PSA: Lemmy.world has been compromised! (Edit: Multiple Instances are down)
  • darrsil darrsil 1y ago 100%

    Yeah, the Lemmy 2FA implementation sucks. It only works in certain authenticators - Authy not being one of them. Google Authenticator does work and apparently so does the iOS keychain (but can't confirm that one).

    Best way to do it is to enable it and set it up but keep the settings window open, then open a separate incognito window and try to log in. If your 2FA code doesn't work, go back to the other settings window and disable it.

    15
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearLE
    Jump
    FYI: lemmy.world appears to have suffered a serious compromise.
  • darrsil darrsil 1y ago 96%

    I'm surprised I haven't seen more posts yet about this. A rogue or compromised admin put JavaScript redirects on Lemmy.world as well as changed the name and some other things. The other admins removed the compromised admin, but then about 30 minutes later they were reinstated and started wreaking havoc again. The instance eventually went offline completely.

    27
  • Warning: lemmy.world just got hacked
  • darrsil darrsil 1y ago 100%

    It works, but it's half-assed. The way Lemmy sets it up only works on a portion of authenticators, and ones like Authy isn't one of them. Then it also doesn't have a confirmation before enabling it, so you may think it's working but then get locked out of your account when you can't log in next time around.

    The best way to test it is to enable 2FA and set up the code, but keep your Lemmy settings open. Then open an incognito window and see if you can log in using the 2FA code. If you can't, go back to the settings window and disable 2FA.

    6
  • Warning: lemmy.world just got hacked
  • darrsil darrsil 1y ago 100%

    Ah, didn't realize they were already defederated. Still, admins should be on the lookout for an attack on Beehaw.

    20
  • I would be cautious about viewing any Lemmy.world communities right now, and the Beehaw admins should make sure their credentials are locked down in case they get targeted next.

    171
    45
    For those trying to kick the Reddit habit
  • darrsil darrsil 1y ago 100%

    I have to say, I kind of like that Android has a better app than iOS for once (albeit barely).

    1