Passwords were leaked?
Lemmy.World Announcements
This Community is intended for posts about the Lemmy.world server by the admins.
Follow us for server news π
Outages π₯
https://status.lemmy.world/
For support with issues at Lemmy.world, go to the Lemmy.world Support community.
Support e-mail
Any support requests are best sent to info@lemmy.world e-mail.
Report contact
- DM https://lemmy.world/u/lwreport
- Email report@lemmy.world (PGP Supported)
Donations π
If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.
If you can, please use / switch to Ko-Fi, it has the lowest fees for us
Join the team
Probably not, it seems only temporary "session" cookies (JWT) were leaked for those affected, so they were revoked for everyone. If you wanna feel safer, changing your password is a good idea "just in case".
Based on what I read I'd say no. XSS usually just affects browsers or anything that runs JS so it mainly affects the client side. JWTs don't (if following the spec) contain passwords, it's just a short lived token that identifies someone. If you sent your password as a DM you're dumb, and they got your password if they compromised your account.
Thanks for the quick reaction and TRANSPARENCY!!
I appreciate the transparency. Hopefully with more eyes on the source code hacks like this will not happen again.
So that was why the logo and name was changed to israel. And for some reason getting redirected to a gif that was from lemmy
Thank you for your fast answer!
Thanks for the post-mortem and the quick fix! Glad you guys around to help battle test Lemmy's code.
Hmm. Liftoff won't let me post but shows logged in and as a newbie be damned if I can find where to log out.
Good shit! Thanks for keeping things up and the pretty quick response as well.
Iβd like to logout, then log back in, because I canβt upvote / downvote- how do I logout? I canβt seem to find a logout button.
Is a password change advised? How does the JWT cookie and exploit effect apps eg Jerboa?
You will have to login again for those apps. As far as we know, the exploit doesn't allow someone to actually steal your password directly, just the session you were logged into.
However, it is my personal opinion that you should change your password anyway out of an abundance of caution.
It seems that I lost all my subs. There were not many but still annoying.
E: Still subbed but can't see those in Voyager.
Thanks for the quick response! This admin team rules!