Clicking the image isn’t the issue, scrolling by it will nab your Auth tokens. Resetting your password will reset the Auth tokens protecting your account. A sign out everywhere button would fix it but that isn’t an option yet. It really needs to be.
Clicking the image isn’t the issue, scrolling by it will nab your Auth tokens. Resetting your password will reset the Auth tokens protecting your account. A sign out everywhere button would fix it but that isn’t an option yet. It really needs to be.
I used Firefox… So I definitely reset my password. Thing is I do not see an option for Lemmy where you can “sign out everywhere” which is the counter to Auth token stealing.
So I had to change it so that the Auth token would expire. Whilst I am not an admin I won’t take the chance. It could compromise other users and I do not want to take that risk.
That’s even worse, if Lemmy has a vulnerability like that it needs to get fixed ASAP… Also if that code actually works, I am going to have to secure my account.
Some information I have posted to Lemmy.World:
I am not a super code-literate person so bare with me on this… But. Still please becareful. There appears to be a vulnerability.
Users are posting images like the following:
And inside hidden is JavaScript code that when executed can take cookie information and send it to a URL address.
Among other things. At this time if you see an image please click the icon circled before clicking the link. DO NOT CLICK THE IMAGE. If you see anything suspicious, please report it immediately. It is better a false report than a missed one.
I have seen multiple posts by these people during the attack. It is most certainly related to JS.
So they should, child labour laws should apply to these kids just as any other business. The money earned from these videos need to be paid to the child. Even if it’s in a trust fund where the kid can take it out when they’re old enough and can make better decisions. Like child tv stars they need to only have to work a set amount of hours, no longer.
When I say this I’m talking about toy channels, I’m not talking about the mumfluencer channels. This kind of constant forceful filming of their childrens every moment should be stopped, kids need to have privacy, it’s known to be detrimental to their mental health when they’re constantly documented, and they are also far more likely to get bullied because of it.
I can’t begin to imagine all my bad childhood memories being immortalised thanks to a pushy parent who saw me as a money machines more than a person.