Comment on New bot rules, Lemmy 0.18.3, and a message about alternative Lemmy frontends on lemm.ee

athlon@lemm.ee ⁨11⁩ ⁨months⁩ ago

As an author of one Lemmy front-end, I can confirm that you are potentially sharing your username and password. Unfortunately, there is no way for Lemmy front-end developers to, say, open a web socket to Lemmy instance and have you login through a web browser (which would be much prefered from security standpoint, but it is what it is).

Furthermore, from what I see, many of such instances store your password, instead of just the Bearer token. Unfortunately, from what I get, there is also no way of invalidating the Bearer tokens right now, so in the event of it getting stolen - you’re f***ed.

Now, couple of tips:

source
Sort:hotnewtop