faebudo

joined 1 year ago
[–] [email protected] 5 points 1 year ago* (last edited 1 year ago) (1 children)

According to one of the vuln posts a redirect and cookie stealing code was added as onload js (can even be seen in a screenshot).

Together with the JWT that are valid for a year and non revokable (https://github.com/LemmyNet/lemmy/issues/3364) that means if you logged in or browsed an affected instance while logged in to it the attacker got your account and the only way to get it back is not in your hands but in the instance admins (they have to delete all sessions from the DB).

[–] [email protected] 4 points 1 year ago

reddit was/is not really a for profit corporation as they burn money every day. So they paid for the platform people could use to build their communities and people were willing to do it for free. Now reddit wants to make money and sell all those communities to the fancy new LLM companies.

view more: ‹ prev next ›