As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.
As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.
Why are they dropping support for Tesseract after Lemmy 1.0?
don’t want to maintain a solution from a bastard that clearly is untrustworthy.
If you fork it, the fork doesn’t belong to them. You can do what you want with it.
Besides, if they don’t want to maintain it, why don’t they stop maintaining it right now? What does Lemmy 1.0 have to do with it?
just because we found two things he did doesn’t mean there aren’t other surprises.
for all we know at this point, he’s implemented a backdoor into instances that use it.
if you’re an instance admin using tesseract and you’re reading this right now, you should probably drop it asap.
Yeah, I could see a credential stealer being smuggled into an alternative frontend…