Jonkman Microblog
  • Login
Show Navigation
  • Public

    • Public
    • Network
    • Groups
    • Popular
    • People

Notices by kaniini (kaniini@mastodon.dereferenced.org), page 61

  1. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:50:03 EST kaniini kaniini
    • beatrix bitrot
    • Crazypedia :cyber_heart:

    @bea @crazypedia

    the approach of using a visibility seemed best for usability (in terms of obviousness), and provided an excuse to dig deeper on OStatus leaks

    In conversation Wednesday, 22-Nov-2017 22:50:03 EST from mastodon.dereferenced.org permalink
  2. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:44:14 EST kaniini kaniini
    in reply to
    • beatrix bitrot

    @bea

    the generic patch needs work, but i think i know what's wrong.

    In conversation Wednesday, 22-Nov-2017 22:44:14 EST from mastodon.dereferenced.org permalink
  3. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:43:04 EST kaniini kaniini

    this is another local-only toot

    In conversation Wednesday, 22-Nov-2017 22:43:04 EST from mastodon.dereferenced.org permalink Repeated by kaniini
  4. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:43:04 EST kaniini kaniini

    this is another local-only toot

    In conversation Wednesday, 22-Nov-2017 22:43:04 EST from mastodon.dereferenced.org permalink
  5. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:42:31 EST kaniini kaniini
    • beatrix bitrot
    • Crazypedia :cyber_heart:

    @bea @crazypedia

    overall the auth model in mastodon 2 seems reasonable, it's just the specific policy objects that need tweaking.

    or in the case of OStatus leaks, it's because the post privacy settings on variant objects were always set to "public."

    this patch would likely allow things like followers-only boosting too, but that's for another day.

    In conversation Wednesday, 22-Nov-2017 22:42:31 EST from mastodon.dereferenced.org permalink
  6. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:37:11 EST kaniini kaniini
    in reply to
    • beatrix bitrot

    @bea

    testing generic version of the patch now, which should eliminate *all* OStatus leaks

    In conversation Wednesday, 22-Nov-2017 22:37:11 EST from mastodon.dereferenced.org permalink
  7. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:33:59 EST kaniini kaniini
    • beatrix bitrot

    @bea

    i fixed it. going to clean up the patch and post it momentarily.

    In conversation Wednesday, 22-Nov-2017 22:33:59 EST from mastodon.dereferenced.org permalink
  8. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:32:09 EST kaniini kaniini
    • beatrix bitrot

    @bea no i fucked up and forgot to set the privacy

    In conversation Wednesday, 22-Nov-2017 22:32:09 EST from mastodon.dereferenced.org permalink
  9. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:31:15 EST kaniini kaniini

    this is a private status and it should hopefully not get exposed in RSS.

    In conversation Wednesday, 22-Nov-2017 22:31:15 EST from mastodon.dereferenced.org permalink
  10. 💫Alyx (alyx@witches.town)'s status on Wednesday, 22-Nov-2017 22:30:14 EST 💫Alyx 💫Alyx

    boost if you disagree

    In conversation Wednesday, 22-Nov-2017 22:30:14 EST from witches.town permalink Repeated by kaniini
  11. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:28:26 EST kaniini kaniini
    • beatrix bitrot

    @bea testing quick and dirty fix

    In conversation Wednesday, 22-Nov-2017 22:28:26 EST from mastodon.dereferenced.org permalink
  12. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:12:44 EST kaniini kaniini
    • beatrix bitrot

    @bea

    actually, it seems it is a security problem in mastodon itself.

    i'm working on fixing the general case

    (mastodon is leaking things it shouldn't be into public view, but this leak was hidden because reboosts of private posts is normally forbidden)

    In conversation Wednesday, 22-Nov-2017 22:12:44 EST from mastodon.dereferenced.org permalink
  13. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:07:22 EST kaniini kaniini

    so it's reboosts getting leaked via OStatus.

    In conversation Wednesday, 22-Nov-2017 22:07:22 EST from mastodon.dereferenced.org permalink
  14. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:06:58 EST kaniini kaniini

    harumph this is the one i am going to reboost

    In conversation Wednesday, 22-Nov-2017 22:06:58 EST from mastodon.dereferenced.org permalink Repeated by kaniini
  15. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:06:58 EST kaniini kaniini

    harumph this is the one i am going to reboost

    In conversation Wednesday, 22-Nov-2017 22:06:58 EST from mastodon.dereferenced.org permalink
  16. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 22:02:12 EST kaniini kaniini
    • beatrix bitrot
    • snackolantern 🎃
    • packetcat

    @staticsafe @bea @er1n

    there is a decent shawarma place across the street from what i was told was a male strip club (remington's?)

    In conversation Wednesday, 22-Nov-2017 22:02:12 EST from mastodon.dereferenced.org permalink
  17. kaniinitesting (kaniinitesting@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 21:55:19 EST kaniinitesting kaniinitesting

    this is another test, supposed to be local-only

    In conversation Wednesday, 22-Nov-2017 21:55:19 EST from mastodon.dereferenced.org permalink Repeated by kaniini
  18. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 21:53:53 EST kaniini kaniini
    • Chris

    @csaurus did you get the original status or the reblog? i have concerns about how mastodon handles OStatus reblogs.

    In conversation Wednesday, 22-Nov-2017 21:53:53 EST from mastodon.dereferenced.org permalink
  19. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 21:30:58 EST kaniini kaniini
    in reply to

    Patch: https://github.com/kaniini/mastodon-hardened/commit/3e832e91d1fada8f7efbd89059bd14e7ca258ad8

    In conversation Wednesday, 22-Nov-2017 21:30:58 EST from mastodon.dereferenced.org permalink

    Attachments

    1. add local-only statuses · kaniini/mastodon-hardened@3e832e9
      from GitHub
  20. kaniini (kaniini@mastodon.dereferenced.org)'s status on Wednesday, 22-Nov-2017 21:29:52 EST kaniini kaniini

    this is a local-only status i say

    In conversation Wednesday, 22-Nov-2017 21:29:52 EST from mastodon.dereferenced.org permalink Repeated by kaniini
  • After
  • Before
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.

Switch to desktop site layout.