GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Vincent Sparks (avincentinspace@furry.engineer)'s status on Thursday, 23-Oct-2025 18:47:51 JST Vincent Sparks Vincent Sparks
    • N33R

    @N33R so the funny thing about discord is that most people don't log into it using google

    In conversation about 10 months ago from furry.engineer permalink
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Thursday, 23-Oct-2025 18:47:39 JST Blurry Moon Blurry Moon
      in reply to
      • Trash Panda
      • N33R
      @AVincentInSpace @raccoon @N33R why don’t you read a blog post for five minutes and learn your craft
      In conversation about 10 months ago permalink
    • Embed this notice
      Vincent Sparks (avincentinspace@furry.engineer)'s status on Thursday, 23-Oct-2025 18:47:45 JST Vincent Sparks Vincent Sparks
      in reply to
      • Trash Panda
      • N33R

      @raccoon @N33R you just think i should do it for free.

      or were you planning to use my website if there was a $20 signup fee?

      In conversation about 10 months ago permalink
    • Embed this notice
      Trash Panda (raccoon@hollow.raccoon.quest)'s status on Thursday, 23-Oct-2025 18:47:46 JST Trash Panda Trash Panda
      in reply to
      • N33R

      @AVincentInSpace@furry.engineer @N33R@fops.cloud
      I didn't say it's easy.

      In conversation about 10 months ago permalink
    • Embed this notice
      Vincent Sparks (avincentinspace@furry.engineer)'s status on Thursday, 23-Oct-2025 18:47:47 JST Vincent Sparks Vincent Sparks
      in reply to
      • Trash Panda
      • N33R

      @raccoon @N33R make it secure, he says, as if that's the easiest thing in the goddamned world

      i don't like google or github or who the fuck ever either, but they can afford to hire a cybersecurity analyst. with the $0 you pay me to use my service, i cannot.

      In conversation about 10 months ago permalink
    • Embed this notice
      Trash Panda (raccoon@hollow.raccoon.quest)'s status on Thursday, 23-Oct-2025 18:47:48 JST Trash Panda Trash Panda
      in reply to
      • N33R

      @AVincentInSpace@furry.engineer @N33R@fops.cloud
      If you don't check your emails that's on you.
      Forcing people to use a literal data harvesting company and their garbage TOS because you can't be bothered to make your own database and make it secure is immoral in my opinion.

      I stand by my meme and it's message.
      If I can't make an account I just don't use the website.

      In conversation about 10 months ago permalink
    • Embed this notice
      Vincent Sparks (avincentinspace@furry.engineer)'s status on Thursday, 23-Oct-2025 18:47:49 JST Vincent Sparks Vincent Sparks
      in reply to
      • Trash Panda
      • N33R

      @raccoon @N33R and that's fair enough. no outfit is perfect. but when discord gets a data breach, it makes the news. everyone has to care and everyone changes their password because of it. (or they do if they're smart, which most people don't.)

      when the smash mouth message boards get hit with a data breach, and you don't happen to see that corporate half-apologetic email, you might not even *know.* it might happen once or twice a MONTH for all you know. the people running the website might not know either. at least when discord got breached they found out and told everyone within 24 hours

      In conversation about 10 months ago permalink
    • Embed this notice
      Trash Panda (raccoon@hollow.raccoon.quest)'s status on Thursday, 23-Oct-2025 18:47:51 JST Trash Panda Trash Panda
      in reply to
      • N33R

      @AVincentInSpace@furry.engineer @N33R@fops.cloud
      I don't know if you are oblivious or of you are playing dumb to turn the things in your favor, but discord is one of the bullshit things websites ask you to login with.
      Google, github, facebook... They all hava data breach.

      In conversation about 10 months ago permalink
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Thursday, 23-Oct-2025 19:57:28 JST Blurry Moon Blurry Moon
      in reply to
      • Trash Panda
      • N33R
      @raccoon @AVincentInSpace @N33R lol furry engineer disabled my server
      In conversation about 10 months ago permalink
    • Embed this notice
      Trash Panda (raccoon@hollow.raccoon.quest)'s status on Thursday, 23-Oct-2025 19:57:29 JST Trash Panda Trash Panda
      in reply to
      • Blurry Moon
      • N33R

      @AVincentInSpace@furry.engineer @sun@shitposter.world @N33R@fops.cloud
      Congratulations, you understand that there's no 100% safe tool.
      I would rather have my account on a small, specific website be hacked than one with as much personal info as google requires.

