Comment on UI Idea for one-click Lemmy account migration

Kinglink@lemmy.world ⁨1⁩ ⁨year⁩ ago

There’s two problems with this.

A. You’re now allowing people to hop, and even name change. Let’s say they’ll allow that.

B. You’re missing the password. Every instance should have a unique salt, passwords should NEVER be reversible, and never be stored insecurely (AKA before salting the hash for instance). I use a different password for every site, but I’ve had sites tell me “Your password is X” … holy shit that’s a HUGE security flaw for multiple reasons.

So if I’m migrating and don’t need to set a new password, that’d be questionable.

C. This can be done unscrupulously. If I get control of someone’s account, I can migrate it and essentially steal all their accounts.

source
Sort:hotnewtop