

Removed “and above” from page and instead added a note to always get the latest version if your version isn’t listed as supported explicitly.
I made LASIM! https://github.com/CMahaff/lasim
I currently have 3 accounts (big shock):
Removed “and above” from page and instead added a note to always get the latest version if your version isn’t listed as supported explicitly.
Thanks for your kind words, I’m glad it has helped you!
LASIM author here, ironically on my own alt: Just an FYI that support for Lemmy 0.18.3 is not yet out, but keep an eye out for it soon (I have it working on a branch but I need to test it more before release).
This is the first breaking API change since it’s creation, so here are the limitations:
So that all means:
This will be true of every release with breaking API changes.
EDIT: PR is out. Once it builds, I’ll publish a new release! https://github.com/CMahaff/lasim/pull/21
EDIT 2: Release is published! https://github.com/CMahaff/lasim/releases/tag/v0.2.0
The whole site is having stability issues at the minute.
There was ddos attack on it earlier and it hasn’t really recovered.
There are tools that can help! https://lemmy.ml/post/1875767
I made LASIM - it’s takes 2 API calls to fetch your subscriptions (1 login, 1 profile), so with lemmy.world being 50/50 on those calls, you might have to try a few time, but once you have em, it will be easy to push them to a new instance.
To answer your other questions:
I don’t think so, but I’d love to be proven wrong!
Oh man this one is SO much worse. If this is what is going on the only way to kick out the hacker will probably be to manually alter the DB. Yikes.
I hope the admin team is aware of this - not sure how one would even contact them.
The issue does say changing the password should kick the user out, but yeah, still not good.
Oh man, that would be brutal if they are resetting the password and it isn’t kicking the attacker out…
Yeah, I’ve been scared to turn on 2FA with all the reports of people being locked out:
There’s actually another thread on exactly this topic: https://lemmy.ml/post/1875767
I actually consider it good news that the redirection is happening this way (something that can be done just by having the lemmy credentials of an admin) vs something indicating they have access to the server itself.
My concern is that configuring the site to automatically redirect users sounds like they have pretty large control over the site - the kind of control that I would assume is usually limited to users with root access on the server.
Obviously hope nothing of value is lost and that there is a proper off-site backup of the content.
Edit: See Max-P’s comment, it looks like the site redirection was accomplished in a way that IMO suggests they do NOT have full control over the site. We’ll obviously have to wait for the full debrief from the admins.
4AM in the Netherlands where the instance owner Ruud lives… hopefully his assistant admins can clean it up, but it might be a bit before he even knows anything is wrong.
Well I guess I’ll have to respond with my .ml account instead of my .world account.
Tried to delete this post and post it again, which is what I see from .world, but on .ml both new posts came across, but no deletes did.
So now I can’t access this specific post from .world.
Federation bugs are a trip!
Another thread linked to this post which has some digging / speculation into what may have gone wrong: https://lemdit.com/post/262746