Skip Navigation
Lemmy Support @lemmy.ml yesbutnobutyesbutno @sh.itjust.works
Possible security issues?

cross-posted here from https://sh.itjust.works/post/1658215 to get some additional feedback on this.

> Hi, > > As my regular instance was experiencing downtime, I decided it might be a good idea to have a backup account on a different instance. So I created a new account on feddit.uk, configured 2FA and all was well. Although… > > > When I later tried to log on using Voyager, it kept returning a connection error. I tried logging on to the instance directly using the browser: no error, but just lands back on the login page. > > > Seems like the issue was caused because of the password length (originally 65 characters). Resetting my password and bringing it down to 45 characters resolved the issue. However, directly after the password reset, I was logged in, and my 2FA code wasn't asked?! > > > For a minute I thought it might be due to cached credentials, but retrying the same scenario in a private window confirmed it. This means that if your e-mail account is compromised, 2FA will no longer protect you. > > > Another possible issue (just to be clear, in this scenario, your e-mail account is not compromised): if someone is able to access your account (maybe you forgot to log out), they can modify your e-mail address without you being notified, nor do they need to know your password. A verification e-mail will be sent to the new address, and they can reset your password using the approach described above. The new e-mail address does not need to be verified to do so (a verification e-mail is sent, but resetting the password works even if you don't verify), and the old e-mail address is not given a heads up of the change (I know, the old address might no longer work, but still). > > > Not only can your password be reset this way, after gaining entry, 2FA can be disabled without issue. > > > Am I wrong in thinking the scenarios described above are security issues? > Thanks for your feedback!

5
Long username & photo post issue

As you can see, for accounts with long usernames, the username is not truncated when looking at the posts or comments overview, causing it to overflow into the title area.

One more thing: if you create a new post, add a photo, then type the post text, you’ll get a message saying “please add a photo” when tapping “Post” (see second screenshot).

0
Keyboard issues on iOS

This is a very weird bug, and I’ve only encountered it once before on my iPad, but it just happened on my iPhone too.

Basically, when tapping a text field, the keyboard will no longer show up. You’ll notice at the bottom there’s a small toolbar that appears (which seems to be the top of the keyboard), but nothing more.

In the screen recording you’ll first see the issue being reproduced in Voyager (standalone), then with Voyager in Safari (where it works correctly).

I’ve tried reinstalling Voyager, but no joy. Strange thing is that the issue only presents itself in the (standalone) app, not while using it in Safari (as you can see from the screen recording).

FYI: I’m running iOS 16.6 (but it also happened before on iPadOS 16.5).

6
Just wanted to say...
  • I've been testing other Lemmy iOS apps (Mlem, Avelon, Thunder, Lemmios, Liftoff, Memmy and Bean), and for me personally, Voyager beats them all in terms of design, features, releases and app performance.

    The latter rather surprised me, but when scrolling and otherwise interacting with a post with a very large number of (nested) comments, Voyager showed no hiccups whatsoever, while some of the native apps really struggled.

    Yes, I know the scrolling sometimes "hangs", but that's because of a bug with Safari, not Voyager, so you can't really fault the app for that (well you can, but I won't).

    Great work, much appreciated. This certainly helps to cope with the loss of Apollo.

  • I heard that lemmy.ml is going to die soon, how to I sync all my subscribed communities to another sccount on another instence?
  • Thanks for this, works like a charm and exactly what I needed. Especially nice that it does a delta and not simply overwrites the target profile (as I already had some new communities I was following in the target account).

    Only thing I missed was a swap or reverse for Download and Upload, as I wanted to sync both accounts. Just meant I had to fill in both forms again, no biggie.

    Thanks again!

  • Possible security issues?

    Hi,

    As my regular instance was experiencing downtime, I decided it might be a good idea to have a backup account on a different instance. So I created a new account on feddit.uk, configured 2FA and all was well. Although…

    When I later tried to log on using Voyager, it kept returning a connection error. I tried logging on to the instance directly using the browser: no error, but just lands back on the login page.

    Seems like the issue was caused because of the password length (originally 65 characters). Resetting my password and bringing it down to 45 characters resolved the issue. However, directly after the password reset, I was logged in, and my 2FA code wasn't asked?!

    For a minute I thought it might be due to cached credentials, but retrying the same scenario in a private window confirmed it. This means that if your e-mail account is compromised, 2FA will no longer protect you.

    Another possible issue (just to be clear, in this scenario, your e-mail account is not compromised): if someone is able to access your account (maybe you forgot to log out), they can modify your e-mail address without you being notified, nor do they need to know your password. A verification e-mail will be sent to the new address, and they can reset your password using the approach described above. The new e-mail address does not need to be verified to do so (a verification e-mail is sent, but resetting the password works even if you don't verify), and the old e-mail address is not given a heads up of the change (I know, the old address might no longer work, but still).

    Not only can your password be reset this way, after gaining entry, 2FA can be disabled without issue.

    Am I wrong in thinking the scenarios described above are security issues? Thanks for your feedback!

    0
    [Self Promo] I've just made Avelon (a native iOS app for Lemmy) available for download!
  • I’m quite a fan of voyager (née wefwef), but out of curiosity, I tend to install all lemmy apps and give them a whirl.

    I have to say, there is quite a lot to like about your app. I’m very curious to see where it goes next.

  • Which e-mail service should I use?
  • I've been using Fastmail for almost a decade now, and extremely satisfied by the service, privacy, features and price.

    If you're interested in signing up for it, I have a referral link (the above one isn't it, I'm not that shady) you can use for a 10% discount on your first year.

    Good luck with the search.

  • PWA of macOS

    I quite love wefwef (ahem Voyager), building on the legacy of Apollo and filling the hole caused by the whole Reddit kerfuffle (obligatory fuck u/spez).

    Due to being averse to everything Google, I only use Safari (FF if there is some kind of technical issue where Safari is causing issues). From what I gathered researching on the web, there doesn't seem to be any support for PWA in either of those browsers.

    I'm currently running Voyager in a pinned tab, but if anyone has any suggestions to improve usability, I'd love to hear them. Thanks!

    10
    I feel like we should federate with threads.net
  • No thank you. I've done my best to keep everything Meta out of my life (and by extension, Twitter, TikTok, YouTube, etc), despite peer pressure. Throughout its history, Meta (basically le Zuck and friends) have demonstrated their unquenchable greed and with it their immeasurable ego to justify their actions, however immoral.

    I don't use Gmail. I pay for a service that provides me email and respects my privacy. If you want to use Gmail, be my guest. Should you? Definitely not. Same goes for Facebook, Whatsapp, Instagram and the latest incarnation: Threads. If I want to talk to people on Threads, I'll create a Threads account.

  • InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)YE
    yesbutnobutyesbutno @sh.itjust.works
    Posts 5
    Comments 15