Avatar

Aceivan [they/them]

Aceivan@hexbear.net
Joined
5 posts • 240 comments
Direct message

I’m not sure there’s any way of knowing that for sure actually… since it was a clientside exploit. it would have been anyone browsing the megathread (or anywhere else the attacker posted, I think it was just the mega?) in that 30 min window would have had their token sent to the attacker’s server (exposing their IP if they were not using a VPN). Then if the attacker used the token they could have logged in and viewed profile settings (of which really the only sensitive one is email I would think) or DMs. I can’t think of a simple way to prove whether or not the attacker did so, but given their MO and relative lack of sophistication I’d guess they weren’t interested in user info, just defacing the site by gaining admin accounts, which they failed to do. I assume the 3 accounts were the ones that posted the gore or targeted admins with the stealer via DM.

permalink
report
parent
reply

yeah lol. it has a dark mode even! and we could self host it in single instance mode. browsing at least works without js, didn’t want to give them my login info to see if anything else did

permalink
report
parent
reply

yeah it was a paid ep I think but there were pirate reuploads like, immediately that made the rounds

permalink
report
parent
reply

They usually work, though many bt headphones and many devices that connect to them are flaky, bad range, dumb broken features, etc. but most of all I just detest the concept of taking something dead simple that will just work for decades unless you like, break the wires or speakers, and turning it into another disposable device that will die in at most like 3-4 years because the non replaceable batteries wear out or the electronics shit the bed.

I have headphones from the soviet union that still work fine with modern equipment, I have 40 year old koss headphones that still sound nice, etc. bluetooth shit is inherently disposable.

permalink
report
parent
reply

https://mlmym.org/hexbear.net/ this is that I think

Not like the one we are using though. just an exact clone of old reddit lol

permalink
report
parent
reply

eh I like the way it turbocharged lemmy (and I only browse there with libreddit when it gets linked or comes up in search results so nothing is changing for me really )

I mean there’s a lot of shitty redditors flowing into lemmy, but at least its mostly the leftlib anti-corporate redditors, a lot of them aren’t even hardline anti-communists which is nice. If mastodon is anything to go by, lemmy will remain a viable if niche alternative and the enshittification will continue, driving further waves of people away.

Its not like the less reactionary posters are just gone, they’ve just dispersed to elsewhere on the internet (or will cave and go back to reddit soon, hard to say)

permalink
report
reply

Some places its actually legal I think but definitely not all and that won’t save you from police harasssment, tresspassing charges, etc.

permalink
report
parent
reply

sweet, man made horrors beyond comprehension (actually I usually like this channel but haven’t seen this one yet)

permalink
report
reply

ohhhh gotcha

if you can still reproduce the problem on that other browser I’d check for things like cookies and cached service workers and stuff… (if it’s firefox, ctrl-shift-e and then go to the storage tab to look at cookies. Things like the domain, expiration date, and settings like httponly, secure, samesite should be innocuous to share but potentially useful to infer if it’s an old stuck cookie, or using the wrong domain, etc)

permalink
report
parent
reply

yeah instagram users but basically. I assume all the content farmers and bots are jumping on it, plus some fraction of the 1.6 billion instagram users, since the accounts are inextricably linked for now it does make it easy to sign up anyhow.

permalink
report
parent
reply