While I was asleep, apparently the site was hacked. Luckily, (big) part of the
lemmy.world team is in US, and some early birds in EU also helped mitigate this.
As I am told, this was the issue: - There is an vulnerability which was
exploited - Several people had their JWT cookies leaked, including a...
We're all being hacked the moment we signed up for this instance. The owner is a notorious hacker wanted by the FBI, CIA, KGB, Sesame Street, and Megatron. Imagine using an Ubuntu server for an Arch instance! The nerve!
Jk.
I hope not, tbh. I do hope instance owners and admins have a Matrix/Discord group where they can communicate in real time with each other. I haven't seen any of the comments that allegedly contain the exploit locally. Hopefully the ones in charge update us. :)
We do communicate privately, don't worry. Been a busy day at work for me till now so I only seen whats going on exactly now (there were just some reports of lemmy.world being hacked when I woke up this morning and nothing more). I just sent the server owner a link as to how to resolve the situation so hopefully its all resolved soon.
Thank you. We do appreciate the stuff you guys do behind the scenes. But I have no life so I'm often on lemmy and might see stuff you guys might miss. 😂
Yea, for me it depends a lot on the day how much time I spend here. Some days hours some days 0, so I might miss some stuff but hopefully the other 2 catch them or someone reports it to us.
Sören (he is the one that actually owns it) just replied to me, so should be sorted very soon. I guess one of us will update once its done (or you might notice the server going down for a restart).