home.social

#mastosec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mastosec, aggregated by home.social.

fetched live
  1. Thank you @arcanicanis for making us users on here safer and reporting this critical Mastodon vulnerability.

    And @Gargron and team for the prompt fix and patching of mastodon.social.

    If your instance isn't patched, you should probably ping your admin.

    "Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account.”

    github.com/mastodon/mastodon/s

    #Mastodon #MastoSec #CVE_2024_23832 #MastoAdmin

  2. Thank you @arcanicanis for making us users on here safer and reporting this critical Mastodon vulnerability.

    And @Gargron and team for the prompt fix and patching of mastodon.social.

    If your instance isn't patched, you should probably ping your admin.

    "Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account.”

    github.com/mastodon/mastodon/s

    #Mastodon #MastoSec #CVE_2024_23832 #MastoAdmin

  3. @davidgerard @Edent

    The underling design problem:
    Instances in a federated network are implemented as peers in a p2p network.
    Thus not advantaging federation at all.

    ¯\_(ツ)_/¯

    #Infosec
    #FediSec
    #MastoSec
    #vulnerability
    #cybersecurity
    #SoftwareEngineering
    #DistributedSystems

  4. @davidgerard @Edent

    The underling design problem:
    Instances in a federated network are implemented as peers in a p2p network.
    Thus not advantaging federation at all.

    ¯\_(ツ)_/¯

    #Infosec
    #FediSec
    #MastoSec
    #vulnerability
    #cybersecurity
    #SoftwareEngineering
    #DistributedSystems

  5. » What is the number one vulnerability?

    That question caught me by surprise.
    ...
    I responded with “developers pushing credentials into public repositories”.

    The interviewer smiled at me, she liked my answer, but clearly I was wrong. She said

    The number one vulnerability is system misconfiguration «

    @alevsk

    alevsk.com/2022/11/system-misc

    #Infosec
    #FediSec
    #MastoSec
    #vulnerability
    #cybersecurity

  6. » What is the number one vulnerability?

    That question caught me by surprise.
    ...
    I responded with “developers pushing credentials into public repositories”.

    The interviewer smiled at me, she liked my answer, but clearly I was wrong. She said

    The number one vulnerability is system misconfiguration «

    @alevsk

    alevsk.com/2022/11/system-misc

    #Infosec
    #FediSec
    #MastoSec
    #vulnerability
    #cybersecurity