Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. So @pixelfed still hasn't fully acknowledged nor fixed the security vulnerability from earlier this year, despite multiple people asking for updates over the past ~6 months.

So @pixelfed still hasn't fully acknowledged nor fixed the security vulnerability from earlier this year, despite multiple people asking for updates over the past ~6 months.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
47 Indlæg 10 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • chad@mstdn.caC chad@mstdn.ca

    @thisismissem @dansup @deadsuperhero this conversation has progressed to the point where I think Dan is owed an opportunity to weigh in.

    rey@toot.catR This user is from outside of this forum
    rey@toot.catR This user is from outside of this forum
    rey@toot.cat
    wrote sidst redigeret af
    #37

    @chad @thisismissem @dansup @deadsuperhero he's been tagged on this entire thread

    chad@mstdn.caC 1 Reply Last reply
    0
    • rey@toot.catR rey@toot.cat

      @chad @thisismissem @dansup @deadsuperhero he's been tagged on this entire thread

      chad@mstdn.caC This user is from outside of this forum
      chad@mstdn.caC This user is from outside of this forum
      chad@mstdn.ca
      wrote sidst redigeret af
      #38

      @rey @thisismissem @dansup @deadsuperhero I'm aware. It's also 6am MDT.

      rey@toot.catR 1 Reply Last reply
      0
      • chad@mstdn.caC chad@mstdn.ca

        @rey @thisismissem @dansup @deadsuperhero I'm aware. It's also 6am MDT.

        rey@toot.catR This user is from outside of this forum
        rey@toot.catR This user is from outside of this forum
        rey@toot.cat
        wrote sidst redigeret af
        #39

        @chad @thisismissem @dansup @deadsuperhero this thread started three days ago and he has, apparently, already responded to it

        thisismissem@hachyderm.ioT 1 Reply Last reply
        0
        • rey@toot.catR rey@toot.cat

          @chad @thisismissem @dansup @deadsuperhero this thread started three days ago and he has, apparently, already responded to it

          thisismissem@hachyderm.ioT This user is from outside of this forum
          thisismissem@hachyderm.ioT This user is from outside of this forum
          thisismissem@hachyderm.io
          wrote sidst redigeret af
          #40

          @rey @chad @dansup @deadsuperhero yes, and the only response has been an accusation of spread misinformation which was easily disproven

          chad@mstdn.caC 1 Reply Last reply
          0
          • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

            @rey @chad @dansup @deadsuperhero yes, and the only response has been an accusation of spread misinformation which was easily disproven

            chad@mstdn.caC This user is from outside of this forum
            chad@mstdn.caC This user is from outside of this forum
            chad@mstdn.ca
            wrote sidst redigeret af
            #41

            @thisismissem @rey @dansup @deadsuperhero I feel that given the overall careful discussion here, an accusation of misinformation is a great departure.

            thisismissem@hachyderm.ioT 1 Reply Last reply
            0
            • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

              @chad @dansup @deadsuperhero If he's not actually doing the leading then that's a problem. Where are the people doing PRs? He chased them all off, I can think of at least 3 people that wanted to contribute actively to his projects and he pissed them off by being completely unpredictable to work with.

              hiphopheaven@mastodon.socialH This user is from outside of this forum
              hiphopheaven@mastodon.socialH This user is from outside of this forum
              hiphopheaven@mastodon.social
              wrote sidst redigeret af
              #42

              @thisismissem @chad @dansup @deadsuperhero why do they not create an alternative? This ia suppose to be the power of open source you can fork projects and create new wonderful things

              chad@mstdn.caC 1 Reply Last reply
              0
              • hiphopheaven@mastodon.socialH hiphopheaven@mastodon.social

                @thisismissem @chad @dansup @deadsuperhero why do they not create an alternative? This ia suppose to be the power of open source you can fork projects and create new wonderful things

                chad@mstdn.caC This user is from outside of this forum
                chad@mstdn.caC This user is from outside of this forum
                chad@mstdn.ca
                wrote sidst redigeret af
                #43

                @hiphopheaven @thisismissem @dansup @deadsuperhero there's no one stopping anyone from forking Dan's projects.

                thisismissem@hachyderm.ioT 1 Reply Last reply
                0
                • chad@mstdn.caC chad@mstdn.ca

                  @thisismissem @rey @dansup @deadsuperhero I feel that given the overall careful discussion here, an accusation of misinformation is a great departure.

                  thisismissem@hachyderm.ioT This user is from outside of this forum
                  thisismissem@hachyderm.ioT This user is from outside of this forum
                  thisismissem@hachyderm.io
                  wrote sidst redigeret af
                  #44

                  @chad @rey @dansup @deadsuperhero that was *his* accusation. Not mine. I then spent the time to review the changes, and was fully prepared to update as resolved, only, it wasn't & the changes where thousands of lines of unrelated code. I spent quite some time checking.

                  1 Reply Last reply
                  0
                  • chad@mstdn.caC chad@mstdn.ca

                    @hiphopheaven @thisismissem @dansup @deadsuperhero there's no one stopping anyone from forking Dan's projects.

                    thisismissem@hachyderm.ioT This user is from outside of this forum
                    thisismissem@hachyderm.ioT This user is from outside of this forum
                    thisismissem@hachyderm.io
                    wrote sidst redigeret af
                    #45

                    @chad @hiphopheaven @dansup @deadsuperhero it's hard when he'll actively fight against you, iirc, he got extremely mad when pixelfed-glitch was started, and threatened a trademark lawsuit. That probably killed that person's energy to work on it.

                    He also went after the developer of Vernissage a while back too, when they decided to do their own thing away from pixelfed.

                    Meanwhile he raises 100k for pixelfed, but it seems like all the energy is going into his other projects.

                    1 Reply Last reply
                    0
                    • chad@mstdn.caC chad@mstdn.ca

                      @thisismissem @dansup @deadsuperhero all those words are great, and I align with many of them, but I still haven't seen anyone offer a PR for any of his projects.

                      Honestly, and I'm sorry to say, this is a step up or shut up situation.

                      "He created too much too quickly" really isn't aligned with any of the values many of us hold in the hopes of growth of the fediverse.

                      julian@community.nodebb.orgJ This user is from outside of this forum
                      julian@community.nodebb.orgJ This user is from outside of this forum
                      julian@community.nodebb.org
                      wrote sidst redigeret af
                      #46

                      chad@mstdn.ca re: “step up or shut up”, thisismissem@hachyderm.io has been (is currently?) a contributor for Pixelfed, and was the person responsible for the discovery, analysis, and responsible disclosure of the 10/10 severity vulnerability from last year.

                      She also provided best practice recommendations and guidance on remediation, all for free (there was no security fund back then, and Pixelfed has no bug bounty.)

                      For her to buck responsible disclosure practice (and even then she’s being deliberately vague about the technical details) is a sign that someone is being stonewalled.

                      1 Reply Last reply
                      0
                      Svar
                      • Svar som emne
                      Login for at svare
                      • Ældste til nyeste
                      • Nyeste til ældste
                      • Most Votes


                      • Log ind

                      • Har du ikke en konto? Tilmeld

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      Graciously hosted by data.coop
                      • First post
                        Last post
                      0
                      • Hjem
                      • Seneste
                      • Etiketter
                      • Populære
                      • Verden
                      • Bruger
                      • Grupper