Post B5nHqPy8uwmuyHBZ0y by cxiao@infosec.exchange
(DIR) More posts by cxiao@infosec.exchange
(DIR) Post #B5nHqPy8uwmuyHBZ0y by cxiao@infosec.exchange
0 likes, 0 repeats
RE: https://infosec.exchange/@jvoisin/116488420408417722For @ifin folks, I started a discussion about this on the Discourse here: https://discourse.ifin.network/t/carrot-disclosure-forgejo/My personal thought is that I appreciate, as a defender, knowing this information about a project having a systematic lack of security.RT: https://infosec.exchange/users/jvoisin/statuses/116488420408417722
(DIR) Post #B5nHqQUkxgsMbQRbqi by oilheap@infosec.exchange
0 likes, 0 repeats
@cxiao @ifin "carrot disclosure" wtf. This is not the most stupid thing I've seen this week, but it's up there. This helps nobody and only inflates the ego of the researcher. The fact that they considered "sellability" of these issues already gives enough insight.
(DIR) Post #B5nHqQr5cejxigtRey by kouhai@social.treehouse.systems
0 likes, 0 repeats
@oilheap @cxiao @ifin for what it’s worth, we (treehouse staff and community) had a productive discussion with the author on discord; hopefully further updates will trickle out over the next days
(DIR) Post #B5nHqRE8EzAis9fqZk by cxiao@infosec.exchange
0 likes, 0 repeats
@kouhai @oilheap @ifin TY! I'm a little surprised by the extreme negative reactions to this TBH. From the perspective of being a Forgejo or other OSS maintainer it sucks to see this. But at the end of the day attackers don't care and aren't going to tell you in this way, or any way, that you have serious issues
(DIR) Post #B5nHqRVrB5Lll7y0Ce by demize@unstable.systems
0 likes, 0 repeats
@cxiao @kouhai I can understand the negative reaction; telling a well-respected and very open source project “you have serious issues but I’m not going to tell you what they actually are” without any attempt to actually flag the issues to them is… not great? it’s not like this is a company that can bring in someone to audit the code, it’s an open source project that would love to fix the issues but is resource constrained by virtue of being an open source project it’s an inherently aggressive approach to disclosure and it doesn’t come off as “helpful” nearly as much as “condescending”, and while that’s one thing to direct at a corporation…