1. I create a well crafted post to a normal site that gets 10.000 upvotes.

  2. I change the URL to a malicious site.

  3. ???

  4. Profit

3 points

There’s also

  1. I create a well crafted post woth a url to a normal site in the body of my post that gets 10.000 upvotes.

  2. I change the URL to a malicious site.

  3. ???

  4. Profit

permalink
report
reply
1 point

This pretty much - any user can do the same to a link in the body of a post

permalink
report
parent
reply
2 points

Yeah, this is why reddit didn’t allow it. I don’t think Lemmy should either.

permalink
report
reply
2 points

Reminds me of a long time ago when GameSpot and GameFAQs forums merged. GameSpot users had the ability to edit titles so they would have threads like “what’s your shoe size?” Then they would change the title to something like “how old are you?” to get the GameFAQs posters banned (due to the minimum age requirements)

permalink
report
reply
1 point

One down vote?? Why lol

permalink
report
reply
0 points

It makes it a little bit easier to do, but it is not difficult to replicate this effect without changing the URL in the title - using a redirected URL and changing the redirect address, for example.

I think that this small increase in the way this kind of attack can be delivered is more than counter-balanced by the convenience of having editable titles.

permalink
report
reply
3 points

Most subreddits also blocked redirect links for (partially) reason.

permalink
report
parent
reply
2 points
*

You don’t need to use a known redirect link. If the plan begins with a post that obtains 10,000 likes, I am sure the attacker can spend a small amount of effort and register a domain.

permalink
report
parent
reply
1 point

Surely you don’t think that’s equivalent to a simple 5 second copy paste of a new URL into the textbox, right?

And it’s not just about attack vectors, it’s also about stealth ads and misinformation

permalink
report
parent
reply

Lemmy

!lemmy@lemmy.ml

Create post

Everything about Lemmy; bugs, gripes, praises, and advocacy.

For discussion about the lemmy.ml instance, go to !meta@lemmy.ml.

Community stats

  • 882

    Monthly active users

  • 1.2K

    Posts

  • 14K

    Comments

Community moderators