TruckBC, (edited )

Out of precaution we will defederate from lemmy.world until this is resolved.

Edit: Lemmy.world has resolved the issue

hawkwind,

It’s unresolved.

Roggie,

It is once again comprised

durablenapkin,

I appreciate the proactivity/precaution!

dampfnudel, (edited )

This seems unnecessary. The other Admins already removed the offending account as an admin.

Although requiring 2FA, for all admins on your instance seems appropriate. 

Edit: The instance is completely down after they briefly reinstated the compromised Admin’s account.

Please disregard my earlier comment. It’s a clown-show over there at lemmy.world right now.

TruckBC,

Thank you for the heads up that it’s fixed.

TruckBC,

Although requiring 2FA, for all admins on your instance seems appropriate.

To my knowledge we all have 2FA enabled. Will confirm.

remotedev,

Have they resolved it? I can’t comment there, or is that from this instance defederating from them? I don’t have my lemmy.world account on this app

TruckBC,

We believe they have resolved it but we will remain defederated overnight.

AnonymousLlama,
AnonymousLlama avatar

Lemonparty! Now that's a name I haven't heard in ages 🍋🍋🍋👴

sykccc,

Looks like it’s gonna be a bit really put a lid on this, but I guess another sign why this is a good system?

Tugboater203,
Tugboater203 avatar

It's still compromised, right now it's showing text that says site seized by reddit for copyright infringement. Lol. Jerboa is just showing Lemmy World heads

Vampiric_Luma,
@Vampiric_Luma@lemmy.ca avatar

*infringment

Anon819450514,

The page redirects is named Israel and it redirects to blank page with “This site was seized by Reddit for copyright infringement”. So no, they don’t have control yet.

PenguinTD,

Is there a way to not do email verification but still using 2FA? That way, even if a user’s account is somehow phished/compromised, it won’t compromise their other accounts.

elscallr,
elscallr avatar

Absolutely you can do no phone/email and MFA. It's a TOTP thing like Google or Microsoft authenticator. The service doing the authentication has no idea how it's done on the other side, it just makes sure the codes match.

TruckBC,

I just successfully set up 2FA for an account on another instance that doesn’t have a verified email without any issues, so there’s no need to have done email verification to use 2FA.

hawkwind,

Guys, the new Israel lemmy instance has a lot of content I like, but some images I don’t agree with. should we defederate?

elscallr,
elscallr avatar

I don't think you realize what happened. The entire instance got fucked, it wasn't just some posts someone didn't like.

hawkwind,

I was trying to by funny. :(

mintiefresh,

Yeah… I caught all that. Glad to see that they fixed it already though. Rough day for Rudd.

ihavenopeopleskills,
ihavenopeopleskills avatar

Thanks for the heads-up. Password changed.

bioemerl,

And this is why you use a password manager whenever you make new accounts on the internet.

If you had an account on the Lemmy.world website you need to change your password.

V699,

I logged on and was like wtf because the site still works. Thought my phone was hacked heh

takina_soldpairtm,
takina_soldpairtm avatar

Man, after all that commenting and stuff I did... :(

FARTYSHARTBLAST,
@FARTYSHARTBLAST@sh.itjust.works avatar

Bummer.

solarzones,
solarzones avatar

I am glad I’m on programming.dev for lemmy, but this could’ve happened to anyone. Hope nothing catastrophic happens

Izzy,

I was about to make a thread. Quite the bummer.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • main@lemmy.ca
  • ngwrru68w68
  • DreamBathrooms
  • khanakhh
  • magazineikmin
  • InstantRegret
  • ethstaker
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • osvaldo12
  • everett
  • kavyap
  • Durango
  • megavids
  • cubers
  • tester
  • GTA5RPClips
  • modclub
  • mdbf
  • cisconetworking
  • tacticalgear
  • Leos
  • normalnudes
  • anitta
  • provamag3
  • JUstTest
  • lostlight
  • All magazines