troed

joined 2 years ago
[–] [email protected] 90 points 1 day ago (46 children)

It's a list from 2021 and as a cybersec researcher and Jellyfin user I didn't see anything that would make me say "do not expose Jellyfin to the Internet".

That's not to say there might be something not listed, or some exploit chain using parts of this list, but at least it's not something that has been abused over the last four years if so.

[–] [email protected] 2 points 1 day ago (1 children)

There are still server softwares our there that are going to be exposing people's private Mastodon posts.

You could've saved yourself a lot of typing there by just admitting to claiming things you actually didn't know.

[–] [email protected] 2 points 1 day ago (3 children)

If you know of other ActivityPub servers that expose private posts the same way I suggest you make a responsible disclosure to the developers.

I don't know of any, but you claim they exist so ...

[–] [email protected] 2 points 1 day ago (1 children)

You have absolutely no idea what "responsible" in "responsible disclosure" means :) It's completely irrelevant how Mastodon has implemented private posts when it comes to how Dansup handled the issue, knowing what the effects were.

You don't, when told of a vulnerability, handle it in a way that cause harm if it can be avoided.

[–] [email protected] 2 points 1 day ago (3 children)

Read more, post less. I've said nothing about any spec violation. That's not relevant.

[–] [email protected] 2 points 1 day ago (5 children)

hahahahaha

Watch and try again ;) I post under my real name.

https://www.cve.org/CVERecord?id=CVE-2024-44754

https://www.youtube.com/watch?v=ZbKLAjPYOEg

Feel free to post less and read more.

[–] [email protected] 5 points 1 day ago (7 children)

It has everything to do with ActivityPub since if you follow that protocol strictly you will cause this behavior. It still doesn't change that Dansup was told that this caused Bad Things(tm) and yet he didn't follow normal procedure in how you handle it.

Vulnerabilities don't need to be buffer overflows.

/cybersec researcher

[–] [email protected] 9 points 1 day ago (18 children)

Regardless whether you want to pretend that not caring about Mastodon is a valid defense when implementing software using the ActivityPub protocol, that still doesn't change anything regarding how Dansup handled the disclosure of the effects it had.

[–] [email protected] 1 points 2 days ago

As I wrote, at the time the MEPs in question believed this to be fully legal. I do not know any MEPs personally today.

[–] [email protected] 4 points 2 days ago (3 children)

Is it correct that the crime Le Pen was convicted of was hiring assistants to her parliament office who in reality were working for the national political party?

I've seen this claimed and if true I hope that a lot of people were convicted, not just her. Because I know for a fact that this exact setup has been used by other MEPs. At the time they believed it to be fully legal.

I'm happy she got convicted, but I don't want this to in any way having been politically targeted because that opens up a shitload of worm cans.

[–] [email protected] 15 points 2 days ago (1 children)

If you have a garden, plant flowers instead of keeping a boring grass lawn.

 

74% of Ukrainians support fighting Russia even without U.S. assistance. A significant majority—59% of respondents—also believe that Ukraine can defeat Russia on the battlefield

only 6% of respondents said they were willing to make territorial concessions regarding areas occupied by Russia after the full-scale invasion in 2022

Additionally, 70% of respondents are against lowering the mobilization age,

Original article is paywalled, quotes from https://ukrainetoday.org/74-of-ukrainians-ready-to-resist-russia-without-u-s-aid-support-zelenskyys-actions/

 

We're consolidating our social media presence due to limited resources and no longer posting on Mastodon. Follow us on Reddit

Please tell us that you're not moving away from Lemmy/Mbin too. There's a gigantic tonedeafness to asking your supporters to use centralized social media at this specific time that's hard to accept you're not realizing.

(quote from Proton's mastodon.social account info - there wasn't even a post made about it)

 

Swedish author and famous pro-Ukraine blogger Lars Wilderäng (Cornucopia) reports today that the Swedish security expert Karl Emil Nikka has revealed that Kagi is using the Kremlin propaganda tool Yandex as a backend for searches.

Wilderäng speculates this might mean search terms are leaking to Russia, while others worry about how Kremlin thus can get their talking points into western search results.

Security expert Karl Emil Nikka tells us that the search engine Kagi, popular among tech geeks, uses Russian Yandex, which was introduced after the full-scale invasion. This, of course, gives Russia the opportunity to look at what is searched for via Kagi.

Link (in Swedish), see 11:22 update: https://cornucopia.se/2024/10/uppdateras-ryssland-medger-bruk-av-c-stridsmedel-mot-ukraina-rysk-pilot-som-mordade-68-ukrainare-ihjalslagen-med-hammare-bland-de-allra-storsta-ryska-forlusterna-under-kriget-igar/

view more: next ›