They been redirecting to lemon party and some weird video. Do not go to the website. This is the admin that been hacked:

EDIT: lemmy.blahaj.zone also compromised!

  • TruckBC@lemmy.ca
    shield
    M
    link
    fedilink
    English
    arrow-up
    53
    ·
    edit-2
    2 年前

    Out of precaution we will defederate from lemmy.world until this is resolved.

    Edit: Lemmy.world has resolved the issue

  • bioemerl@kbin.social
    link
    fedilink
    arrow-up
    10
    ·
    2 年前

    And this is why you use a password manager whenever you make new accounts on the internet.

    If you had an account on the Lemmy.world website you need to change your password.

  • Tugboater203@kbin.social
    link
    fedilink
    arrow-up
    9
    ·
    2 年前

    It’s still compromised, right now it’s showing text that says site seized by reddit for copyright infringement. Lol. Jerboa is just showing Lemmy World heads

  • Anon819450514@lemmy.ca
    link
    fedilink
    English
    arrow-up
    8
    ·
    2 年前

    The page redirects is named Israel and it redirects to blank page with “This site was seized by Reddit for copyright infringement”. So no, they don’t have control yet.

  • solarzones@kbin.social
    link
    fedilink
    arrow-up
    7
    ·
    2 年前

    I am glad I’m on programming.dev for lemmy, but this could’ve happened to anyone. Hope nothing catastrophic happens

  • sykccc@lemmy.ca
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 年前

    Looks like it’s gonna be a bit really put a lid on this, but I guess another sign why this is a good system?

  • PenguinTD@lemmy.ca
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 年前

    Is there a way to not do email verification but still using 2FA? That way, even if a user’s account is somehow phished/compromised, it won’t compromise their other accounts.

    • TruckBC@lemmy.caM
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 年前

      I just successfully set up 2FA for an account on another instance that doesn’t have a verified email without any issues, so there’s no need to have done email verification to use 2FA.

    • elscallr@kbin.social
      link
      fedilink
      arrow-up
      1
      ·
      2 年前

      Absolutely you can do no phone/email and MFA. It’s a TOTP thing like Google or Microsoft authenticator. The service doing the authentication has no idea how it’s done on the other side, it just makes sure the codes match.

  • V699@kbin.social
    link
    fedilink
    arrow-up
    2
    ·
    2 年前

    I logged on and was like wtf because the site still works. Thought my phone was hacked heh

  • mintiefresh@lemmy.ca
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 年前

    Yeah… I caught all that. Glad to see that they fixed it already though. Rough day for Rudd.