Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)P
Posts
58
Comments
564
Joined
1 yr. ago

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • Yeah, don't they realize they could have just spent that time productively by making a pull request, instead?

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  •  
        
    --- a/docker-compose.yml	2025-07-12 00:17:33.050443300 +0000
    +++ b/docker-compose.yml	2025-07-12 00:18:21.038972526 +0000
    @@ -37,7 +37,7 @@
         image: dessalines/lemmy-ui:0.19.12
         environment:
           - LEMMY_UI_LEMMY_INTERNAL_HOST=lemmy:8536
    -      - LEMMY_UI_LEMMY_EXTERNAL_HOST=lemmy.ml
    +      - LEMMY_UI_LEMMY_EXTERNAL_HOST={{ domain }}
           - LEMMY_UI_HTTPS=true
         volumes:
           - ./volumes/lemmy-ui/extra_themes:/app/extra_themes
    
      

    Edit: From https://github.com/LemmyNet/lemmy-docs/tree/main/assets

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  •  
        
    --- a/docker-compose.yml	2025-07-12 00:17:33.050443300 +0000
    +++ b/docker-compose.yml	2025-07-12 00:18:21.038972526 +0000
    @@ -37,7 +37,7 @@
         image: dessalines/lemmy-ui:0.19.12
         environment:
           - LEMMY_UI_LEMMY_INTERNAL_HOST=lemmy:8536
    -      - LEMMY_UI_LEMMY_EXTERNAL_HOST=lemmy.ml
    +      - LEMMY_UI_LEMMY_EXTERNAL_HOST={{ domain }}
           - LEMMY_UI_HTTPS=true
         volumes:
           - ./volumes/lemmy-ui/extra_themes:/app/extra_themes
    
      

    Edit: Just to be clear, this applies to https://github.com/LemmyNet/lemmy-docs/tree/main/assets which is linked to from https://join-lemmy.org/docs/administration/install_docker.html

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • I am not typing here in the hopes that they will fix it. I am typing here to communicate to other users what's up with it. Whether or not to fix it is up to them. You're welcome to your opinion.

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • I think it would be very rare that people would put two and two together to realize that their password had been "stolen" by this event. Like I say, I have no real idea even if it is being stolen, just that it would be trivial for .ml to decide that they wanted to start keeping a little cache of everyone's admin email addresses and passwords.

    Like someone else said, if it was anyplace other than lemmy.ml, I wouldn't give it a second thought, it would just be "whoa you gotta fix this." I sort of agree with you that there's not even really any strong indication that there's anything all that bad they could do with it. It's only because lemmy.ml moderation actions already have such a pattern of authoritarian dishonesty that I get to any degree paranoid or alarmed about it.

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • Within the last hour, dessalines has posted three things about communism that are longer than the fix for this issue.

    Edit: Everyone's got the right to do whatever they want to do. I'm not trying to accuse anyone of not spending enough time making software for me, just because occasionally they might want to do some other things with their life. The thing I'm trying to emphasize with this is how short the fix is. It's seconds. It's not one of those "but you have to recompile, what about this other branch" or anything like that. It's literally a fairly critical security fix with 100% of the fix in a one-line change to a documentation file.

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • Did you use a different admin password when you did the new setup after fixing it? If not, I think you should change your admin password.

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • The longer I look at it the more suspicious I am of it, to be honest. I'm just kind of generally a paranoid and accusatory person, so take that into account, but... the files are pretty carefully set up. They have variable substitutions for everything, including a bunch of places where there's a template substitution to change a string around when setting cache keys so that it'll still work out-of-the-box right away, even in complex configurations like multiple domains on a single server. It all works out-of-the-box right away, they've clearly been attentive to making sure it's all set up right and keeps working cleanly as things have been evolving forward. Except for that one place.

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • I cannot imagine any responsible dev who would read this notification and say anything other than "Oh shit, yeah, that's really bad," and fix it on the spot before they continue with whatever they had visited Lemmy to do. Like I say, it's relevant that it takes literally seconds to grasp the issue and fix it.

    I don't fully disagree with you, I get it, github issues is where issues with the software belong. I wasn't trying to be a jerk by suggesting that you do it. Anyone from these comments is welcome to. But, also, I am sort of curious about what their reaction will be. Finding out that kind of thing is interesting to me.

    If they are actively uninterested in fixing it, however they get made aware of it, then that's really interesting.

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • It would literally take me longer to make the github issue than it would take them to fix it, by quite a big margin. You can make one for it, if you still feel super-strongly about it though.

  • YSK: If you set up a Lemmy instance, and follow the Docker setup instructions to the letter, it will send lemmy.ml your admin password during the setup process (Edit: Not anymore, it’s fixed now)

    Jump
  • I think it should be more public knowledge than just people who peruse the github issues. Also, it's so trivial to fix that it will save them some time if they don't have to close the issue after they spend literally 10-15 seconds fixing it.

  • They might actually just care about the moral issues involved (or at least be worried enough about pushback to fake it).

    They’re going to make a river of money regardless, and so maybe it’s not worth taking a reputational hit or risking some kind of legislation, just to preserve the 0.00000001% of their revenue stream that is deepfake porn based.

