1
505
Blahaj zone hacked (pen.blahaj.zone)
submitted 4 days ago* (last edited 2 days ago) by ada to c/main

Firstly, apologies to everyone for the extended downtime. Unfortunately, it was for a pretty bad reason. We were hacked.

The bad news is that it was a comprehensive attack, and the attackers had privileged access to our database system, across all of our services (except for writefreely, which doesn't use postgres). From what we can tell, the attacker did not do anything with that access, so we don't believe any user data was accessed, but we can't be certain of that. For lemmy, the impact of this should be minimal. If you registered with a real email address, they may have that. User passwords are encrypted in the database, so if you were using a secure, non trivial password, it should be safe, but you should still change it. You should also reset your 2 factor authentication if you had it enabled, as the seeds for these are not encrypted.

Our understanding is that the attacker used a peertube exploit, then a postgres exploit and then a kernel exploit to systematically gain access to different layers of our database server. A side effect of the hack was that it filled up our database servers hard drive, and caused it to fail over to our backup, which we believe mitigated some of the potential fall out.

We have had to reset activitypub keypairs for every account and community on lemmy, so there may be some federation hicoughs for a day or so, until remote servers have dropped any cached copies of our users public keys. This is uncharted territory though, so hopefully it's as smooth as we think it will be, but we can't be sure!

As stated earlier, our writefreely instance is still up and running as it wasn't impacted by this attack. Vernissage (our pixelfed replacement) has been brought back online, as has our matrix server.

We will be bringing up Sharkey, and then Piefed hopefully later today, but we have to rotate keypairs on those services too, which is also uncharted territory, so the timelines are hopes, not guarantees. At this point in time, we don't plan on bringing pixelfed back online, as it was slated for shutdown in August in any case. If people still need access to pixelfed to export data, we can spin it up briefly if needed, so please reach out if this is you. We also won't be bringing peertube back up at this point. It was not heavily utilised, and it was the source of the attack, so Kaity is a bit gun shy about spinning it back up on shared database infrastructure. If there is a strong desire to bring peertube back, we can consider doing that on isolated hardware, but at the current utilisation level, it doesn't seem worth the cost/effort to run it isolated.

in any case, you can read a fuller explanation of the attack by Kaity here https://pen.blahaj.zone/supakaity/weve-been-hacked

Edit - Piefed is back now!

2
35
submitted 30 minutes ago by Valuy@lemmy.zip to c/news@lemmy.world
3
35
4
18
submitted 23 minutes ago* (last edited 17 minutes ago) by Wudi@feddit.uk to c/politics@lemmy.world
5
52
6
74
7
98

Join the list any time before June 25th at 10 a.m. PT. On that date, the list will be closed and randomized, and you will receive an email with your results shortly after.

8
17

Just absolutely pathetic of this joke of an administration.

9
27
10
10
11
103
Steam machine prices are live (store.steampowered.com)
submitted 1 hour ago* (last edited 1 hour ago) by gwheel@lemmy.zip to c/steamdeck@sopuli.xyz

$1050 for 512gb no controller

12
20

I've gotten through (I believe) all the comments in the meta thread. So I want to establish a few things, first being a better definition on spam.

Spam is not "I don't like this and its a paid product" or "I don't like this and they used AI/LLMs".

Spam would generally be considered:

  • Mass-posting - Posting the exact same post across a bunch of of different communities, rapidly.
  • Repetitive Content (aka karma farming) - repeatedly submitting old popular content. I'll note that this is completely irrelevant on lemmy, this was more of a reddit issue due to karma.
  • Bot Activity / AI Abuse - Using scripts/bots/gen AI to automate posts and comments.
  • Unsolicited DMs - Mass private messages or chats to users, completely unsolicited

I'd say anything other than that deserves a followup rule, and this definition should go in the sidebar.

Regarding the promotional posts themselves, I think something like the 10% rule makes sense - no more than 10% of the account should be self-promotional material or comments within the community.

I do think it makes sense to include an exception for 100% free/libre open source projects. Partially open projects with a closed (paid) component should be subject to the 10% rule. So what I propose as the rule would be:

Promotional posts require community participation or they will be removed. No more than 10% of your posts or comments may be self-promotional, or your post will be removed. F/LOSS Exception: If your post is about a project that is completely open source & without any paywalls, it will be exempt from this rule.

Questions, comments, clarifications, and harsh criticisms are welcomed in the comments. As a reminder from my intro post, and because of some comments in the other thread, I will mention:

There are people on both sides of the keyboards, so please be respectful of others.

13
186
Hmmm, what shall we talk about? (img-9gag-fun.9cache.com)
14
121
15
9
submitted 23 minutes ago* (last edited 18 minutes ago) by supersquirrel@sopuli.xyz to c/FuckMusk@lemmy.ca

If his relationships to the people close to him are a train wreck, Musk’s relationship with the public isn’t much better. As the years go on, it’s become clear that he badly wants to be seen as cool, funny, and popular, and yet the harder he tries to win everyone’s admiration, the less cool he becomes. Lately, his public antics just exude a desperate, sweaty energy that makes him painful to watch.

