This is a valid privacy issue, and other fediverse projects like Mastodon already solve this. The problem is that by embedding an image, you can tell the client to make a network request to your server, revealing information such as your IP address and browser. The solution is to proxy media through your instance, which is presumably trusted. this hides your IP address and browser information. And as someone else mentioned here, a Content-Security-Policy can be used to ensure this attack isn’t possible in a browser.
- 0 Posts
- 18 Comments
Any thoughts on how fixable this is?
This shouldn’t be hard to fix. Lemmy needs to proxy images, there’s an open issue for this. Right now, I don’t use Lemmy outside of Tor Browser specifically because of issues like this, and the recent XSS vulnerability is making me even more concerned. Lemmy is a great project, but it needs work and probably a security audit.
CanOpener@sh.itjust.worksto Selfhosted@lemmy.world•Plex and Mullvad now that port forwarding is goneEnglish61·2 years agoI use Tailscale with my Jellyfin server.
CanOpener@sh.itjust.worksto Firefox@lemmy.ml•Firefox plugin to click through cookie popups.English4·2 years agoEnable AdGuard - Cookie Notices and EasyList - Cookie Notices under Filter lists > Annoyances > AdGuard - Annoyances / EasyList - Annoyances in uBlock Origin
The domain for Threads is threads.net, not threads.com
CanOpener@sh.itjust.worksto Privacy Guides@lemmy.one•Lighttube - A lightweight, privacy respecting alternative frontend for YouTube written in ASP.NETEnglish4·2 years agoProbably not, Piped supports higher resolutions and better video formats.
CanOpener@sh.itjust.worksto Privacy Guides@lemmy.one•Lighttube - A lightweight, privacy respecting alternative frontend for YouTube written in ASP.NETEnglish5·2 years agoImages don’t seem to be proxied.
CanOpener@sh.itjust.worksto Selfhosted@lemmy.world•Which kind of command/apps you always wanted to self-host but you never bothered doing so because it's "overkill"?English1·2 years agoI use Traefik and configuring everything through docker-compose files is way more convenient than nginx or a proxy manager (never used one though). Traefik also has a web interface, but you can’t configure anything with it.
CanOpener@sh.itjust.worksto Privacy Guides@lemmy.one•YouTube tests disabling videos for people using ad blockersEnglish3·2 years agoOdysee is a right wing cesspool with no moderation and crypto is a complete scam at this point. https://thelinuxexp.com/Im-leaving-odysee/
CanOpener@sh.itjust.worksto Privacy Guides@lemmy.one•YouTube tests disabling videos for people using ad blockersEnglish2·2 years agoTry tilvids.com. PeerTube doesn’t have much content right now, and it’s mostly videos with 1-3 views.
CanOpener@sh.itjust.worksto Privacy Guides@lemmy.one•YouTube tests disabling videos for people using ad blockersEnglish14·2 years agoIf they break Piped and Invidious, I guess I’ll have to only watch Nebula content.
CanOpener@sh.itjust.worksto Privacy Guides@lemmy.one•YouTube tests disabling videos for people using ad blockersEnglish25·2 years agoOdysee is a right wing cesspool with no moderation: https://thelinuxexp.com/Im-leaving-odysee/
CanOpener@sh.itjust.worksto Privacy Guides@lemmy.one•Is it possible to protect my privacy while disabling uBlock to support some websites?English2·2 years agoNot really. Allowing any form of advertising will harm your privacy because you will be tracked. You could use Tor Browser which would make the advertising requests anonymous and prevent anything from being saved.
Immediately hitting the back button.
I’ve always found Riseup to be super slow and Proton VPN to be fast. Maybe try changing your protocol to WireGuard in the Proton VPN settings?
CanOpener@sh.itjust.worksto Privacy Guides@lemmy.one•what imgur alternatives do you use to share images?1·2 years agoThis is a privacy risk because Lemmy doesn’t proxy external media (or cache remote media like Mastodon). It’s also better for longevity, if an external image host the image is gone.
Fedora. Used to use Arch but it broke and I moved to Fedora, it’s a way more polished experience. I like how Fedora is stable but not “stale” like Debian. Want to try Fedora Silverblue as well.
Apple Maps is the best replacement for Google Maps. None of the other options even come close, but it’s only for Apple devices. Organic Maps may work for you but it depends where you are and you won’t get traffic information and the routing is very basic.