GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Nicholas Dionysopoulos (nikosdion@fosstodon.org)

  1. Embed this notice
    Nicholas Dionysopoulos (nikosdion@fosstodon.org)'s status on Friday, 02-Jun-2023 09:13:26 JST Nicholas Dionysopoulos Nicholas Dionysopoulos

    #joomla now has the only MFA implementation in the world with a pointless and user-hostile retry limit, therefore making sure that people WILL get locked out of their sites, with no way to get back in that doesn't involve database editing, thereby conditioning them to NOT use MFA. I should had never contributed this to Joomla. I should have known better. Stupid me.

    In conversation Friday, 02-Jun-2023 09:13:26 JST from fosstodon.org permalink
  2. Embed this notice
    Nicholas Dionysopoulos (nikosdion@fosstodon.org)'s status on Friday, 02-Jun-2023 09:13:25 JST Nicholas Dionysopoulos Nicholas Dionysopoulos
    in reply to

    Another idiotic thing this so-called "security" #joomla patch gets wrong is that it does not reset the MFA retry count when you log in with WebAuthn (or any other "silent" login). You know, the authentication options which deliberately bypass MFA because the security is guaranteed otherwise.

    In conversation Friday, 02-Jun-2023 09:13:25 JST from fosstodon.org permalink
  3. Embed this notice
    Nicholas Dionysopoulos (nikosdion@fosstodon.org)'s status on Friday, 02-Jun-2023 09:13:23 JST Nicholas Dionysopoulos Nicholas Dionysopoulos
    in reply to
    • Martin

    @MartinH Therefore, you are disabling the ONLY secure way of logging into your site. Because Joomla decided to water down this feature so much that it became a nuisance. I tried to keep y'all safe with WebAuthn and MFA but the Joomla! idiocracy prevailed. I should have kept this code as 3PD extensions. I should have known better than to trust Joomla! with my code. Well, not a mistake I'll be doing again!

    In conversation Friday, 02-Jun-2023 09:13:23 JST from fosstodon.org permalink
  4. Embed this notice
    Nicholas Dionysopoulos (nikosdion@fosstodon.org)'s status on Thursday, 05-Jan-2023 06:52:23 JST Nicholas Dionysopoulos Nicholas Dionysopoulos

    Ah, January. What better way to start the new year than spending a day to change #copyright headers across the numerous #foss repositories I actively manage? It's nearly midnight and I'm just done — literally and figuratively.

    In conversation Thursday, 05-Jan-2023 06:52:23 JST from fosstodon.org permalink

User actions

    Nicholas Dionysopoulos

    Nicholas Dionysopoulos

    Father, husband, PHP tamer, mechanical keyboard enthusiast, cat herder. I write FOSS for a living. I stand for privacy, equality, and social justice. He/him.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          85043
          Member since
          4 Jan 2023
          Notices
          4
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.