GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 10-Feb-2025 22:36:58 JST daniel:// stenberg:// daniel:// stenberg://

    lemme show you 140,000 (!) places in code where certificate verification is switched off when using libcurl: https://github.com/search?q=CURLOPT_SSL_VERIFYPEER%2C+FALSE&type=code

    In conversation about 3 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: github.githubassets.com
      Build software better, together
      GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
    • kaia and clacke like this.
    • Blaise Pabón - controlpl4n3 repeated this.
    • Embed this notice
      nyanide :nyancat_rainbow::nyancat_body::nyancat_face: (nyanide@lab.nyanide.com)'s status on Monday, 10-Feb-2025 22:43:34 JST nyanide :nyancat_rainbow::nyancat_body::nyancat_face: nyanide :nyancat_rainbow::nyancat_body::nyancat_face:
      in reply to
      @bagder i do it with pride
      In conversation about 3 months ago permalink
    • Embed this notice
      翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Monday, 10-Feb-2025 22:45:42 JST 翠星石 翠星石
      in reply to
      @bagder >That doesn't work without a github account and probably without proprietary JavaScript.
      Many such cases.
      In conversation about 3 months ago permalink
    • Embed this notice
      Buccia (bucciabuccia@mastodon.social)'s status on Monday, 10-Feb-2025 23:49:32 JST Buccia Buccia
      in reply to

      @bagder Chinese instances are due to many chinese networks doing MiTM so instead of flooding the user with errors, they just disable certificate verification altogether.

      In conversation about 3 months ago permalink
    • Embed this notice
      Ret (ret@furry.engineer)'s status on Monday, 10-Feb-2025 23:49:46 JST Ret Ret
      in reply to

      @bagder wait until you find out Amazon Application Load Balancers don't validate server certificates.

      Edit: CloudFront does

      In conversation about 3 months ago permalink
    • Embed this notice
      Annika Backstrom (annika@xoxo.zone)'s status on Tuesday, 11-Feb-2025 17:53:15 JST Annika Backstrom Annika Backstrom
      in reply to

      @bagder 👏

      In conversation about 3 months ago permalink
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 11-Feb-2025 17:53:16 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to
      • Annika Backstrom

      @annika 😱

      In conversation about 3 months ago permalink
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 11-Feb-2025 17:53:16 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to
      • Annika Backstrom

      @annika https://github.com/php-mod/curl/issues/108

      In conversation about 3 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        Misleading TLS verification instructions · Issue #108 · php-mod/curl
        The README currently says: SSL verification setup: $curl = new Curl\Curl(); $curl->setOpt(CURLOPT_RETURNTRANSFER, TRUE); $curl->setOpt(CURLOPT_SSL_VERIFYPEER, FALSE); $curl->get('https://encrypted....
    • Embed this notice
      Annika Backstrom (annika@xoxo.zone)'s status on Tuesday, 11-Feb-2025 17:53:17 JST Annika Backstrom Annika Backstrom
      in reply to

      @bagder This is maybe my favourite, where a curl wrapper explains how to turn peer verification off under the heading "SSL verification setup":

      https://github.com/php-mod/curl#:~:text=SSL%20verification%20setup&text=CURLOPT_SSL_VERIFYPEER,%20FALSE

      In conversation about 3 months ago permalink
    • Embed this notice
      clacke (clacke@libranet.de)'s status on Tuesday, 11-Feb-2025 23:17:41 JST clacke clacke
      in reply to
      @bagder Removed a -k from a curl line today when implementing something according to internal documentation. It felt good.
      In conversation about 3 months ago permalink
    • Embed this notice
      haerench (haerench@mastodon.social)'s status on Friday, 14-Feb-2025 00:35:40 JST haerench haerench
      in reply to

      @bagder Certainly 140k occurrences is good enough for AI to label this as good code/practice and suggest it in new code ...

      In conversation about 3 months ago permalink
      clacke likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.