this post was submitted on 10 Jul 2023
        
      
      3279 points (99.3% liked)
      Lemmy.World Announcements
    30725 readers
  
      
      1 users here now
      This Community is intended for posts about the Lemmy.world server by the admins.
Follow us for server news ๐
Outages ๐ฅ
https://status.lemmy.world/
For support with issues at Lemmy.world, go to the Lemmy.world Support community.
Support e-mail
Any support requests are best sent to info@lemmy.world e-mail.
Report contact
- DM https://lemmy.world/u/lwreport
- Email report@lemmy.world (PGP Supported)
Donations ๐
If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.
If you can, please use / switch to Ko-Fi, it has the lowest fees for us
Join the team
        founded 2 years ago
      
      MODERATORS
      
    you are viewing a single comment's thread
view the rest of the comments
    view the rest of the comments
So, do we change passwords, esp those who logged on during the attack? (I created this acct right before the attack happened tho.)
No, passwords weren't compromised
I think it's good practice to change passwords after an attack no matter what
If you don't use a randomly generated password, it's a good idea to change it anyway. Not because of this specific attack but in general. For the longest time the Lemmy software was just a hobby of a very small group of individuals. While the back-end is written in Rust and probably more robust than the PHP code over at Kbin, I don't think a proper security review was ever conducted, so there's a not so small chance there will be some additional growing pains in the somewhat near future.
According to the admin, no, but changing your password and keeping your data safer is always totally fine to do and you should probably do it every once in a while regardless.