Salta al contenuto
0
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Old Web Site
  • Recenti
  • Popolare
  • Tag
  • Utenti
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Old Web Site
  • Recenti
  • Popolare
  • Tag
  • Utenti
Skin
  • Chiaro
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Scuro
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Predefinito (Cerulean)
  • Nessuna skin
Collassa

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  1. Home
  2. Categorie
  3. Meta
  4. "Security" category

"Security" category

Pianificato Fissato Bloccato Spostato Meta
securityactivitypubcve
6 Post 3 Autori 46 Visualizzazioni
  • Da Vecchi a Nuovi
  • Da Nuovi a Vecchi
  • Più Voti
Rispondi
  • Risposta alla discussione
Effettua l'accesso per rispondere
Questa discussione è stata eliminata. Solo gli utenti con diritti di gestione possono vederla.
  • julian@activitypub.space Questo utente è esterno a questo forum
    julian@activitypub.space Questo utente è esterno a questo forum
    julian@activitypub.space
    scritto su ultima modifica di
    #1

    Just a thought as I work through some bugs reported to NodeBB... would there be interest in ActivityPub.space hosting a "security" category for discussion around vulnerabilities, CVEs, and such that are related to ActivityPub?

    For example, if NodeBB were to receive a bug bounty report and responsibly disclose the details, it would be ideal to have it archived in a place where it won't just disappear off the feed in a matter of minutes.

    thisismissem@hachyderm.io fentiger@mastodon.social 2 Risposte Ultima Risposta
    0
    • julian@activitypub.space julian@activitypub.space

      Just a thought as I work through some bugs reported to NodeBB... would there be interest in ActivityPub.space hosting a "security" category for discussion around vulnerabilities, CVEs, and such that are related to ActivityPub?

      For example, if NodeBB were to receive a bug bounty report and responsibly disclose the details, it would be ideal to have it archived in a place where it won't just disappear off the feed in a matter of minutes.

      thisismissem@hachyderm.io Questo utente è esterno a questo forum
      thisismissem@hachyderm.io Questo utente è esterno a questo forum
      thisismissem@hachyderm.io
      scritto su ultima modifica di
      #2

      @julian @smallcircles that'd probably be a bad idea, as you'd likely get irresponsible disclosure happening.

      julian@activitypub.space 1 Risposta Ultima Risposta
      0
      • julian@activitypub.space julian@activitypub.space

        Just a thought as I work through some bugs reported to NodeBB... would there be interest in ActivityPub.space hosting a "security" category for discussion around vulnerabilities, CVEs, and such that are related to ActivityPub?

        For example, if NodeBB were to receive a bug bounty report and responsibly disclose the details, it would be ideal to have it archived in a place where it won't just disappear off the feed in a matter of minutes.

        fentiger@mastodon.social Questo utente è esterno a questo forum
        fentiger@mastodon.social Questo utente è esterno a questo forum
        fentiger@mastodon.social
        scritto su ultima modifica di
        #3

        @julian It would be great to have a collection of these that I could look through, to make sure I'm not making easily preventable mistakes myself.

        Of course, potential bad guys would be able to look through it too...

        1 Risposta Ultima Risposta
        0
        • thisismissem@hachyderm.io thisismissem@hachyderm.io

          @julian @smallcircles that'd probably be a bad idea, as you'd likely get irresponsible disclosure happening.

          julian@activitypub.space Questo utente è esterno a questo forum
          julian@activitypub.space Questo utente è esterno a questo forum
          julian@activitypub.space
          scritto su ultima modifica di
          #4

          thisismissem@hachyderm.io how so? In the sense that discussed vulnerabilities might be exploitable cross-implementation?

          1 Risposta Ultima Risposta
          0
          • thisismissem@hachyderm.io Questo utente è esterno a questo forum
            thisismissem@hachyderm.io Questo utente è esterno a questo forum
            thisismissem@hachyderm.io
            scritto su ultima modifica di
            #5

            @julian we've definitely seen that before, but also people might not realize that they're discussing a vulnerability

            julian@activitypub.space 1 Risposta Ultima Risposta
            0
            • thisismissem@hachyderm.io thisismissem@hachyderm.io

              @julian we've definitely seen that before, but also people might not realize that they're discussing a vulnerability

              julian@activitypub.space Questo utente è esterno a questo forum
              julian@activitypub.space Questo utente è esterno a questo forum
              julian@activitypub.space
              scritto su ultima modifica di
              #6

              thisismissem@hachyderm.io hmm that's fair. I don't think it precludes interested parties from having these discussions though.

              I'm not sure what the right solution is.

              1 Risposta Ultima Risposta
              0

              Ciao! Sembra che tu sia interessato a questa conversazione, ma non hai ancora un account.

              Stanco di dover scorrere gli stessi post a ogni visita? Quando registri un account, tornerai sempre esattamente dove eri rimasto e potrai scegliere di essere avvisato delle nuove risposte (tramite email o notifica push). Potrai anche salvare segnalibri e votare i post per mostrare il tuo apprezzamento agli altri membri della comunità.

              Con il tuo contributo, questo post potrebbe essere ancora migliore 💗

              Registrati Accedi
              Rispondi
              • Risposta alla discussione
              Effettua l'accesso per rispondere
              • Da Vecchi a Nuovi
              • Da Nuovi a Vecchi
              • Più Voti


              Feed RSS
              "Security" category
              @pierobosio@soc.bosio.info
              NodeBB Contributors
              • Accedi

              • Accedi o registrati per effettuare la ricerca.
              • Primo post
                Ultimo post