• henfredemars@infosec.pub
    link
    fedilink
    English
    arrow-up
    22
    ·
    23 hours ago

    And we’re able to talk about it on the same platform on another instance. All in all, a success IMHO.

    • AbnormalHumanBeing@lemmy.abnormalbeings.space
      link
      fedilink
      arrow-up
      7
      ·
      edit-2
      23 hours ago

      I guess in theory, malicious actors have some options trying to target and overload all of the Fediverse, but I don’t think any are really feasible. At the point, where you could take out the (vast majority of) nodes with something like a DDOS, you already had enough resources to spare, to take out just significant parts of the overall internet altogether.

      0-day exploits could of course be problematic, as they are for anything, but even then, using one on all (or then majority of) nodes simultaneously, and/or distributing a payload to all/the majority of nodes is also just so much effort. Also, chances are quite low you will get an exploit for all platform software, and if it targets something in ActivityPub, then all you can do at best is stifling federation, I guess, still allowing for local content to remain up.

      Not only censorship resilient and with dynamic interlocking communities, also pretty damn resilient when it comes to overall uptime security.

      • b1t@lemm.ee
        link
        fedilink
        English
        arrow-up
        12
        ·
        23 hours ago

        If someone is burning 0days for fucking Lemmy they seriously need to get some help and re-evaluate their life choices lol

    • Rhaedas@fedia.io
      link
      fedilink
      arrow-up
      5
      ·
      23 hours ago

      The biggest limitation left is for users of that instance. The workaround is to make accounts on one or more different instances, even often with the same handle just different addresses. Then you most likely can get back to consumption until your main account is working again. The caveat is there isn’t a way (yet*) to share a lot of the info between those accounts to make it feel less like a temp account. Still far better than refreshing a singular website status page over and over.

      • yet or even if it’s practical. I know some played with a few importing ideas early on for themes and I think subscriptions, but I doubt anything more. History and such would open a lot of security issues.
      • henfredemars@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        21 hours ago

        I’ve definitely taken the main and back up approach. Not perfect, but it’s worked reasonably well.

  • scsi@lemm.ee
    link
    fedilink
    arrow-up
    14
    ·
    22 hours ago

    https://lemmy.ca/post/40456774

    Sorry for the downtime! Unfortunately our secondary firewall took over for some reason, and haproxy failed to properly come up.

    I’ll be scheduling a maintenance window in the next few days to do some further digging, so I can make sure this is fully resolved.