this post was submitted on 22 Jul 2023
2103 points (98.7% liked)
Lemmy.World Announcements
29100 readers
5 users here now
This Community is intended for posts about the Lemmy.world server by the admins.
Follow us for server news ๐
Outages ๐ฅ
https://status.lemmy.world/
For support with issues at Lemmy.world, go to the Lemmy.world Support community.
Support e-mail
Any support requests are best sent to [email protected] e-mail.
Report contact
- DM https://lemmy.world/u/lwreport
- Email [email protected] (PGP Supported)
Donations ๐
If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.
If you can, please use / switch to Ko-Fi, it has the lowest fees for us
Join the team
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
My proposal: using old UI by default must mitigate the attacks because we will no longer have to download shitty *.js files anymore.
This would probably be less useful than you think.
Firstly, changing the default doesn't matter - the attackers will just switch to targeting whichever URL causes the most pain.
Secondly, in comparison to prerendered pages of live content, js files are incredibly cheap and easy to chuck on a CDN. They don't change often, so you don't need to worry about cache invalidation, and even at a server level they're probably hosted by a simple file server rather than hitting the DB.
OK, block non-old UI completely ASAP!
I just f*cking hate js files and XHR though you're right! :(
By the way, does the old UI make lemmy.world heavier than its default UI? Either yes or no, I want lemmy.world to continue providing the old UI. I love it! :D