I would be cautious about viewing any Lemmy.world communities right now, and the Beehaw admins should make sure their credentials are locked down in case they get targeted next.

    • Dankenstein@beehaw.org
      link
      fedilink
      arrow-up
      26
      ·
      3 年前

      Just because Beehaw is defederated from this instance, that does not mean that visiting a recently compromised server will not cause your credentials to be compromised.

      • BrikoX@lemmy.zip
        link
        fedilink
        arrow-up
        10
        ·
        3 年前

        Read the post again. It was specifically mentioning viewing lemmy.world communities, which is not possible through beehaw.org due to defederation. All you would see is the content before defederation.

        • Dankenstein@beehaw.org
          link
          fedilink
          arrow-up
          3
          ·
          3 年前

          I don’t have to read the post again, nobody should be accessing hacked servers and expecting their credentials to be safe.

      • TheOtherJake@beehaw.org
        link
        fedilink
        arrow-up
        7
        ·
        3 年前

        No user data like credentials gets transfered. Everything between instances is done with bot like helpers that do the data transfers.

        • Dankenstein@beehaw.org
          link
          fedilink
          arrow-up
          4
          ·
          edit-2
          3 年前

          That’s the problem, they don’t. If you have them stored anywhere on the device you view the communities with, your credentials are not safe.

          Edit: this was for someone else.

          Anything can be transferred without your knowledge. Do not access hacked servers while expecting privacy.

          • jarfil@beehaw.org
            link
            fedilink
            arrow-up
            2
            ·
            3 年前

            That would require your device to get hacked, not just the server.

            As for privacy… there is really little of that on Lemmy or the fediverse as a whole.

      • SatyrSack
        link
        fedilink
        arrow-up
        6
        ·
        3 年前

        Why would a “foreign” instance need to know my credentials from my local instance just to allow me to browse that foreign instance?

        • Dankenstein@beehaw.org
          link
          fedilink
          arrow-up
          1
          ·
          3 年前

          That’s the problem, they don’t. If you have them stored anywhere on the device you view the communities with, your credentials are not safe.

    • darrsil@beehaw.orgOP
      link
      fedilink
      arrow-up
      20
      ·
      3 年前

      Ah, didn’t realize they were already defederated. Still, admins should be on the lookout for an attack on Beehaw.

        • Fester@lemm.ee
          link
          fedilink
          arrow-up
          11
          ·
          3 年前

          People have multiple accounts - maybe even specifically to view .world, or on .world, and this PSA is what made them think twice before switching to it. I mean, you’re here reading and commenting on this post, and you’re not a beehaw.org user. But you could also have a beehaw account if you wanted. If you did, maybe you’d have been on it browsing local when you saw this.

          Not sure why this post is a problem. It’s a good PSA.