How much effort would it be for them to create a new one and do it again?
Minimal, but it is the domain that gets blocked so the attacker would still need to purchase a new domain.
anarchiddy@lemmy.dbzer0.com 1 week ago
Seems relatively painless to chop those two instances off - chinese.lol has less than 200 users, and I can’t even find instance info for doesnotexist.club (coincidence? i think NOT).
I do personally wonder how difficult it is to spin up new instances though. How much effort would it be for them to create a new one and do it again?
I’m actually most concerned with the IP leaking of the fediverse chick posts - hopefully some progress has been made with the IP leaking in auto-loaded external media through DM’s
How much effort would it be for them to create a new one and do it again?
Minimal, but it is the domain that gets blocked so the attacker would still need to purchase a new domain.
Not with sub domains.
I checked the images and so far every image I’ve encountered linked to the users’s lemmy instance’s pictrs instance.
I’m actually most concerned with the IP leaking
I’m curious, what is it about IP leaking that concerns you? I’ve been thinking about it lately but I have a hard time seeing why it’s a problem.
For one, you now know there is someone on the other end, so you can target your attacks instead of trying random ips.
That’s what I’m afraid of. Once some bad actors realize Lemmy is as defenseless as it is, it’ll be carnage for a while. The only tool we have is defederation and it’s slow and borderline useless against spam or worse.
fairly low effort but annoying like one click with yunohost
asudox@lemmy.asudox.dev 1 week ago
Some instances enable the image proxy, which should prevent this.