this post was submitted on 09 Aug 2023
88 points (100.0% liked)
Asklemmy
43831 readers
1020 users here now
A loosely moderated place to ask open-ended questions
Search asklemmy ๐
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- !lemmy411@lemmy.ca: a community for finding communities
~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Exactly this, I don't see why everyone is so obsessed with cracking the passwords in the database.
Evil instance admin guide:
This won't work against people who never log in again. Active users will.
If the admin just wants to impersonate you... they can just generate a session under your account name and do that. 2FA doesn't stop them, difficult passwords doesn't stop them, OAuth doesn't stop them.
There's no way for other admins validate if someone is actually getting hacked by their admin or if they're just being dicks spreading rumours.
The best you can do is create a new account and always cryptogroahically sign your messages using a key stored offline on your computer..There are PGP applications for every platform. If you and someone you DM both have PGP keys, you can even use that to send end-to-end encrypted messages. If everyone does that, unsigned posts can essentially he discarded by the community as fakes.
This won't stop the admin from faking your account downvoting everyone, subscribing you to pedo communities, or messing with your account. The admin can also post things like "I don't have my PGP key on this phone, I'll sign this later" and delete any of your messages that indicate any protest against the admin's actions. The admin can even strip the signature from all of your previous posts and replace with with a different signature using a key of theirs. Only if you and everyone around you know that your messages should always be signed by a certain key, are you free from admin interference.
Just like every other online platform (that isn't run by cryptobros).
You can only avoid all of this by hosting stuff yourself and being your own admin.