TheSaneWriter

joined 1 year ago
MODERATOR OF
[–] TheSaneWriter@lemm.ee 7 points 1 year ago

In all honesty, I can see your comments from lemm.ee. I wonder if lemmy.world is back up now.

[–] TheSaneWriter@lemm.ee 7 points 1 year ago

Damn, hackers are being really uncool towards lemmy.world. Hopefully some good can come from this and they can implement robust security systems that help protect Lemmy instances from these types of attacks.

[–] TheSaneWriter@lemm.ee 17 points 1 year ago (1 children)

A mixture of social conservatives voting against "wokeness," unrestricted guns rights and anti-abortion one-issue voters, and people that misguidedly believe the Republicans are better for the economy keep the party chugging along in elections.

[–] TheSaneWriter@lemm.ee 2 points 1 year ago

I'm looking forward to seeing the final result, seeing so many of the third party apps moving to Lemmy has been really inspiring.

[–] TheSaneWriter@lemm.ee 3 points 1 year ago (2 children)

Oh crap, I forgot which asklemmy I'm on, I'm a dumbass.

[–] TheSaneWriter@lemm.ee 2 points 1 year ago

As much as any other app I've seen, but I would still recommend using unique credentials for Lemmy.

[–] TheSaneWriter@lemm.ee 3 points 1 year ago

I'll make sure to let you know if I see it anywhere.

[–] TheSaneWriter@lemm.ee 1 points 1 year ago (1 children)

All of the apps have you enter your credentials into their page because Lemmy doesn't support OAuth2. I don't think it's fair to criticize Voyager for a problem that is currently inherent to all Lemmy apps.

[–] TheSaneWriter@lemm.ee 2 points 1 year ago

You're correct, but by maintaining distinct passwords with a password manager you make sure only the one account is compromised. 2FA also helps, you may have the username and password, but the 2FA code that you were given needs to be used immediately or else it will expire, and an expired 2FA code won't allow you to successfully breach the account you're trying to break into to.

[–] TheSaneWriter@lemm.ee 8 points 1 year ago

That's fair, but sometimes a malicious actor will attempt to covertly contribute code that introduces a security vulnerability.

[–] TheSaneWriter@lemm.ee 8 points 1 year ago

Indeed, this is a real weak spot with Lemmy's security. I honestly think we need to place more emphasis on implementing OAuth2, when I have the time I'll have to take a look at that again to see if I'm able to.

[–] TheSaneWriter@lemm.ee 2 points 1 year ago

Indeed. I'm certain they exist, but it's a case of needing to research which organizations are reputable and respected for their certifications.

view more: next ›