Notices by :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site), page 45
-
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 13:39:16 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@lanodan nope, there's containment violations in the testsuite -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 13:25:54 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
and this is why you have to be careful when validating IR.
Screenshot_20190714_122457.png… -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 13:03:18 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@karen @lanodan
yes, i am going to cut 1.0.1 today with MRF transparency exclusions and both of these security fixes. -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 12:58:19 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
regarding the OStatus spoofing bug, I merged @lanodan's quick fix, but i am working on a more generic fix on the IR level, so that protocol implementations ultimately don't have to worry about containment. -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 12:51:06 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@ilja @smithy @Conan_Kudo
i like how the comment for rich text formatting is basically "a lot of drama on the Mastodon github" -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 12:45:42 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@Conan_Kudo @ignatenkobrain https://git.pleroma.social/pleroma/pleroma/commit/26f265fb0e22ee7b7f4e9e1df4240283f5db3a9a btw -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 12:37:45 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@mangeurdenuage
nope. ActivityPub, frankly, *is* more secure than OStatus to begin with. OStatus is a giant hell of undefined behaviour and obsolete security primitives.In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 12:35:31 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
in fact, i have a better solution for the OStatus spoofing problem In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 12:32:23 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@sim @aru @mangeurdenuage @smithy
OStatus is complete trash. of course, so is ActivityPub, but that's beside the point. removing support for OStatus is good security praxis.In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 12:30:33 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@sim @aru @mangeurdenuage @smithy
elsewhere in that thread, wew
Screenshot_20190714_113015.png…In conversation from pleroma.site permalink -
nil (sim@shitposter.club)'s status on Sunday, 14-Jul-2019 09:15:40 EDT nil
It's still weird hearing people go on about mastodon like it came up with federation rather than piggybacking off it. The federation was here before mastodon, and it would have kept going if it had never existed. Not to the same extent as we have now, but I'm sure there would have been different waves of interest in it. In conversation from shitposter.club permalink Repeated by kaniini -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 12:13:17 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@Thib @href i doubt big G will merge it In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 12:11:36 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@Thib @href if what passes? i'm not up to date on what the transparency efforts are over on masto side? nightpool of course, knows best, and will be blocking transparency attempts I think. In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 11:46:06 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@ben @schestowitz
Micros~1 is the most well known bastion of free software ever.In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 11:43:22 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@lanodan weh In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 11:34:53 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@feld @Conan_Kudo @ignatenkobrain
i would assume that Depending on the exact erlang package that generated the release would be functionally equivalent.In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 11:20:57 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@roka @ffs
so far most of the evidence is pointing to juche.town as being the target, honestly.In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Sunday, 14-Jul-2019 11:18:59 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@ffs @roka
(and besides if he wanted to DDoS me, he would have actually succeeded. this was just some dumbass with a booter.)In conversation from pleroma.site permalink