• Saik0@lemmy.saik0.com
    link
    fedilink
    English
    arrow-up
    30
    arrow-down
    1
    ·
    11 months ago

    While the login system works…

    It’s ripe for abuse though. DMs are federated traffic and are not cryptographically secured in any form. So in theory a bad actor instance admin could spawn unlimited accounts and login… Or just sniff incoming requests from whatever instance this traffic is spawned from and obtain the login code.

    For something like this, probably fine… But I wouldn’t use it for anything else, nor would I trust any app that does use this system.

    • Shadow@lemmy.ca
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      edit-2
      11 months ago

      Their original system required you to enter your creds + OTP, so this is a huge improvement 🤣

      • Saik0@lemmy.saik0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 months ago

        That’s how I just logged in.

        Gave instance, username on instance, and received inbox message on my lemmy instance. (also sniffed the message cause I was curious since I’m my instance admin)

          • Saik0@lemmy.saik0.com
            link
            fedilink
            English
            arrow-up
            2
            ·
            11 months ago

            I think they meant that too… But that’s not what was provided to login.

            I would not give up my instance password to another person. The list I provided was what I specifically provided.

  • 👁️👄👁️@lemm.ee
    link
    fedilink
    English
    arrow-up
    8
    ·
    11 months ago

    I’ve seen you on the reddit alternatives sub, voat, ruqqus, and now here lmao. One day you’ll get a non member osrs account.

    • OsrsNeedsF2POP
      link
      fedilink
      arrow-up
      6
      ·
      11 months ago

      What was your name on Ruqqus? That place was great, minus the rampant racism.

      The Ruqqus shutdown last year is what made me come to Lemmy full-time, taught me a good lesson on why you need federation

      • 👁️👄👁️@lemm.ee
        link
        fedilink
        English
        arrow-up
        6
        ·
        11 months ago

        My username was randomly generated and was 47RX6h. I mostly went on there to argue with right wingers but really I was just wasting my time lol. I got banned from most of the communities on there.

        • OsrsNeedsF2POP
          link
          fedilink
          arrow-up
          3
          ·
          11 months ago

          Oh wait, were you the one who started +OpenLeft?? I took over that community when you quit

      • 👁️👄👁️@lemm.ee
        link
        fedilink
        English
        arrow-up
        4
        ·
        11 months ago

        This was like within the first few months of Voat during one of the Reddit exoduses. I was on it for like a week in some meditation communities. Then yeah it pretty quickly turned into Nazi shit. Ruqqus was also Nazi shit.

    • 🦊 OneRedFox 🦊@beehaw.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 months ago

      It’s an open standard for granting clients access to APIs without needing to hand over things like your password each time.

  • Bappity@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    2
    ·
    11 months ago

    do I understand this correctly, it requires you to login to check your PMs for the code you need to login?