Dusty

joined 2 years ago
[–] Dusty@l.dustybeer.com 5 points 2 years ago

The “responsibility” part of responsible disclosure goes both ways

It absolutely does, it also means following up, not "They didn't reply in a week so instead of trying other ways to contact them, I'm just going to post about it". They didn't even try to open an issue because they "don't use github" all while coming here talking about how bad the vulnerability is.

It's poor (lack of) judgement on OP's part.

[–] Dusty@l.dustybeer.com 3 points 2 years ago (3 children)

Typical reasonable disclosure is in terms months usually, not "nearly a week". OP is being irresponsible at best by posting this before giving time to the developers to see, and act on it.

[–] Dusty@l.dustybeer.com 2 points 2 years ago (1 children)

Thank you, I was going to write one up tonight for it. You emailed security @ correct? https://github.com/LemmyNet/lemmy/security/policy

[–] Dusty@l.dustybeer.com 8 points 2 years ago (5 children)

OP doesn't seem interested in that. They state they "sent a vulnerability a week ago" and didn't hear back so they are being completely irresponsible and posting about it publicly on a community instead.

[–] Dusty@l.dustybeer.com 9 points 2 years ago (5 children)

If you find a way to disclose vulnerabilities without being ghosted by Lemmy developers: update me.

How have you been "ghosted by Lemmy developers" especially if you "do not use GitHub"

[–] Dusty@l.dustybeer.com 17 points 2 years ago (1 children)

It's not even a question (outside of clickbait bs by news agencies)

[–] Dusty@l.dustybeer.com 6 points 2 years ago

lemmy.world is probably overloaded.

On my instance, everything from them floods through all at once, filling my first couple of pages with hours or even days worth of stuff, then I'll get nothing from them for a while again.

[–] Dusty@l.dustybeer.com 15 points 2 years ago (1 children)

I mean, maybe it's because I'm not overly paranoid or live in the US, but this doesn't seem like a big deal at all.

As for the "drama" of them telling someone they can unfollow, it's true. It's again, not a big deal.

This screams people trying to make a mountain out of a molehill.

[–] Dusty@l.dustybeer.com 1 points 2 years ago (1 children)

I ended up just hosting my own Searxng instance. Seems a lot easier to control and not be dependent on how someone else has theirs set up.

[–] Dusty@l.dustybeer.com 1 points 2 years ago

Do we know the domains they are going to use for federation yet?

[–] Dusty@l.dustybeer.com 1 points 2 years ago

What's wrong with Ubuntu?

[–] Dusty@l.dustybeer.com 10 points 2 years ago

My favorite part is when it finally becomes somewhat less overloaded, and my instance gets flooded with a bunch of posts from there filling the entirety of my front page, and the second page...

 

I tried searching for a local place, and all I got for the first two pages are instagram and facebook pages. It wasn't until the third page I got past all that crap to get to the actual website for the location. I even tried search "PlaceName City Website" and still got all that crap instead.

Is there any way to block it on my personal searxng instance? Sorry if it's obvious.

view more: next ›