There was the godawful “let that sink in” joke that he used to announce his arrival to Twitter’s headquarters, carrying a physical porcelain sink; the stupid X-shaped jumping jack he kept doing for a while, apparently to resemble the logo of “X the Everything App”; the cowboy hat incident; the photo he posted of his bedside table with a huge gun and four cans of Diet Coke on it; the poem (Maybe religion’s not so bad / To keep you from being sad). In his comprehensive, largely flattering biography, Walter Isaacson writes that Musk’s “jokes tended to be filled with smirking references to 69, other sex acts, body fluids, pooping, farts, dope smoking, and topics that would crack up a dorm room of stoned freshmen.” (More like a classroom of sixth-graders.)

[It seems that writing a methodical analysis of all the cringey things Elon Musk has done is such a odyssean feat that you begin to sound like James Joyce in your run on lists disguised as sentences that never end...]

At one point, Musk admitted that he pays other people to play video games for him, so he’ll quickly get the highest scores and levels and Twitch streamers will see him as a “living god of video games.” For him, the point is not to enjoy the games, but to acquire whatever token or icon marks you as having won them, and thus earn the admiration of nerds who watch livestreams all day. And he couldn’t even get that, because when Musk attempted to stream himself playing Path of Exile 2 last year, the audience trolled him relentlessly, posting “YOU HAVE NO REAL FRIENDS AND WILL DIE ALONE” over and over in the chat box. But just caring about this kind of thing in the first place is the pathetic part, and apparently no amount of money can fix that.

16
19
submitted 56 minutes ago by cm0002@toast.ooo to c/world@quokk.au
17
54
Steam Machine launches today! (store.steampowered.com)
18
22
submitted 59 minutes ago by NanoooK@sh.itjust.works to c/games@sh.itjust.works
19
102
submitted 1 hour ago* (last edited 1 hour ago) by Lurian@lemmy.world to c/politics@lemmy.world

His mom sat on the Senate Agriculture —which has jurisdiction over derivates — until this past year

20
9
submitted 31 minutes ago by Wudi@feddit.uk to c/europe@feddit.org
21
9
submitted 38 minutes ago* (last edited 35 minutes ago) by Valuy@lemmy.zip to c/fuckcars@lemmy.world
22
14
23
6
submitted 16 minutes ago by Zapados@sh.itjust.works to c/world@quokk.au
24
9
submitted 36 minutes ago* (last edited 34 minutes ago) by supersquirrel@sopuli.xyz to c/globalnews@lemmy.zip

The new proclamation would roll back protections for roughly 1.3 million km2 (500,000 mi2) of the area to allow industrial fishing. Such commercial fishing could include kilometers of baited hooks, known as long lines, and purse seine nets more than 2,000 meters (6,600 feet) long. Both types of fishing gear are highly effective at catching tuna, the target species, as well as other marine life as bycatch.

Conservationists say opening the Pacific monuments to industrial fishing is a significant concern for many species in the area, including threatened sea turtles, whales, dolphins, seabirds, sharks and fish; many are endemic, found nowhere else on Earth.

25
8
submitted 12 minutes ago by Godric@lemmy.world to c/lemmyshitpost@lemmy.world
view more: next ›

Blåhaj Lemmy

10,435 readers
380 users here now

Blåhaj Lemmy

Blåhaj Lemmy is brought to you by the kind folk at Blåhaj Zone, and while anyone is free to register for an account here, please bear in mind that this is a server that is very protective of our minority members and bigotry of any variety will be squashed with great prejudice.

We have several alternative lemmy frontends you can use. Just login with your regular blahaj login details.

We have a public matrix channel for all Blahaj users at #blahaj:chat.blahaj.zone

We also have a matrix channel for gender diverse folk and our allies! If you're already a matrix user, you can head straight to our application room https://matrix.to/#/#gv-apply:chat.blahaj.zone, or by searching for #gv-apply:chat.blahaj.zone from within your matrix client.

If you're new to matrix, you can find some more details and an instruction video on how to get up and running here https://chat.blahaj.zone/c/genderverse/

Community Guidelines

Blåhaj Lemmy is a space where everyone should feel able to participate safely, and to that end, our community is built on the guiding philosophies of empathy, inclusion and acceptance.

Empathy

We want our community members to be guided by compassion and empathy for others.

Examples of behaviour that are contrary to this philosophy are personal attacks, insults, doxing etc. If your comment is designed to hurt someone, this isn't the space for it.

Inclusion and Acceptance

Embracing inclusion and acceptance means listening when people tell you who they are and what their needs are. It means not telling people that you know their experiences better than they do. It means not gatekeeping experiences of identities of others. It means no bigotry such as racism, sexism, anti LGBT commentary, ableism etc. It means doing your best to ensure that you don't over-talk the voices of folk who don't share your privileges.

Supporting Blåhaj Lemmy

After much hesitation, we have a Ko Fi to enable people to help with supporting some of the running costs associated with our instances.

Providing a safe space for our community is the goal, so please only consider donating if you are in a position to do so without any financial stress.

Mascot and logo

Find out about our mascot Shonky (they/them) who appears on our site logo here.

--

founded 3 years ago
ADMINS