this post was submitted on 10 Jul 2023
92 points (96.9% liked)

Lemmy.ca's Main Community

3283 readers
1 users here now


Welcome to the lemmy.ca/c/main community!

All new users on lemmy.ca are automatically subscribed to this community, so this is the place to read announcements, make suggestions, and chat about the goings-on of lemmy.ca.

For support requests specific to lemmy.ca, you can use !lemmy_ca_support@lemmy.ca.


founded 4 years ago
MODERATORS
92
Lemmy.world is compromised (talk.kururin.tech)
submitted 2 years ago* (last edited 2 years ago) by Kururin@talk.kururin.tech to c/main@lemmy.ca
 

They been redirecting to lemon party and some weird video. Do not go to the website. This is the admin that been hacked:

EDIT: lemmy.blahaj.zone also compromised!

you are viewing a single comment's thread
view the rest of the comments
[–] PenguinTD@lemmy.ca 2 points 2 years ago (2 children)

Is there a way to not do email verification but still using 2FA? That way, even if a user's account is somehow phished/compromised, it won't compromise their other accounts.

[–] TruckBC@lemmy.ca 3 points 2 years ago

I just successfully set up 2FA for an account on another instance that doesn't have a verified email without any issues, so there's no need to have done email verification to use 2FA.

[–] elscallr@kbin.social 1 points 2 years ago

Absolutely you can do no phone/email and MFA. It's a TOTP thing like Google or Microsoft authenticator. The service doing the authentication has no idea how it's done on the other side, it just makes sure the codes match.