Note: This post now archived and as such no longer works

109 points

This is possible because Lemmy doesn’t proxy external images but instead loads them directly. While not all that bad, this could be used for Spy pixels by nefarious posters and commenters.

Note, that the only thing that I willingly log is the “hit count” visible in the image, and I have no intention to misuse the data.

permalink
report
reply
92 points

The best part is it also works on DMs, so it’s trivial to get any persons IP address. Want an admins IP address? Just DM them a message with an embedded spy pixel.

I emailed the lemmy developers about this a few weeks ago since IMHO it’s a pretty big security issue, no reply.

permalink
report
parent
reply
41 points

I think you’re overestimating the value of someone’s IP address. Not much one can do with it unless someone really tries to expose themselves.

permalink
report
parent
reply
20 points
*
  1. If you are planning on hijacking one of their online accounts, then obtaining all possible intel about someone helps to make phishing their other service providers easier. Knowing someone’s IP address means you instantly know what city they are in.

  2. If you are trying to reveal someone’s true identity and you have already learned of their IP address through some other means, then this would allow you to reveal their identity on lemmy. Example: an employer already knows the home ip addresses of their employees who work remotely and vpn into the company office. They see someone on lemmy sharing insider info about the company they would rather not have shared and suspect the lemmy user is a disgruntled employee and send them a dm with tracking pixel to verify whether that lemmy user’s ip address matches the addresses of any of their employees.

  3. Consider the case of someone thinking they are anonymous and boasting about some activities that might be legally questionable, then consider some law enforcement agency using tracking pixel to get user’s ip address. If the lemmy server is outside of jurisdiction they might not be able to subponea the lemmy instance admins for that user’s ip address, but now they don’t have to. With the IP address they can just subponea the isp to get the user’s identity. This could be over criminal activity…or maybe just something like admitting being gay in a country that sentences to death for that.

These are just three examples…there are countless other examples just as bad.

TL/DR: it is a significant security breach to allow 3rd parties the ability to use the platform to expose user’s ip addresses, and even worse when it can be targeted at specific users (such as the DM scenerio that is also affected).

permalink
report
parent
reply
17 points

Joke’s on you, I’m in front of 9 proxies. 🤡

permalink
report
parent
reply
10 points
*

1: DM all admins a spy pixel.

2: Coordinate a mass effort to spam rule-breaking posts and comments at some day.

3: Distributed denial of service attack on all admin IPs on that day.

Profit?

permalink
report
parent
reply
4 points

Didn’t knew you can DM on lemmy. Maybe the Jerboa devs have not implemented it yet.

permalink
report
parent
reply
20 points

Not really.

permalink
report
parent
reply
2 points

Same, I’m using an app.

permalink
report
parent
reply
1 point

Jerdoa

permalink
report
parent
reply
73 points

“an unknown (mobile?) client”

Well, nice try anyway.

permalink
report
reply
6 points

sPoOky

permalink
report
parent
reply
3 points

Same, woo for my security I guess!

permalink
report
parent
reply
23 points

You are viewing this from Apple Mail on MacOSX…. Ummm, okay. If you say so…

permalink
report
reply
12 points

iCloud relay perhaps?

permalink
report
parent
reply
21 points

permalink
report
reply
6 points

uBlock Origin? NoScript? Internet Explorer?

permalink
report
parent
reply
-1 points

Liftoff, and the device has Blokada5 running but it didn’t block that.

permalink
report
parent
reply
15 points

You are viewing this from a (rand() % 2 == 0) ? "android" : "apple" phone.

permalink
report
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 17K

    Monthly active users

  • 12K

    Posts

  • 543K

    Comments