      In conversation about 10 months ago permalink
    • Embed this notice
      Vincent Sparks (avincentinspace@furry.engineer)'s status on Thursday, 23-Oct-2025 19:57:30 JST Vincent Sparks Vincent Sparks
      in reply to
      • Trash Panda
      • N33R

      @raccoon @sun@shitposter.world @N33R i have a homework assignment for you, type "php password-hash vulnerability" into your search engine of choice and tell me how many results you get back.

      In conversation about 10 months ago permalink
    • Embed this notice
      Trash Panda (raccoon@hollow.raccoon.quest)'s status on Thursday, 23-Oct-2025 19:57:32 JST Trash Panda Trash Panda
      in reply to
      • Blurry Moon
      • N33R

      @sun@shitposter.world @AVincentInSpace@furry.engineer @N33R@fops.cloud

      https://www.php.net/manual/en/function.password-hash.php
      https://www.php.net/manual/en/function.password-verify.php

      You're welcome bro

      In conversation about 10 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.php.net
        PHP: password_hash - Manual
        from @official_php
        Creates a password hash
      2. Domain not in remote thumbnail source whitelist: www.php.net
        PHP: password_verify - Manual
        from @official_php
        Verifies that a password matches a hash
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Thursday, 23-Oct-2025 20:05:49 JST Blurry Moon Blurry Moon
      in reply to
      • Trash Panda
      • N33R
      @raccoon @AVincentInSpace @N33R snowflake instance probably did it a long time ago

      It’s their right
      In conversation about 10 months ago permalink
    • Embed this notice
      Trash Panda (raccoon@hollow.raccoon.quest)'s status on Thursday, 23-Oct-2025 20:05:51 JST Trash Panda Trash Panda
      in reply to
      • Blurry Moon
      • N33R

      @sun@shitposter.world @AVincentInSpace@furry.engineer @N33R@fops.cloud
      Not sure why tbh though.
      The guy was being unreasonable.
      "I don't want data harvesting companies to have my data"
      "Akshually"

      In conversation about 10 months ago permalink
    • Embed this notice
      Trash Panda (raccoon@hollow.raccoon.quest)'s status on Thursday, 23-Oct-2025 20:07:40 JST Trash Panda Trash Panda
      in reply to
      • Blurry Moon
      • N33R

      @sun@shitposter.world @AVincentInSpace@furry.engineer @N33R@fops.cloud

      In conversation about 10 months ago permalink

      Attachments


      1. https://hollow.raccoon.quest/files/334185ce-083f-48c5-90c1-ba08d57ac5a0
      Blurry Moon likes this.
    • Embed this notice
      Blurry Moon (sun@shitposter.world)'s status on Friday, 24-Oct-2025 00:21:44 JST Blurry Moon Blurry Moon
      in reply to
      • Trash Panda
      • N33R
      • Veinglory
      @veinglory @N33R @AVincentInSpace @raccoon this is a better response than they deserved
      In conversation about 10 months ago permalink
    • Embed this notice
      Veinglory (veinglory@freebeerextremist.com)'s status on Friday, 24-Oct-2025 00:21:45 JST Veinglory Veinglory
      in reply to
      • Trash Panda
      • N33R

      @AVincentInSpace @raccoon @N33R

      I personally believe that responsibility in this regard is best left decentralized.

      Naturally, no one expects your forum or whatever to have the same level of security as Google or Facebook, but it's also a less enticing target. The kind of attacks that are visited upon Google's databases are not going to be leveraged against your service because you don't have as much. I don't expect you to be a super de duper security analyst, which is why the password (and maybe even the email/username) that I use on your service is not the one that I use everywhere. If you make a mistake, and my password is compromised somehow, then I just need to change it for your services, because I take some of the responsibility of my security on as well. So you take a chunk of responsibility, and the user takes a chunk, and we don't need to rely on google. Provided you keep your software up to date, and don't make any glaring mistakes, that will be fine for most users. Let's not make the perfect the enemy of the good.

      Also, I think it's a mistake to think that "a system is inherently safer because it has more resources". Google is a closed system. You're not taking into account infrastructure sprawl, increased probability for malicious actors, bureaucratic negligence, misappropriation of resources, failure on the account of contractors/data aggregate partners, etc etc. Just because the paychecks are big doesn't mean everyone is incentivized to be perfect. In fact, if pay is regular, and systems are large and complex enough, compensation can become completely decoupled from incentive. Everyone knows a well-paid manager or employee who just skates by because he hasn't gotten caught yet. I think it's more responsible, and safer for everyone, to reduce attack surface and mitigate risk by spreading it around, rather than giving the keys to the city to one guy and hoping he doesn't screw up.

      In conversation about 10 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.