Skip Navigation

Posts
715
Comments
826
Joined
2 yr. ago

  • The vulnerability gave attackers access to user accounts and admins accounts by stealing their session token.

    Admin accounts on Lemmy have no access to emails, IPs or anything similar. The worst that could have happened is them using the admins capability of permanently delete stuff from the database which can be fixed with importing a backup.

    Also, getting access to impacted users and admins private messages. But only for the users that viewed an infected post in an impacted instance.

  • actor_id is just the full url of an user. It has the username at the end. That's why I have censored it.

  • I don't think we were impacted. We don't have custom emoji.

    I'm looking into this now. I might still clear everyone's session token just in case. Thank you for making this post.

  • This reads like some super shady mystery.

  • I have a plan for that, but it needs to be implemented in coordination with other instance admins. Anyways this post is just an example, not a rant.

  • That's not exactly my concern. The top users in that list seem to systematically engage in downvoting everything instead of simply blocking the community.

    This does not seem to be mere stumbling upon something in All.

  • Yeah, I had to join something like 4 database tables together.

    I'm interested in seeing if someone could develop a statistical model that could accurately detect certain behavior. I can query the data but I don't know enough statistics to really make use of it.

  • In case anyone's wondering this is what we instance admins can see in the database. In this case it's an obvious example, but this can be used to detect patterns of vote manipulation.

  • Not to mention that any problems caused by green bubble lack of compatibility are Apple's fault, not Android's.

  • May I ask if there will be a way to disable de NSFW blur?

  • New instances would have a lower voting weight by default.

  • No need to make all federation under a whitelist. It's enough to ignore votes from suspicious instances or reduce their weight.

  • This. It's only a matter of time until we can automatically detected vote manipulation. Furthermore, there's a possibility that in future versions we can decrease the weight of votes coming from certain instances that might be suspicious.

  • Oh, I've never heard about gray romanticism or gray gender before.

  • I'm perfectly fine with whatever it is they're referring to.

  • This used to be possible with Xposed framework, but I don't know if that is still a thing.

  • Cake

    Jump
  • Woah I saw troll face and then I stopped seeing him.

  • It's this quote real? 😂

  • Furry (Safe For Work) @yiffit.net

    Who's moving over there? (by Kenket)

    Furry (Safe For Work) @yiffit.net

    Khajiit (by Istirus)

    Furry Wallpapers @yiffit.net

    Khajiit (by Istirus)

    Meta and Announcements @yiffit.net

    Status: there's been some downtime due to server resources. It has now been fixed. We're growing faster than expected. I'll do some maintenance tomorrow to future-proof things.

    Meta and Announcements @yiffit.net

    Please tag posts as NSFW even if they're already in a NSFW community. It's not redundant.

    Reddit @lemmy.ml

    Should we encourage a spirit of "no more content by me on reddit" for people who are upset and want to take steps to leave Reddit?

    Meta and Announcements @yiffit.net

    New communities on Yiffit.net (2023-06-16)

    Furry Wallpapers @yiffit.net

    Nick Wilde (by Hiromatsu)

    Furry Wallpapers @yiffit.net

    Jackal (Sassaren12)

    Meta and Announcements @yiffit.net

    FYI, Lemmy and Kbin are Progressive Web Apps, meaning you can install them as regular apps to your phone's home screen

    Fediverse @lemmy.world

    If you're still worried about the suitability of Lemmy/Kbin as a reddit alternative go check out calckey

    Furry memes @yiffit.net

    Radiohead (by Kenket)

    Meta and Announcements @yiffit.net

    Notice: there was a misconfiguration that impacted users ability to comment. I've fixed it.

    Furry Technologists @pawb.social

    PSA: set your community's language to "undetermined" AND English if you want to be able to reply to Mastodon users (endless spinning wheel bug)

    Meta and Announcements @yiffit.net

    PSA: set your community's language to "undetermined" AND English if you want to be able to reply to Mastodon users (endless spinning wheel bug)

    Furry (Safe For Work) @yiffit.net

    Bolt and mittens (by Reysi)

    In An Alternate Universe... @lemmy.world

    How do I keep my pet T-Rex from attacking the mailman?

    Furry Chat @yiffit.net

    Puritanism took over online fandom — and then came for the rest of the internet

    Furry (Safe For Work) @yiffit.net

    Pride Themed Bulbasaurs

    Furry Technologists @pawb.social

    An extension to make interacting with different lemmy instances easier.