-
Password hashing occurs server-side. Even without removing the hashing step an admin can intercept the plaintext password during login. Use unique safe passwords.
-
An admin can intercept the jwt authentication cookie and use any account that lives in the instance.
-
Private messages are stored as plaintext in the database
-
Admins can see who upvotes/downvotes what
-
These are not things that are unique to Lemmy. This is common.
-
To avoid having to trust your admin, run an instance.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: