#globaleaks — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #globaleaks, aggregated by home.social.
-
two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
-
two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
-
this is objectively a harmful lie and you should educate yourself and use Tor-based whistleblowing tools like @securedrop or #globaleaks like the New York Times uses for the protection of sources
-
this is objectively a harmful lie and you should educate yourself and use Tor-based whistleblowing tools like @securedrop or #globaleaks like the New York Times uses for the protection of sources
-
USING GLOBALEAKS TO PROTECT SOURCES https://lipanisecurity.com/using-globaleaks-to-protect-sources/ #security #globaleaks #opensource #saftey #cybersecurity #networksecurity #computersecurity #privacy
-
USING GLOBALEAKS TO PROTECT SOURCES https://lipanisecurity.com/using-globaleaks-to-protect-sources/ #security #globaleaks #opensource #saftey #cybersecurity #networksecurity #computersecurity #privacy
-
Top 6 Anonymous Whistleblower Tools to Protect Your Identity
https://stackdiary.com/anonymous-whistleblower-tools/
#whistleblower #securedrop #briar #eff #onionshare #haven #globaleaks
-
-
O evento #Tor, #Snowflake & #Globaleaks é Sábado dia 29 de Julho de 2023 a partir das 11:30, no Makers In Little Lisbon - #MILL, que é em #Lisboa e conta com a colaboração da #PrivacyLx.
-
Oltre confine: scambi culturali ad Amsterdam sulle piattaforme di whistleblowing
Dal 30/5 al 1/6 i rappresentanti delle piattaforme di whistleblowing di Nigeria, Indonesia e Messico hanno visitato #FreePressUnlimited ad Amsterdam.
Queste derivano da #Publeaks, fondata da FPU con il supporto di #Greenhost e #GlobaleaksLe piattaforme di whistleblowing consentono a #whistleblower e giornalisti di comunicare in modo privato, anonimo e sicuro.
-
Oltre confine: scambi culturali ad Amsterdam sulle piattaforme di whistleblowing
Dal 30/5 al 1/6 i rappresentanti delle piattaforme di whistleblowing di Nigeria, Indonesia e Messico hanno visitato #FreePressUnlimited ad Amsterdam.
Queste derivano da #Publeaks, fondata da FPU con il supporto di #Greenhost e #GlobaleaksLe piattaforme di whistleblowing consentono a #whistleblower e giornalisti di comunicare in modo privato, anonimo e sicuro.
-
Community call: pubblicazione in riuso e gestione delle contribuzioni - l'esperienza di #GlobaLeaks
https://mobilizon.it/events/14a8edaf-2af5-4bd1-a178-1420c71d7d61
Condividere idee, scambiare buone pratiche, costruire sinergie e creare occasioni d’incontro: riprendono le community call di #Developers Italia e #Designers Italia. Un momento di scambio pensato per tutti noi impegnati nella promozione della cultura dell’#opensource e della progettazione dei #servizipubblici digitali centrati sui bisogni dei cittadini.
-
Imagine you are an org that would like to help #whistleblowers.
You consider installing #Securedrop but decide against it because it's too complicated.
You stumble over #Globaleaks by #HermesCenter in Italy only to find out that they …
– embed Google's reCaptcha on their website
– let Google set a cookie that Google can use to identify you elsewhere
– include Google fonts directly from Google servers
– use GMail for e-mailWhat do you do?
https://privacyscore.org/site/148601/
https://webbkoll.dataskydd.net/en/results?url=http%3A%2F%2Fglobaleaks.org
/c
-
Quelle est selon vous la meilleure plateforme pour lanceurs d'alerte ? (du type #securedrop ou #globaleaks)
@aeris j'imagine que tu as un avis -
in aggiunta a quanto riportato nell'articolo, #ANAC sta quindi pure violando la licenza di #GlobaLeaks, avendolo abusivamente distribuito sotto un'altra licenza #waytogo
« Corruzione, #OpenWhistleblowing è stata un’occasione mancata » https://www.ilfattoquotidiano.it/2019/02/04/corruzione-openwhistleblowing-e-stata-unoccasione-mancata/4944067/ via @fattoquotidiano