Spacc BBS Spacc BBS
    • Categorie
    • Recenti
    • Tag
    • Popolare
    • Mondo
    • Utenti
    • Gruppi
    • Registrati
    • Accedi
    La nuova BBS è in fase Alpha. I post precedenti al 22 luglio 2024 potrebbero non essere trasferibili, ma rimarranno disponibili per la lettura su /old/.

    So @pixelfed still hasn't fully acknowledged nor fixed the security vulnerability from earlier this year, despite multiple people asking for updates over the past ~6 months.

    Pianificato Fissato Bloccato Spostato Uncategorized
    47 Post 10 Autori 111 Visualizzazioni
    Caricamento altri post
    • Da Vecchi a Nuovi
    • Da Nuovi a Vecchi
    • Più Voti
    Rispondi
    • Topic risposta
    Effettua l'accesso per rispondere
    Questa discussione è stata eliminata. Solo gli utenti con diritti di gestione possono vederla.
    • chad@mstdn.caC Questo utente è esterno a questo forum
      chad@mstdn.ca @thisismissem@hachyderm.io
      ultima modifica di

      @thisismissem @rey @dansup @deadsuperhero I feel that given the overall careful discussion here, an accusation of misinformation is a great departure.

      thisismissem@hachyderm.ioT 1 Risposta Ultima Risposta Rispondi Cita 0
      • hiphopheaven@mastodon.socialH Questo utente è esterno a questo forum
        hiphopheaven@mastodon.social @thisismissem@hachyderm.io
        ultima modifica di

        @thisismissem @chad @dansup @deadsuperhero why do they not create an alternative? This ia suppose to be the power of open source you can fork projects and create new wonderful things

        chad@mstdn.caC 1 Risposta Ultima Risposta Rispondi Cita 0
        • chad@mstdn.caC Questo utente è esterno a questo forum
          chad@mstdn.ca @hiphopheaven@mastodon.social
          ultima modifica di

          @hiphopheaven @thisismissem @dansup @deadsuperhero there's no one stopping anyone from forking Dan's projects.

          thisismissem@hachyderm.ioT 1 Risposta Ultima Risposta Rispondi Cita 0
          • thisismissem@hachyderm.ioT Questo utente è esterno a questo forum
            thisismissem@hachyderm.io @chad@mstdn.ca
            ultima modifica di

            @chad @rey @dansup @deadsuperhero that was *his* accusation. Not mine. I then spent the time to review the changes, and was fully prepared to update as resolved, only, it wasn't & the changes where thousands of lines of unrelated code. I spent quite some time checking.

            1 Risposta Ultima Risposta Rispondi Cita 0
            • thisismissem@hachyderm.ioT Questo utente è esterno a questo forum
              thisismissem@hachyderm.io @chad@mstdn.ca
              ultima modifica di

              @chad @hiphopheaven @dansup @deadsuperhero it's hard when he'll actively fight against you, iirc, he got extremely mad when pixelfed-glitch was started, and threatened a trademark lawsuit. That probably killed that person's energy to work on it.

              He also went after the developer of Vernissage a while back too, when they decided to do their own thing away from pixelfed.

              Meanwhile he raises 100k for pixelfed, but it seems like all the energy is going into his other projects.

              1 Risposta Ultima Risposta Rispondi Cita 0
              • julian@community.nodebb.orgJ Questo utente è esterno a questo forum
                julian@community.nodebb.org @chad@mstdn.ca
                ultima modifica di

                chad@mstdn.ca re: "step up or shut up", thisismissem@hachyderm.io has been (is currently?) a contributor for Pixelfed, and was the person responsible for the discovery, analysis, and responsible disclosure of the 10/10 severity vulnerability from last year.

                She also provided best practice recommendations and guidance on remediation, all for free (there was no security fund back then, and Pixelfed has no bug bounty.)

                For her to buck responsible disclosure practice (and even then she's being deliberately vague about the technical details) is a sign that someone is being stonewalled.

                1 Risposta Ultima Risposta Rispondi Cita 0
                • Primo post
                  Ultimo post