Post B5nDLuYak7bH2nQqQa by kouhai@social.treehouse.systems
(DIR) More posts by kouhai@social.treehouse.systems
(DIR) Post #B5nCsfPLzHxRf8AMoy by ariadne@social.treehouse.systems
1 likes, 1 repeats
@jvoisin carrot disclosure is intended to be the nuclear option. while Forgejo and Gitea before it do have eyebrow-raising code from a security pov, it is also a true community-based FOSS project and going nuclear on them like this is a horrid look.
(DIR) Post #B5nDLuYak7bH2nQqQa by kouhai@social.treehouse.systems
0 likes, 0 repeats
@ariadne treehouse did a positive peer pressure on the discord :)
(DIR) Post #B5nDaJkVsKk1EMsTUO by wronglang@bayes.club
1 likes, 0 repeats
@ariadne @jvoisin <snark>but I mean the alternative would've been to spend time reporting and maybe the developers wouldn't take you as seriously as you think you should be taken and that might hurt your feelings or require emotional labor to convince someone to look more broadly</snark>
(DIR) Post #B5njT3rVk49qSojbiC by sam@shonk.sam.ax
0 likes, 0 repeats
@ariadne@social.treehouse.systems @jvoisin@infosec.exchange yeah it’s riddled with technical debt, but still a FOSS project with good governance that I hold in high esteem. get off your high horse, OP - this isn’t Cisco
(DIR) Post #B5njT47SmkuzGICLZo by sam@shonk.sam.ax
0 likes, 0 repeats
@ariadne@social.treehouse.systems @jvoisin@infosec.exchange ah it’s a blog reposter bot, in that case: OP is absolutely a dick
(DIR) Post #B5njT4Mhs56y1ZKWKu by kpcyrd@chaos.social
0 likes, 0 repeats
@sam @ariadne @jvoisin as much as I want forgejo to be the good folks, the optics ain't great: https://codeberg.org/forgejo/forgejo/pulls/12288You may ASK unpaid security research volunteers to participate in some coordinated disclosure, but you can't demand they surrender their free time beyond the report. The maintainers are NLnet funded, the security researcher is operating on goodwill. The bugs are still sitting unaddressed in the open, although there's a recent commit fixing token expiry.
(DIR) Post #B5njYshk8dqPb3wP6e by ariadne@social.treehouse.systems
0 likes, 0 repeats
@sam @jvoisin @kpcyrd I will concede their security policy is pretty silly, e.g.> If you discover a security vulnerability in Forgejo, you MUST send an encrypted email to security@forgejo.org, combined with all available details. The same applies when a security issue was not properly addressed in Forgejo.I must send an *encrypted* email? okay I choose to encrypt with null cipher :) in this case I would just continue opening PRs and ignore that person 🙃