Lemmy.world compromised, should we temporarily defederate?

https://sh.itjust.works/post/921912

Lemmy.world compromised, should we temporarily defederate? - sh.itjust.works

PSA: DO NOT ATTEMPT TO ACCESS LEMMY.WORLD, THERE MIGHT BE MALWARE Lemmy.world member here. I created this account after .world started redirecting me to porn sites and odd mp3 files. We might want to defederate to limit the potential impact. Also, SJW might be affected by the same vulnerabilities as .world, so maybe the admins here should look at that.

What impact?

As long as you dont go on lemmy.world, it’s not going to redirect you to all the stupid websites.

And I doubt whatever they’re posting (if they’re posting anything) is getting upvoted, so you won’t see it anywhere else.

And where are you getting “malware” from?

People are acting like it’s some crazy hack, and not the 4chan rejects from exploding heads finally guessing an admins password a week after they got defederated. And after all that time chasing the mailman, they had no idea what to do when they guessed it

But this does highlight an issue with instances. I doubt the handful of admins know each other. Like, maybe an email, but for the most part if shit like this happens during “off hours” it might be a while before the top admin even knows there’s an issue

There’s an admin matrix chat

And how many people answer that on Sunday night?

What I’m getting at is a major website has at least a skeleton staff that can do something, even if that’s just pulling the plug.

I don’t even reply to most work texts after hours unless it’s someone saying they have to use sick leave. I don’t expect people hosting Lemmy as a hobby to be on call 24/7.

But I hope afterwards they’re transparent about what happened and how they’re going to stop it from happening again. If not, it’s easy to hop instances

There’s other admins working on it now. It’s 5am where the owner is now.
Instance name checks out