Poa.st / Chudbuds.lol General Discussion Thread - !! Poa.st and Bae.st have been compromised, all direct messages have been leaked. !!

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.
and understood that every website will be compromised at some point.
This is the more important part. Everything gets hacked at some point whether it's KF, Poast, Target, or Reddit, there's just too much happening on every site these days for everything to be secure at all times. More so, private messages are private to users, but not moderators/admins, so it's important to understand that anything said in them will be leaked at some point.

Also, it's important to watch how the admins and operators react to a breach, if they're transparent and take action quickly it's a good thing. If they're like Ralph and tell people it's all good and nothing got leaked, despite it obviously being leaked, then you should never trust them.
 
Noticing a lot of users are migrating accounts now. I'm wondering at this point with pleroma having security issues now if people migrate to another version. The larger the instance the bigger the target. Or in other words. Don't exist on an instance with e-celebs on it.
If its an oauth issue it will effect all Pleroma instances including the Kiwifarms one, migrating will have no zero change on your vulnerability because it will just be scripted to trawl all instances. Bae.st getting jacked shows that this isn't a poa.st exclusive flaw, bae.st has been attacked maybe 4 times in the past week as that spammer guy has been using Wayne Lambright images with a random QR code on it moved around to spam graf, josh, and a few others I can't remember.
 
If this is real there's no way in fucking hell I'm touching leaked Poast DM's. Knowing the user bases... interests, theres likely to be shit in there you don't want on your fucking hardrives.
You see the shit they send openly, I don't want to even imagine what they send to each other "privately"
This is a PSA: Fediverse DMs, Kiwi Farms DMs, all of that shit is PLAIN FUCKING TEXT. There is no encryption. Sure, maybe other users on the site can't see it, but the admins sure can. Oh, and so can any nigger with access to the database.

Also, yeah, don't look at these DMs. I'm almost 100% you will find some abhorrent shit in there. Not just neo-nazi propaganda or clips of Nick Fuentes, but probably much, much worse. You be warned.
 
This is a PSA: Fediverse DMs, Kiwi Farms DMs, all of that shit is PLAIN FUCKING TEXT. There is no encryption. Sure, maybe other users on the site can't see it, but the admins sure can. Oh, and so can any nigger with access to the database.

That's why I'm Cats, that's why I only ever post cats and send people photographs of cats. you can't get mad at a cat. you can't be embarrassed by sending a cat.
 
Sucks to suck graf. Best fedi instance security btw. :story:

As for the DMs
noclick.png
 
This is a PSA: Fediverse DMs, Kiwi Farms DMs, all of that shit is PLAIN FUCKING TEXT. There is no encryption. Sure, maybe other users on the site can't see it, but the admins sure can. Oh, and so can any nigger with access to the database.

Also, yeah, don't look at these DMs. I'm almost 100% you will find some abhorrent shit in there. Not just neo-nazi propaganda or clips of Nick Fuentes, but probably much, much worse. You be warned.
This is why every platform nowadays calls them Direct Messages, not Private Messages. Because they sure as shit aren't fucking private in the slightest.
 
Back