Note: This post now archived and as such no longer works
This is possible because Lemmy doesn’t proxy external images but instead loads them directly. While not all that bad, this could be used for Spy pixels by nefarious posters and commenters.
Note, that the only thing that I willingly log is the “hit count” visible in the image, and I have no intention to misuse the data.
The best part is it also works on DMs, so it’s trivial to get any persons IP address. Want an admins IP address? Just DM them a message with an embedded spy pixel.
I emailed the lemmy developers about this a few weeks ago since IMHO it’s a pretty big security issue, no reply.
I think you’re overestimating the value of someone’s IP address. Not much one can do with it unless someone really tries to expose themselves.
Joke’s on you, I’m in front of 9 proxies. 🤡
Not really.
Jerdoa
You are viewing this from a
(rand() % 2 == 0) ? "android" : "apple"
phone.The post know where I am because it knows where I am not.
Very interesting, I think I’ll probably be using Tor for my Lemmy usage from now on, or at least a VPN since this does have the potential to be used maliciously in personal DDoS attacks.
Your IP isn’t a secret. There plenty of ways to get it. And this one doesn’t even link it to your identity
It’s not about identification it’s about being disconnected in a DoS by someone with faster internet (until I can get a new one, dynamic IP rotates).
DoS is expensive. Who the hell would spend money just to get you disconnected? Nobody cares about your connection
Annoyingly, lemmy.world blocks tor. They should host a tor onion service
Are you sure about that because I can open and view lemmy.world just fine in Tor, I think what they mean is federation between hidden services i.e. lemmyinstanceoniondomain.onion is blocked or just not implemented.
I can if I use a browser and solve the cloud flare capt ha, but not if I use sync behind tor
I haven’t gotten Cloudflare captchas on lemmy.world yet, Haven’t tried using an app with Tor, as a general rule it’s best to use Tor through the browser since it has features to reduce fingerprinting and MITMs
uBlock Origin? NoScript? Internet Explorer?
Liftoff, and the device has Blokada5 running but it didn’t block that.
What is the functioning process of this?