It seems like they are down for a longer time now. How will they recover? Does longer down mean they will have to do more catching up with other instances? Can I get updates somewhere?

  • WaveCommander@lemmy.ca
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 years ago

    Sites don’t store passwords, they store password hashes. There is no reason to give any personal info you aren’t comfortable giving. You can use the site just fine without posting any

    • Illogicalbit@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 years ago

      Hacking an account is still a valid concern though for various reasons , and hashes can still be used against password lists. Additionally, Two factor authentication is a necessity for sure. Now don’t get me wrong, I completely understand this feature is coming and that this is a developing service but many of these concerns do seem valid to me.

        • Illogicalbit@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 years ago

          Mostly thinking impersonation, spamming, deletion or modification of history…. Although I’m sure there are probably other reasons too.

          • areyouevenreal@lemmy.fmhy.ml
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 years ago

            What makes you think large social media platforms don’t have these exact problems? Because they definitely do.

            This software being open source will hopefully make it more secure one day than even things like twitter. This is because everyone can see and inspect the source code and try to find vulnerabilities. When they are fixed then (hopefully) all of the instances get updated. It’s what helps make Linux generally more secure than Windows.

            It seems to me you don’t see the value in open source platforms like this. If this is true then fair enough. Just don’t come crying to me when reddit does something you don’t like.

      • WaveCommander@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 years ago

        Simply salting hashes would be enough to prevent password hash list lookups. Agreed, 2FA is pretty essential, though I can understand not implementing it where people don’t care about the integrity of their pseudonyms. As it gains popularity, it will need to be implemented