Conversation
Notices
-
Embed this notice
if worse comes to worst i can always migrate this server to honk haha
-
Embed this notice
that said i still do have faith in the pleroma team, i really do like this software, and i still want to give devs a chance even after this weird situation. i trust that something like this will not happen again on their watch anymore
-
Embed this notice
@romin pleroma user spoofing bug, you could forge a post coming from anyone using webfinger. gleason actually caught and put in a fix a long time ago but the pleroma team never got around to fixing it
-
Embed this notice
@kirby what happened
-
Embed this notice
@kirby I remember gleas*n complaining about it last year, I wonder why it took that long
-
Embed this notice
@romin same, i guess a dev never saw that post? it seems strange honestly, i trust gleason wouldve shared with the team, but it is really strange
-
Embed this notice
@kirby @romin they care more about heckin problematic posts than sharing code.
Guess what platform doesn't have webfinger spoofing though
tenor_gif6515600088844960354.gif
-
Embed this notice
@romin @kirby It took someone, won't be pointing fingers, actually exploiting it in the wild. No amount of cooties from Gleason could stop them from swallowing their pride in this case.