It seems like they are down for a longer time now. How will they recover? Does longer down mean they will have to do more catching up with other instances? Can I get updates somewhere?

You are viewing a single thread.
View all comments View context
4 points

Sites don’t store passwords, they store password hashes. There is no reason to give any personal info you aren’t comfortable giving. You can use the site just fine without posting any

permalink
report
parent
reply
3 points

Hacking an account is still a valid concern though for various reasons , and hashes can still be used against password lists. Additionally, Two factor authentication is a necessity for sure. Now don’t get me wrong, I completely understand this feature is coming and that this is a developing service but many of these concerns do seem valid to me.

permalink
report
parent
reply
1 point

Simply salting hashes would be enough to prevent password hash list lookups. Agreed, 2FA is pretty essential, though I can understand not implementing it where people don’t care about the integrity of their pseudonyms. As it gains popularity, it will need to be implemented

permalink
report
parent
reply
1 point

Hacking an account is still a valid concern though for various reasons

Let’s assume you’re doing the best practice thing and using a long and unique password for each service you use.

What benefit does a hacker have hacking your lemmy-based account? Considering that everything you post is public… There’s simply nothing of value that you would obtain by “hacking” an account here… The only thing I can think of is if your a moderator of a community or an admin of an instance.

I just don’t see any value to it… But even then… 2fa is slated for v0.18 which is probably coming out in the next few weeks.

permalink
report
parent
reply
1 point

2fa is slated for v0.18 which is probably coming out in the next few weeks.

Only basic TOTP 2FA though. Webauthn/FIDO2 should be coming in the future though.

permalink
report
parent
reply
1 point

Mostly thinking impersonation, spamming, deletion or modification of history…. Although I’m sure there are probably other reasons too.

permalink
report
parent
reply

Technology

!technology@beehaw.org

Create post

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Community stats

  • 2.5K

    Monthly active users

  • 3.4K

    Posts

  • 81K

    Comments