Skip Navigation

User banner
帖子
82
评论
119
加入于
2 yr. ago

  • Not anymore

  • As a spawn of Satan, I would like to propose this...

    Scrambler for the Pattern Lock... It rotates, sometimes it's upsidedown, reverse, angled at the left, angled at the right... 😈

  • This is something we as mods for communities can combat. It's a rule I enforce across my communities, posters who engage in hostility and attack people have their comments removed. Simple as.

    People can discuss things, that's fine but the second conversations devolve into personal attacks that is not okay.

    We have the power to decide how we want the communities we have to grow and what behaviour we want to discourage. Sometimes people just need a little push in the right direction.

    We can also all do our parts without mod intervention by being just decent and not engaging in the same toxic behaviour. You can also report comments to mods. It really helps us out to get reports in for comments/posts that break the rule as we may not always see it due to our instances etc...

  • Lemmy is a play on words for "Let me". Kbin Shitposting wouldn't have the same effect

  • There were cases of them deleting posts that critisced certain governments. Hence why I am on Lemmy.World and not that instance.

    There are good reasons not to like/trust them outside of a "flood of content" those kinds of users don't go on ml they are on Lemmygrad and they are equally awful, which is why I am not on that instance.

  • Let's be honest, probably why the guy was throwing it out lol

  • Reminder: Rules apply, no matter your political affiliation. Behave I do not want to lock posts but I will if you can't be civil.

  • Microplastics are the new teflon. The new secret seasoning

  • Could be where the DM from the admin was legitimate but got compromised following contact by this app developer.

    It is also possible nothing of the sort happened. The timing was just extremely alarming

  • Clicking the image isn't the issue, scrolling by it will nab your Auth tokens. Resetting your password will reset the Auth tokens protecting your account. A sign out everywhere button would fix it but that isn't an option yet. It really needs to be.

  • I used Firefox... So I definitely reset my password. Thing is I do not see an option for Lemmy where you can "sign out everywhere" which is the counter to Auth token stealing.

    So I had to change it so that the Auth token would expire. Whilst I am not an admin I won't take the chance. It could compromise other users and I do not want to take that risk.

  • That's even worse, if Lemmy has a vulnerability like that it needs to get fixed ASAP... Also if that code actually works, I am going to have to secure my account.

  • The attack involved a redirect that only affected pages that were freshly opened. If you had tabs that were opened before the attack no redirects happened, no malicious URLs of the sort. It showed the website as it was normal.

    That statement was in fact true. The attack only happened when you opened a new tab of Lemmy.World

  • I am a moderator of this community, not an admin of Lemmy.World

    I know about as much as you. The difference is I have been spending time researching and discussing findings with other mods rather than sleeping which is what I should be doing.

    I found critical information that I thought important to share. That is all there is to it. If you do not feel safe using Lemmy.World you should login to another instance.

    The owners of Lemmy.World are also in the EU so are likely still asleep or awake and trying to figure this shit out.

  • Some information I have posted to Lemmy.World:

    I am not a super code-literate person so bare with me on this... But. Still please becareful. There appears to be a vulnerability.

    Users are posting images like the following:

    https://imgur.com/a/RS4iAeI

    And inside hidden is JavaScript code that when executed can take cookie information and send it to a URL address.

    Among other things. At this time if you see an image please click the icon circled before clicking the link. DO NOT CLICK THE IMAGE. If you see anything suspicious, please report it immediately. It is better a false report than a missed one.

    I have seen multiple posts by these people during the attack. It is most certainly related to JS.

  • It is concerning as I have received a message from a compromised admin 1 hour ago telling me that an app developer wanted me to help them with mod tools.

    Hard to know if this is genuine or not, but given what has happened I am going with an attempt at breaching my account.

  • Things are slowly getting restored, the mod that was compromised has been removed. Hopefully nothing more happens. I'll unpin this post as soon as I am 100% sure on that though.

  • I mean it kinda is, the hacker exposed potential children to p*rnographic content.

  • AITA quality went down hill because they removed the no-validation rule.

    What you got was poor-faithed questions of people looking for validation about a situation where they clearly weren't going to be the asshole.

    Then as it grew in popularity appealing to the general populace it encouraged people to use it for the purpose of farming karma. They would post low effort, baits. You would get astroturfing or people subtly posting their fetishes.

    The only community I miss is AmITheAngel where people just laughed at some of the more extreme examples of the above mentioned problems.

  • That's such a simple view of how it goes. The bigoted user's go over to communities I run and harass my members.

    In the same way they harass members of non-exploding heads communities. They can go be bigoted in their bubble but I do not want them here.

    I am glad Lemmy.Worlds defederated from them. Good riddance.

  • Mildly Infuriating @lemmy.world

    This happened when I tried to open up my drink.

    Mildly Infuriating @lemmy.world

    Trying to put seasoning on my fries, the lid fell off.