erre
33
237
erre

@feddit.win

erre 104 points 3 years ago

Yea! Jerboa certainly helped me leave Reddit. Well done and thanks devs!

path: 0 444331, hotness: undefined, score: 104, children: 4
erre 96 points 3 years ago

The latest update addresses this in Settings under Privacy Information. No trackers in Connect, those are the trackers on the websites you're visiting when opening links via the app.

Screenshot of connect settings privacy information

path: 0 971243, hotness: undefined, score: 96, children: 2
erre 49 points 3 years ago

If interest rates are high, I'm sure they're hard up for capital. The free money they've grown to depend on is drying up and they need to make money themselves asap.

path: 0 734548 735531, hotness: undefined, score: 49, children: 6
erre 38 points 3 years ago

Looks like it's issuing a GET to https://zelensky.zip/save/{ENCODED_JWT_TOKEN_AND_NAV_FLAG}. The ENCODED_JWT_TOKEN is from btoa(document.cookie+nav_flag) where nav_flag is essentially 'navAdmin' if the account hit is an admin or '' if the user hit is not an admin (it checks if the admin button in the nav exists). Their server is likely logging all incoming requests and they just need to do a quick decoding to get jwt tokens and a flag telling them if it's an admin account.

I'd be hesitant to visit Lemmy on a browser atm πŸ˜“

path: 0 1061543 1061586, hotness: undefined, score: 38, children: 6
erre 35 points 3 years ago

Yep, Lemmy is filling a Reddit-shaped hole. It's a bit different but nice.

path: 0 1033500, hotness: undefined, score: 35, children: 3
erre 32 points 3 years ago

I think they're stealing auth tokens, not sure if 2fa would help. It looks like there may be a vulnerability in the markdown editor and being able to insert JavaScript. The JS being able to access your cookies to share them is the second issue.

https://lemmy.sdf.org/comment/850269

path: 0 1061666, hotness: undefined, score: 32, children: 11
erre 32 points 3 years ago

This is hilariously timed considering the current panic at the hacked instances.

path: 0 1062379, hotness: undefined, score: 32, children: 3
erre 30 points 3 years ago

What kind of terrible markdown editor allows adding onload scripts to images though.. it's insane.

path: 0 1062313 1062470 1062699, hotness: undefined, score: 30, children: 0
erre 30 points 3 years ago

We need /c/incrediblyinfuriating, this is much more than mildly infuriating.

Tough luck.

path: 0 354769, hotness: undefined, score: 30, children: 4
erre 27 points 3 years ago

Connect is ridiculously stable and feature-complete for how new it is. Definitely deserves to be mentioned.

path: 0 965790 966213, hotness: undefined, score: 27, children: 0
erre 25 points 3 years ago

Hilariously posted in the wrong thread I believe. πŸ˜„

path: 0 602553 602701, hotness: undefined, score: 25, children: 4
erre 21 points 3 years ago

If y'all could hurry up and be active so I can go back to lurking, that'd be great 😏

path: 0 717737, hotness: undefined, score: 21, children: 3
erre 21 points 3 years ago

Hopefully there's more research done. It doesn't sound like it's "absolutely carcinogenic".

The "radiofrequency electromagnetic fields" associated with using mobile phones are "possibly cancer-causing". Like aspartame, this means there is either limited evidence they can cause cancer in humans, sufficient evidence in animals, or strong evidence about the characteristics.

https://www.reuters.com/...

path: 0 981012, hotness: undefined, score: 21, children: 9
erre 21 points 3 years ago

Same here, forced me out of my lurker shell. πŸ˜…

path: 0 601341 602245, hotness: undefined, score: 21, children: 3
erre 20 points 3 years ago

I requested one for r/soccer. The community here is small and I don't have the time to spend all day on Twitter looking for the latest news to post it while it grows. So this bot fetches latest posts from there and I crosspost to a Lemmy community of real users on the rare occasion that it's interesting to me. The bot lives in its own instance so it isn't spamming any real user community.

path: 0 604790, hotness: undefined, score: 20, children: 2
erre 19 points 3 years ago

If it's onload then simply viewing the image runs that script. Yikes.

path: 0 1061624 1062652, hotness: undefined, score: 19, children: 6
erre 17 points 3 years ago

Yes!

starship troopers doing my part gif

path: 0 784057, hotness: undefined, score: 17, children: 0
erre 17 points 3 years ago

This is awesome. The kbin support is gonna go over really well too.

path: 0 505961, hotness: undefined, score: 17, children: 0
erre 16 points 3 years ago path: 0 879106, hotness: undefined, score: 16, children: 5
erre 15 points 3 years ago

I'd wager you're likely fine if you're using a mobile app when the affected image loads. Also, it appears they're stealing auth tokens.. not passwords or anything. At worst they could impersonate you until your token expires.. but you're not a high value target unless you're an admin of an instance.

path: 0 1061624 1062652 1062758 1062940, hotness: undefined, score: 15, children: 4

thanks for using Leebra!

go to feed...