4
submitted 1 year ago by DrYes@lemmy.world to c/lemmy@lemmy.ml
  1. I create a well crafted post to a normal site that gets 10.000 upvotes.

  2. I change the URL to a malicious site.

  3. ??????

  4. Profit

top 7 comments
sorted by: hot top controversial new old
[-] Sal@mander.xyz 1 points 1 year ago

It makes it a little bit easier to do, but it is not difficult to replicate this effect without changing the URL in the title - using a redirected URL and changing the redirect address, for example.

I think that this small increase in the way this kind of attack can be delivered is more than counter-balanced by the convenience of having editable titles.

[-] morrowind@lemmy.ml 0 points 1 year ago

Most subreddits also blocked redirect links for (partially) reason.

[-] Sal@mander.xyz 1 points 1 year ago* (last edited 1 year ago)

You don't need to use a known redirect link. If the plan begins with a post that obtains 10,000 likes, I am sure the attacker can spend a small amount of effort and register a domain.

[-] deweydecibel@lemmy.world 0 points 1 year ago

Surely you don't think that's equivalent to a simple 5 second copy paste of a new URL into the textbox, right?

And it's not just about attack vectors, it's also about stealth ads and misinformation

[-] Cinner@kbin.social 1 points 1 year ago

I'm not sure what you're getting at but he's right, it's incredibly simple to setup a new redirect site.

[-] SheeEttin@lemmy.world 1 points 1 year ago

Yeah, this is why reddit didn't allow it. I don't think Lemmy should either.

[-] BombOmOm@lemmy.world -4 points 1 year ago* (last edited 1 year ago)

The url and title should both be locked after a post. The contents should be free to change, that way updates and such can be posted if necessary.

Comments can continue to work as-is, there is a similar danger there, but it doesn't matter nearly as much.

this post was submitted on 19 Jun 2023
4 points (100.0% liked)

Lemmy

11947 readers
54 users here now

Everything about Lemmy; bugs, gripes, praises, and advocacy.

For discussion about the lemmy.ml instance, go to !meta@lemmy.ml.

founded 4 years ago
MODERATORS