GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Taggart :donor: (mttaggart@infosec.town)'s status on Wednesday, 18-Oct-2023 05:49:58 JSTTaggart :donor:Taggart :donor:

    To recap:

    - X added a Settings option for using HTTP proxies in the app.
    - But, it doesn't actually route any traffic to a proxy. Nothing in the app references the setting, and dynamic analysis shows no traffic being sent to the proxy.
    - This means people trying to stay safe by using this feature are in greater danger due to a false sense of security.

    The bug report I reference below was closed instantly as not-a-bug.

    RE: https://infosec.town/notes/9ky1hz9tcj5gf8va

    In conversation2 years ago from infosec.townpermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.town
      Taggart :donor: (@mttaggart)
      Actually took the time to submit a h1 report about the HTTP proxy thing. I can't understand why this isn't a bigger deal. It could get someone killed or imprisoned.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.

Embed this notice