home.social

#globaleaks — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #globaleaks, aggregated by home.social.

fetched live
  1. two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

    CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

    CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

    github.com/globaleaks/globalea and github.com/globaleaks/globalea

    #GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

  2. two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

    CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

    CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

    github.com/globaleaks/globalea and github.com/globaleaks/globalea

    #GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

  3. @EUCommission

    this is objectively a harmful lie and you should educate yourself and use Tor-based whistleblowing tools like @securedrop or #globaleaks like the New York Times uses for the protection of sources

  4. @EUCommission

    this is objectively a harmful lie and you should educate yourself and use Tor-based whistleblowing tools like @securedrop or #globaleaks like the New York Times uses for the protection of sources

  5. O evento #Tor, #Snowflake & #Globaleaks é Sábado dia 29 de Julho de 2023 a partir das 11:30, no Makers In Little Lisbon - #MILL, que é em #Lisboa e conta com a colaboração da #PrivacyLx.

    mill.pt/agenda/tor-snowflake-e

  6. Oltre confine: scambi culturali ad Amsterdam sulle piattaforme di whistleblowing

    @giornalismo

    Dal 30/5 al 1/6 i rappresentanti delle piattaforme di whistleblowing di Nigeria, Indonesia e Messico hanno visitato #FreePressUnlimited ad Amsterdam.
    Queste derivano da #Publeaks, fondata da FPU con il supporto di #Greenhost e #Globaleaks

    Le piattaforme di whistleblowing consentono a #whistleblower e giornalisti di comunicare in modo privato, anonimo e sicuro.

    freepressunlimited.org/en/curr

  7. Oltre confine: scambi culturali ad Amsterdam sulle piattaforme di whistleblowing

    @giornalismo

    Dal 30/5 al 1/6 i rappresentanti delle piattaforme di whistleblowing di Nigeria, Indonesia e Messico hanno visitato #FreePressUnlimited ad Amsterdam.
    Queste derivano da #Publeaks, fondata da FPU con il supporto di #Greenhost e #Globaleaks

    Le piattaforme di whistleblowing consentono a #whistleblower e giornalisti di comunicare in modo privato, anonimo e sicuro.

    freepressunlimited.org/en/curr

  8. Community call: pubblicazione in riuso e gestione delle contribuzioni - l'esperienza di #GlobaLeaks

    mobilizon.it/events/14a8edaf-2

    Condividere idee, scambiare buone pratiche, costruire sinergie e creare occasioni d’incontro: riprendono le community call di #Developers Italia e #Designers Italia. Un momento di scambio pensato per tutti noi impegnati nella promozione della cultura dell’#opensource e della progettazione dei #servizipubblici digitali centrati sui bisogni dei cittadini.

  9. Imagine you are an org that would like to help #whistleblowers.

    You consider installing #Securedrop but decide against it because it's too complicated.

    You stumble over #Globaleaks by #HermesCenter in Italy only to find out that they …
    – embed Google's reCaptcha on their website
    – let Google set a cookie that Google can use to identify you elsewhere
    – include Google fonts directly from Google servers
    – use GMail for e-mail

    What do you do?

    privacyscore.org/site/148601/

    webbkoll.dataskydd.net/en/resu

    /c

  10. Quelle est selon vous la meilleure plateforme pour lanceurs d'alerte ? (du type #securedrop ou #globaleaks)
    @aeris j'imagine que tu as un avis

  11. in aggiunta a quanto riportato nell'articolo, #ANAC sta quindi pure violando la licenza di #GlobaLeaks, avendolo abusivamente distribuito sotto un'altra licenza #waytogo
    « Corruzione, #OpenWhistleblowing è stata un’occasione mancata » ilfattoquotidiano.it/2019/02/0 via @fattoquotidiano