GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    feld (feld@bikeshed.party)'s status on Wednesday, 25-Oct-2023 02:58:20 JSTfeldfeld
    in reply to
    • Wolf480pl
    • jabberati
    @jabberati @wolf480pl if the socket only accepts TLS the attack surface is very much hardened already and trusted that it will Do The Right Thing all the time and sanely handle anyone throwing bad data at it

    if the socket accepts plaintext and has its own parsing of the data before the upgrade to TLS it gives attackers something much more interesting to work with that probably hasn't been as thoroughly fuzzed. I'm less interested in downgrade attacks as those are pretty much dead in the water for XMPP as TLS is "required" by the specs, but other attacks on the XMPP server itself.
    In conversationWednesday, 25-Oct-2023 02:58:20 JST from bikeshed.partypermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.