Admin of lemmy.blahaj.zone

I can also be found on the microblog fediverse at @ada@blahaj.zone or on matrix at @ada:chat.blahaj.zone

  • 2 posts
  • 4 comments
Joined 4 years ago
Cake day: January 2nd, 2023
  • Because I don’t believe that kids (or people in generally) magically develop effective techniques for dealing with addiction and bullying when they reach a certain arbitrary age. They don’t suddenly know how to deal with complex social situations when they turn 16. They don’t know instantly gain knowledge of how to deal with the addictive nature of gamified social media platforms when they turn 16. So hiding them from that stuff, and then letting their first exposure to it be when they’re trying to learn to be independent and less likely to look for answers outside of their own experience solves nothing.

    Social media can be addictive, screen time can be addictive, and navigating online scammers, bullies and fraudsters is something that takes experience to work recognise and work through.

    So I approached it by talking to my kid about recognising what this stuff looks like, about the importance of not revealing personal information, of asking questions if they have doubts. I also let them have as much screen time as they wanted, and told them that the issue isn’t how much time they spend in front of the computer, the issue is whether the computer is the only thing they want to spend time with. If they always say no when someone asks if they want to do something else, if the devices start to get in the way of life, and they never want to leave their room, get resentful at having to do chores etc, then the balance is off. And that’s what I cared about. Teaching the kid how to fit this stuff in to their life whilst they were young enough to still take my advice onboard.

    That’s why

    Edit - Unrelated, but maybe not unrelated, I also told me kid I don’t care if they swear around the house, with their friends or whatever. However, I also told them that lots of people do care if they swear, and they need to be aware of the impact that their choice of words has on the people around them. Swearing at a teacher at school for example, is going to get them in trouble, and “I can swear at home” isn’t an excuse for that. I tried to teach my child that the issue isn’t the words, but rather, the way your words impact the people around you and your relationships with them.

    Kids need to learn by doing and by trying. They don’t learn by being told by their parents “this is how it is”. And the more hard rules you put in front of them, the more things they have the need to rebel against and push back against when they try and find their independence. And every single kid that has ever lived explores and pushes at boundaries in some form or another. So don’t turn the shitty harmful things in to forms of finding independence.

    You give kids independence by giving them agency in their own life, and the life experience to use that agency in an informed way.

Firstly, apologies to everyone for the extended downtime. Unfortunately, it was for a pretty bad reason. We were hacked.

The bad news is that it was a comprehensive attack, and the attackers had privileged access to our database system, across all of our services (except for writefreely, which doesn’t use postgres). From what we can tell, the attacker did not do anything with that access, so we don’t believe any user data was accessed, but we can’t be certain of that. For lemmy, the impact of this should be minimal. If you registered with a real email address, they may have that. User passwords are encrypted in the database, so if you were using a secure, non trivial password, it should be safe, but you should still change it. You should also reset your 2 factor authentication if you had it enabled, as the seeds for these are not encrypted.

Our understanding is that the attacker used a peertube exploit, then a postgres exploit and then a kernel exploit to systematically gain access to different layers of our database server. A side effect of the hack was that it filled up our database servers hard drive, and caused it to fail over to our backup, which we believe mitigated some of the potential fall out.

We have had to reset activitypub keypairs for every account and community on lemmy, so there may be some federation hicoughs for a day or so, until remote servers have dropped any cached copies of our users public keys. This is uncharted territory though, so hopefully it’s as smooth as we think it will be, but we can’t be sure!

As stated earlier, our writefreely instance is still up and running as it wasn’t impacted by this attack. Vernissage (our pixelfed replacement) has been brought back online, as has our matrix server.

We will be bringing up Sharkey, and then Piefed hopefully later today, but we have to rotate keypairs on those services too, which is also uncharted territory, so the timelines are hopes, not guarantees. At this point in time, we don’t plan on bringing pixelfed back online, as it was slated for shutdown in August in any case. If people still need access to pixelfed to export data, we can spin it up briefly if needed, so please reach out if this is you. We also won’t be bringing peertube back up at this point. It was not heavily utilised, and it was the source of the attack, so Kaity is a bit gun shy about spinning it back up on shared database infrastructure. If there is a strong desire to bring peertube back, we can consider doing that on isolated hardware, but at the current utilisation level, it doesn’t seem worth the cost/effort to run it isolated.

in any case, you can read a fuller explanation of the attack by Kaity here https://pen.blahaj.zone/supakaity/weve-been-hacked

Edit - Piefed is back now!