This is a valid privacy issue, and other fediverse projects like Mastodon already solve this. The problem is that by embedding an image, you can tell the client to make a network request to your server, revealing information such as your IP address and browser. The solution is to proxy media through your instance, which is presumably trusted. this hides your IP address and browser information. And as someone else mentioned here, a Content-Security-Policy can be used to ensure this attack isn’t possible in a browser.
- 0 Posts
- 18 Comments
Any thoughts on how fixable this is?
This shouldn’t be hard to fix. Lemmy needs to proxy images, there’s an open issue for this. Right now, I don’t use Lemmy outside of Tor Browser specifically because of issues like this, and the recent XSS vulnerability is making me even more concerned. Lemmy is a great project, but it needs work and probably a security audit.
CanOpener@sh.itjust.worksto
Selfhosted@lemmy.world•Plex and Mullvad now that port forwarding is goneEnglish
61·3 years agoI use Tailscale with my Jellyfin server.
CanOpener@sh.itjust.worksto
Firefox@lemmy.ml•Firefox plugin to click through cookie popups.English
4·3 years agoEnable AdGuard - Cookie Notices and EasyList - Cookie Notices under Filter lists > Annoyances > AdGuard - Annoyances / EasyList - Annoyances in uBlock Origin
The domain for Threads is threads.net, not threads.com
CanOpener@sh.itjust.worksto
Privacy Guides@lemmy.one•Lighttube - A lightweight, privacy respecting alternative frontend for YouTube written in ASP.NETEnglish
4·3 years agoProbably not, Piped supports higher resolutions and better video formats.
CanOpener@sh.itjust.worksto
Privacy Guides@lemmy.one•Lighttube - A lightweight, privacy respecting alternative frontend for YouTube written in ASP.NETEnglish
5·3 years agoImages don’t seem to be proxied.

CanOpener@sh.itjust.worksto
Selfhosted@lemmy.world•Which kind of command/apps you always wanted to self-host but you never bothered doing so because it's "overkill"?English
1·3 years agoI use Traefik and configuring everything through docker-compose files is way more convenient than nginx or a proxy manager (never used one though). Traefik also has a web interface, but you can’t configure anything with it.
CanOpener@sh.itjust.worksto
Privacy Guides@lemmy.one•YouTube tests disabling videos for people using ad blockersEnglish
3·3 years agoOdysee is a right wing cesspool with no moderation and crypto is a complete scam at this point. https://thelinuxexp.com/Im-leaving-odysee/
CanOpener@sh.itjust.worksto
Privacy Guides@lemmy.one•YouTube tests disabling videos for people using ad blockersEnglish
2·3 years agoTry tilvids.com. PeerTube doesn’t have much content right now, and it’s mostly videos with 1-3 views.
CanOpener@sh.itjust.worksto
Privacy Guides@lemmy.one•YouTube tests disabling videos for people using ad blockersEnglish
14·3 years agoIf they break Piped and Invidious, I guess I’ll have to only watch Nebula content.
CanOpener@sh.itjust.worksto
Privacy Guides@lemmy.one•YouTube tests disabling videos for people using ad blockersEnglish
25·3 years agoOdysee is a right wing cesspool with no moderation: https://thelinuxexp.com/Im-leaving-odysee/
CanOpener@sh.itjust.worksto
Privacy Guides@lemmy.one•Is it possible to protect my privacy while disabling uBlock to support some websites?English
2·3 years agoNot really. Allowing any form of advertising will harm your privacy because you will be tracked. You could use Tor Browser which would make the advertising requests anonymous and prevent anything from being saved.
Immediately hitting the back button.
I’ve always found Riseup to be super slow and Proton VPN to be fast. Maybe try changing your protocol to WireGuard in the Proton VPN settings?
CanOpener@sh.itjust.worksto
Privacy Guides@lemmy.one•what imgur alternatives do you use to share images?
1·3 years agoThis is a privacy risk because Lemmy doesn’t proxy external media (or cache remote media like Mastodon). It’s also better for longevity, if an external image host the image is gone.
Fedora. Used to use Arch but it broke and I moved to Fedora, it’s a way more polished experience. I like how Fedora is stable but not “stale” like Debian. Want to try Fedora Silverblue as well.


Apple Maps is the best replacement for Google Maps. None of the other options even come close, but it’s only for Apple devices. Organic Maps may work for you but it depends where you are and you won’t get traffic information and the routing is very basic.