Looks like you're right, admins will just need to update the JWT secret.
Comment on
I'm going to assume the admins here all have 2FA on their accounts, right?
Reply in thread
Really curious to see how they kill the existing tokens, and whether admins have tools to easily clear all sessions. On one of the Matrix chats someone suggested that the tokens have a one year expiry date!
Comment on
Adversarial Prompting
This was a great overview. I hadn't heard about the DAN method, and it's fascinating!