5
Doggos 5 points ago +5 / -0

That was a bug with the time change. Our system for long term sessions relies on a fixed timestamp (rather than Epoch) so when times changed, sessions were invalidated because it appeared that you'd travelled back in time.

3
Doggos 3 points ago +3 / -0

Could you confirm which browser (and which version of it) you're using? Could you also confirm whether you were online the site earlier in the day? This may be a bug with an update 3-4 hours ago (which was temporarily rolled back).

With regards to the compromised aspect - doesn't really add up. If you don't have an email then you can't reset your password. The reason why we ask for the email when processing a password reset is because we only store a hash of email addresses. This means that we do not know your email address. You need to provide it to us again, and then we'll hash it, and check that it matches what we have stored. If it matches, we send the reset link to the email address provided.

6
Doggos 6 points ago +6 / -0

Yes, but not specifically with regards to Win.

The threat in mind when making that comment was the domain situation, which we have now moved on from. I don't regret the comment, but it has created a potentially dangerous situation where all logouts are viewed as a takeover.

Also users should keep in mind that they should not try too many bad passwords, or they may get silently blocked temporarily (correct password attempts denied)

8
Doggos 8 points ago +8 / -0

Been looking into this and a few other issues. I believe it's all the result of the time change.

  1. Our full backup (every two hours) didn't fire at 8AM UTC, this was definitely due to the time change, as it continued as normal at 9AM UTC (three hour gap)

  2. The logout issue is a long explanation and I'm not 100% sure, but I believe anyone who visited the site in the hour before the time change and then also visited the site in the hour after the change would get fully logged out.

And finally, it looks like any new logins made during the hour after the time change would be temporary (they would expire after 60 minutes). They would also expire if you closed your browser or app. Now, however, the sessions should be sticking again.

2
Doggos 2 points ago +2 / -0

What is the second thing you're referring to?

10
Doggos 10 points ago +10 / -0

Agreed. I still use Reddit. I love the platform (Reddit), but strongly dislike the staff and influential users.

Until I replace my Reddit usage with Win, I am not satisfied.

There's an update to the 'Front' and 'All' feeds to merge them into one, but no ETA on when it'll be deployed.

9
Doggos 9 points ago +9 / -0

There wasn't a canary for Win, it was for /r/The_Donald specifically.

13
Doggos 13 points ago +13 / -0

There wasn't a canary for Win, it was for /r/The_Donald specifically.

5
Doggos [M] 5 points ago +6 / -1

What do you mean?

6
Doggos 6 points ago +6 / -0

Many of them will claim to be suffering from symptoms even a year later, with some going as far as claiming they still can't taste.

Six months later and I'm still unable to smell (mostly, 95%) although I do not support lockdowns.

4
Doggos [M] 4 points ago +4 / -0

Those are removals, not shadowbans. Read what I wrote:

Content may be removed for rule violations, in which case you will still be able to see it (unless it was removed for legal reasons)

Image of the removed content.

A shadowban would be flagging your account so that your posts and comments are removed as soon as they're posted. We do not have this functionality.

5
Doggos [M] 5 points ago +6 / -1

Removed all but one of these posts of yours. Please stop spamming.

We do not shadowban (we don't have that functionality) and we haven't changed anything in regards to moderation in probably 2 months.

Content may be removed for rule violations, in which case you will still be able to see it (unless it was removed for legal reasons)

2
Doggos [M] 2 points ago +2 / -0

It does work, except with special characters such as periods, exclamation points, etc.

We're going to be switching search to a new system within the next week hopefully, which will remove that limitation and will be faster.

3
Doggos [M] 3 points ago +3 / -0

No, but we did ban a lot of accounts which were associated with that.

76
Doggos [M] 76 points ago +76 / -0

Looks to be a lot worse - the @getongab Twitter account (which existed yesterday) no longer exists.

Access to the Twitter account suggests a far worse hack than an admin dashboard.

22
Doggos [M] 22 points ago +22 / -0

Yes. If you are logged out in this case, it will be temporary and you will be automatically logged back in.

209
Doggos [M] 209 points ago +209 / -0

I use ProtonMail, and we use ProtonMail for Win, too.

However, there are some seemingly credible accusations against ProtonMail to keep in mind: https://privacy-watchdog.io/truth-about-protonmail/

view more: ‹ Prev Next ›