Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
We Distribute
  1. Home
  2. Meta
  3. "Security" category

"Security" category

Scheduled Pinned Locked Moved Meta
securityactivitypubcve
7 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • julian@activitypub.spaceJ This user is from outside of this forum
    julian@activitypub.spaceJ This user is from outside of this forum
    julian@activitypub.space
    wrote last edited by
    #1

    Just a thought as I work through some bugs reported to NodeBB... would there be interest in ActivityPub.space hosting a "security" category for discussion around vulnerabilities, CVEs, and such that are related to ActivityPub?

    For example, if NodeBB were to receive a bug bounty report and responsibly disclose the details, it would be ideal to have it archived in a place where it won't just disappear off the feed in a matter of minutes.

    thisismissem@hachyderm.ioT 1 Reply Last reply
    0
    • julian@activitypub.spaceJ julian@activitypub.space

      Just a thought as I work through some bugs reported to NodeBB... would there be interest in ActivityPub.space hosting a "security" category for discussion around vulnerabilities, CVEs, and such that are related to ActivityPub?

      For example, if NodeBB were to receive a bug bounty report and responsibly disclose the details, it would be ideal to have it archived in a place where it won't just disappear off the feed in a matter of minutes.

      thisismissem@hachyderm.ioT This user is from outside of this forum
      thisismissem@hachyderm.ioT This user is from outside of this forum
      thisismissem@hachyderm.io
      wrote last edited by
      #2

      @julian @smallcircles that'd probably be a bad idea, as you'd likely get irresponsible disclosure happening.

      julian@activitypub.spaceJ 1 Reply Last reply
      0
      • fentiger@mastodon.socialF This user is from outside of this forum
        fentiger@mastodon.socialF This user is from outside of this forum
        fentiger@mastodon.social
        wrote last edited by
        #3

        @julian It would be great to have a collection of these that I could look through, to make sure I'm not making easily preventable mistakes myself.

        Of course, potential bad guys would be able to look through it too...

        1 Reply Last reply
        0
        • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

          @julian @smallcircles that'd probably be a bad idea, as you'd likely get irresponsible disclosure happening.

          julian@activitypub.spaceJ This user is from outside of this forum
          julian@activitypub.spaceJ This user is from outside of this forum
          julian@activitypub.space
          wrote last edited by
          #4

          thisismissem@hachyderm.io how so? In the sense that discussed vulnerabilities might be exploitable cross-implementation?

          1 Reply Last reply
          0
          • thisismissem@hachyderm.ioT This user is from outside of this forum
            thisismissem@hachyderm.ioT This user is from outside of this forum
            thisismissem@hachyderm.io
            wrote last edited by
            #5

            @julian we've definitely seen that before, but also people might not realize that they're discussing a vulnerability

            julian@activitypub.spaceJ 1 Reply Last reply
            0
            • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

              @julian we've definitely seen that before, but also people might not realize that they're discussing a vulnerability

              julian@activitypub.spaceJ This user is from outside of this forum
              julian@activitypub.spaceJ This user is from outside of this forum
              julian@activitypub.space
              wrote last edited by
              #6

              thisismissem@hachyderm.io hmm that's fair. I don't think it precludes interested parties from having these discussions though.

              I'm not sure what the right solution is.

              1 Reply Last reply
              0
              • thisismissem@hachyderm.ioT This user is from outside of this forum
                thisismissem@hachyderm.ioT This user is from outside of this forum
                thisismissem@hachyderm.io
                wrote last edited by
                #7

                @julian probably a private forum for implementers

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Don't have an account? Register

                • Login or register to search.
                Powered by NodeBB Contributors
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups