this post was submitted on 10 Mar 2025
82 points (94.6% liked)
Nicoled
336 readers
58 users here now
Hi, I'm Nicole! But you can call me the Fediverse Chick :D
For when you or others get nicoled.
founded 3 weeks ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I got my first cluster of DMs today. I notice that those with images are served from some random host. This could be the attack, just getting people to hit that server, tracking certain behaviors of thousands of users. Sure would be nice if Lemmy DMs didn't force my browser to hit any URL an attacker wants just by looking at my inbox.
That's an idea, I didn't think of the image hosting as an information gathering vector
These are definitely disused instances. Maybe somebody should figure out how to restrict federation on open signup instances if certain criteria isn't met.
https://lemmy.ca/post/40761824
Lemmy.ca has started blocking the DMs, i think her days on .ca are over.
I notice the DMs have even been purged from my inbox, which is a bold move.