FYI!!! In case you start getting re-directed to porn sites.

Maybe the admin got hacked?


edit: lemmy.blahaj.zone has also been hacked. beehaw.org is also down, possibly intentionally by their admins until the issue is fixed.

Post discussing the point of vulnerability: https://lemmy.ml/post/1896249

Github Issue created here: https://github.com/LemmyNet/lemmy-ui/issues/1895

You are viewing a single thread.
View all comments View context
31 points

Yep, same. It was also the most likely scenario.

It looks like it was an individual admin getting hacked. Not good but not the worst. Most fallout will probably be whether their security practices were sufficient for an admin and whether lemmy has good enough contingencies for this sort of thing. Lemmy’s 2FA is probably a hot issue now though.

permalink
report
parent
reply
18 points

The JWT are likely a hot issue, already some Issues on GitHub about them not being revoked properly.

permalink
report
parent
reply
11 points

Oh man, that would be brutal if they are resetting the password and it isn’t kicking the attacker out…

permalink
report
parent
reply
12 points

That’s probably what happened here because they did revoke the admin’s access, but it continued.

permalink
report
parent
reply
8 points

JWT issue opened 4 days ago: https://github.com/LemmyNet/lemmy/issues/3499

permalink
report
parent
reply
17 points

Yeah, I’ve been scared to turn on 2FA with all the reports of people being locked out:

permalink
report
parent
reply
15 points

Yeah, the Lemmy 2FA implementation sucks. It only works in certain authenticators - Authy not being one of them. Google Authenticator does work and apparently so does the iOS keychain (but can’t confirm that one).

Best way to do it is to enable it and set it up but keep the settings window open, then open a separate incognito window and try to log in. If your 2FA code doesn’t work, go back to the other settings window and disable it.

permalink
report
parent
reply
6 points

I am using 2fas with no issue and set it up using the method you described. So far, so good…in case anyone needed a vote of confidence!

permalink
report
parent
reply
10 points

The hacked MichelleG account actually commented that it did not have MFA enabled lol. This was on the lemmy.world shitpost community, on one of the posts making memes about the situation. Hilarious that the hacker decided to share that.

permalink
report
parent
reply
3 points

OK good to know that the server itself is unlikely to be compromised. I’ll be changing passwords to all my accounts once this blows over.

permalink
report
parent
reply

Fediverse

!fediverse@lemmy.ml

Create post

A community dedicated to fediverse news and discussion.

Fediverse is a portmanteau of “federation” and “universe”.

Getting started on Fediverse;

Community stats

  • 423

    Monthly active users

  • 962

    Posts

  • 14K

    Comments