  • Tito smoking Cuban cigars in the White House while sitting down with Nixon is also hilarious.

    Nixon told him, “Mr. President, we don’t smoke in the White House.”

    Tito laughed and said, “Lucky you!” and finished his cigar and no one attempted again to make him stop.

  • Grok responded to X users’ questions about public figures by generating foul and violent rape fantasies, including one targeting progressive activist and policy analyst Will Stancil. (Stancil has indicated he may sue X.)

    When you fine-tune a coding AI on code that has deliberate flaws in it, and then switch it back to having conversations in English, it starts praising Hitler and constructing other deliberately hateful content. It wouldn’t surprise me if fine-tuning Grok to be Nazi also led it to “generalize” some additional things that weren’t intended by the operators.

  • All of you in this thread are fucking psychopaths

    Kalamata olives and similar little food objects are fine, they are often delicious

    Eating the rest of these unflavorful little saltpellets on purpose is a ridiculous thing though

  • Him who mountain crush him noHim who sun him stop him noHim who hammer him break him noHim who fire him fear him noHim who raise him head above him heartHim diamond

  • They definitely do check. I don't know how detailed the checks are or how major a crime it is to use someone else's info, but there are enough checks in place, you can't just type in Porky Pig or made-up nonsense or anything.

  • I wonder what that indicates about its data set and the general use of image gen

    I think you know.

    On a more serious note, it's interesting to put in pure nonsense as the prompt (just strings of syllables with no meaning), and see what it comes up with. It likes misshapen heads, which makes sense because it's trained on a lot of human features, but it also likes houses, fish, and hot air balloons quite a lot for some reason. The images are in my opinion a lot more interesting than a lot of what it comes up with if you give it words.

  • Moving to piefed.lemmy.fan/c/weird_news - Weird News - Things that make you go 'hmmm' @real.lemmy.fan

    DC-area veterinarians on heightened alert amid potential inauguration risks

    arstechnica.com /health/2025/01/dc-area-veterinarians-on-heightened-alert-amid-potential-inauguration-risks/
  • Technology @beehaw.org

    TikTok Starts Working Again After Trump Says He Will Stall a Ban

    www.nytimes.com /2025/01/19/technology/trump-tiktok-ban-executive-order.html
  • Technology @beehaw.org

    Italian Legislators Rekindle Decade-Long Grudge Match Against Tripadvisor And Its Reviewers

    www.techdirt.com /2025/01/17/italian-legislators-rekindle-decade-long-grudge-match-against-tripadvisor-and-its-reviewers/
  • Technology @beehaw.org

    Microsoft mimics Google UI when Bing users search for Google

    go.theregister.com /feed/www.theregister.com/2025/01/06/microsoft_bing_spoof_google/
  • You Should Know @lemmy.world

    YSK There’s someone running around Lemmy posting misinformation against Wikipedia

  • Privacy @lemmy.ml

    Think you need a VPN? Start here.

    techcrunch.com /2024/11/15/think-you-need-a-vpn-guide-start-here/
  • Privacy @lemmy.ml

    Traffic Camera 'Selfie' Creator Holds Cease and Desist Letter in Front of Traffic Cam

    www.404media.co /traffic-cam-photobooth-cease-and-desist/
  • Privacy @lemmy.ml

    Russian techie flees Russia following FSB spyware plot

    go.theregister.com /feed/www.theregister.com/2024/12/06/badass_russian_techie_outsmarts_fsb/
  • News @lemmy.world

    FTC Bans Location Data Company That Powers the Surveillance Ecosystem

    www.404media.co /ftc-bans-location-data-company-that-powers-the-surveillance-ecosystem/
  • You Should Know @lemmy.world

    YSK Wikipedia's list of common misconceptions

    en.wikipedia.org /wiki/List_of_common_misconceptions
  • Technology @beehaw.org

    A more complete explanation for the removal of those Russian Linux kernel maintainers

    lore.kernel.org /netdev/e7d548a7fc835f9f3c9cb2e5ed97dfdfa164813f.camel@HansenPartnership.com/t/
  • Technology @beehaw.org

    Radio Station Replaces Journalists With AI 'Presenters'

    www.ibtimes.com /journalists-replaced-ai-presenters-3748057
  • You Should Know @lemmy.world

    YSK that United has significantly escalated their war against basic economy passengers

  • [Dormant, please move to [email protected]] Movies and TV Shows @lemm.ee

    A close look at 1979's "Alien"'s rare type of cinematography

  • [Dormant, please move to [email protected]] Movies and TV Shows @lemm.ee

    When film critics clearly just do not get the movie

  • Technology @beehaw.org

    The British government is transferring sovereignty of an island in the Indian Ocean to Mauritius next week, potentially impacting the existence of the .io domain.

    every.to /p/the-disappearance-of-an-internet-domain
  • Privacy @lemmy.ml

    College students used Meta’s smart glasses to dox people in real time

    www.theverge.com /2024/10/2/24260262/ray-ban-meta-smart-glasses-doxxing-privacy
  • Mildly Infuriating @lemmy.world

    I didn't know HOW bad Google search has gotten.