Is a password change advised? How does the JWT cookie and exploit effect apps eg Jerboa?
Lemmy.World Announcements
This Community is intended for posts about the Lemmy.world server by the admins.
Follow us for server news ๐
Outages ๐ฅ
https://status.lemmy.world/
For support with issues at Lemmy.world, go to the Lemmy.world Support community.
Support e-mail
Any support requests are best sent to info@lemmy.world e-mail.
Report contact
- DM https://lemmy.world/u/lwreport
- Email report@lemmy.world (PGP Supported)
Donations ๐
If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.
If you can, please use / switch to Ko-Fi, it has the lowest fees for us
Join the team
You will have to login again for those apps. As far as we know, the exploit doesn't allow someone to actually steal your password directly, just the session you were logged into.
However, it is my personal opinion that you should change your password anyway out of an abundance of caution.
Good shit! Thanks for keeping things up and the pretty quick response as well.
Hmm. Liftoff won't let me post but shows logged in and as a newbie be damned if I can find where to log out.
Thank you for your fast answer!
Occasional cookie deletions I understand, but will sign-ins persist in the future?
Thanks for the quick response! This admin team rules!
I see you, Imposter.
Maybe there needs to be a quick rundown how to actually log out and in on clients, seems you can't with jerboa without just wiping the app, and wefwef, you need to delete all accounts.
I see some instances are throwing server errors
I appreciate the transparency. Hopefully with more eyes on the source code hacks like this will not happen again.
Just for a bit of perspective -- Scary hacks like this happen all the time in the for-profit corporate world, too. They just don't tell us about it. It will continue to happen as technology constantly grows and evolves.
Praise to the Admins and Devs who play this constant game of whack-a-mole!
is that why I can't log into my lemmy.world account?
ok not a problem anymore. seems like I just had to clear my cache and it let me log in
******* This happened to me, one of my posts had it's photo deleted (I didn't delete it), then when I replaced it, the next time I checked the entire post had been deleted.
Is this why I had to sign in and out of my account on liftoff?
I couldn't comment untill I did that. There may be others!