Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
We Distribute
  1. Home
  2. Fediverse
  3. ActivityPub
  4. This is a program that I've been championing within @nivenly over the past year, after we noticed that security vulnerabilities weren't being disclosed responsibly, and not enough research was going into the security of Fediverse software.

This is a program that I've been championing within @nivenly over the past year, after we noticed that security vulnerabilities weren't being disclosed responsibly, and not enough research was going into the security of Fediverse software.

Scheduled Pinned Locked Moved ActivityPub
fediversesecuritynivenlyfediversesecuri
26 Posts 12 Posters 220 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

    This is a program that I've been championing within @nivenly over the past year, after we noticed that security vulnerabilities weren't being disclosed responsibly, and not enough research was going into the security of Fediverse software.

    You might remember my Pixelfed vulnerability from last year, where OAuth scopes weren't checked allowing for privilege escalation via the API (CVE-2024-25108), that was our very first test-case of this program.

    I'm incredibly proud to be involved in launching the Fediverse Security Fund from Nivenly Foundation (a 501(c)4 not-for-profit cooperative)

    #fediverse #security #nivenly #FediverseSecurityFund

    RE: https://hachyderm.io/@nivenly/114268491892140498

    julian@community.nodebb.orgJ This user is from outside of this forum
    julian@community.nodebb.orgJ This user is from outside of this forum
    julian@community.nodebb.org
    wrote on last edited by julian@community.nodebb.org
    #17

    @thisismissem@hachyderm.io what would buy-in from fediverse software look like?

    NodeBB has its own bug bounty program that awards reporters directly, but if the FSF were to shoulder the grunt work of reporting (and act as a liaison between us and the reporter), we'd be happy to discuss covering the reward and associated costs, for reports that come from Nivenly directly.

    1 Reply Last reply
    0
    • julian@community.nodebb.orgJ julian@community.nodebb.org shared this topic on
    • thisismissem@hachyderm.ioT This user is from outside of this forum
      thisismissem@hachyderm.ioT This user is from outside of this forum
      thisismissem@hachyderm.io
      wrote on last edited by
      #18

      @julian you're still receiving the vulnerability reports directly with the Fediverse Security Fund; we pay *after* you've confirmed & patched.

      I wasn't aware of your bug bounty program, but could list that alongside your project.

      julian@community.nodebb.orgJ 1 Reply Last reply
      0
      • System shared this topic on
      • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

        @julian you're still receiving the vulnerability reports directly with the Fediverse Security Fund; we pay *after* you've confirmed & patched.

        I wasn't aware of your bug bounty program, but could list that alongside your project.

        julian@community.nodebb.orgJ This user is from outside of this forum
        julian@community.nodebb.orgJ This user is from outside of this forum
        julian@community.nodebb.org
        wrote on last edited by julian@community.nodebb.org
        #19

        @thisismissem@hachyderm.io great. I'm thinking that for reports coming from Fediverse Security Fund directly, we'd cover the reward portion (the High (7.0 - 8.9) โ€“ $250 USD, Critical (9.0+) โ€“ $500 USD) part, either directly to the reporter or more likely through an in-kind donation back to the fund.

        Also the fund may need a better acronym... FSF ๐Ÿ˜…

        1 Reply Last reply
        0
        • thisismissem@hachyderm.ioT This user is from outside of this forum
          thisismissem@hachyderm.ioT This user is from outside of this forum
          thisismissem@hachyderm.io
          wrote on last edited by
          #20

          @julian so the reports don't come from Nivenly, the reports come from researchers and contributors and go directly to you. Once you accept & fix, and publish the advisory, the researcher/contributor can come to us and we'll pay them for their responsible disclosure.

          They could also still collect from your bounty program as well, so rather than them getting just $256 or $512 from your program, they could get $506 or $1012 in total, because they can claim both bounties (if your program allows it)

          (I mean, it's better than Fediverse Security Bounty โ€” FSB ๐Ÿ˜‚)

          julian@community.nodebb.orgJ esk@hachyderm.ioE 2 Replies Last reply
          0
          • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

            @julian so the reports don't come from Nivenly, the reports come from researchers and contributors and go directly to you. Once you accept & fix, and publish the advisory, the researcher/contributor can come to us and we'll pay them for their responsible disclosure.

            They could also still collect from your bounty program as well, so rather than them getting just $256 or $512 from your program, they could get $506 or $1012 in total, because they can claim both bounties (if your program allows it)

            (I mean, it's better than Fediverse Security Bounty โ€” FSB ๐Ÿ˜‚)

            julian@community.nodebb.orgJ This user is from outside of this forum
            julian@community.nodebb.orgJ This user is from outside of this forum
            julian@community.nodebb.org
            wrote on last edited by
            #21

            @thisismissem@hachyderm.io ah understood. I didn't quite get how the fund worked, but it makes more sense now (and is much simplerโ€”organizationallyโ€”for Nivenly!)

            I don't think we'll add exclusions for security fund recipients ๐Ÿ™‚

            I would say, though, that one of the requirements has to be that the affected software accepts the vulnerability. Plenty of self-proclaimed "security researchers" have filed reports, and some go as far as to publish CVEs (against our own software!) without our permission.

            Quite the opposite of responsible disclosure.

            1 Reply Last reply
            0
            • thisismissem@hachyderm.ioT This user is from outside of this forum
              thisismissem@hachyderm.ioT This user is from outside of this forum
              thisismissem@hachyderm.io
              wrote on last edited by
              #22

              @julian yes, that's exactly what needs to happen. Like, it's CVE + the fix merged into the project. And we'll actually verify that before paying out. Definitely don't want those low quality reports for stuff that isn't actually a CVE

              thisismissem@hachyderm.ioT 1 Reply Last reply
              0
              • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

                @julian yes, that's exactly what needs to happen. Like, it's CVE + the fix merged into the project. And we'll actually verify that before paying out. Definitely don't want those low quality reports for stuff that isn't actually a CVE

                thisismissem@hachyderm.ioT This user is from outside of this forum
                thisismissem@hachyderm.ioT This user is from outside of this forum
                thisismissem@hachyderm.io
                wrote on last edited by
                #23

                @julian we'll see how the fund goes, but we can always change the terms as necessary to get the right output, that's why this is an experiment.

                1 Reply Last reply
                0
                • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

                  @julian so the reports don't come from Nivenly, the reports come from researchers and contributors and go directly to you. Once you accept & fix, and publish the advisory, the researcher/contributor can come to us and we'll pay them for their responsible disclosure.

                  They could also still collect from your bounty program as well, so rather than them getting just $256 or $512 from your program, they could get $506 or $1012 in total, because they can claim both bounties (if your program allows it)

                  (I mean, it's better than Fediverse Security Bounty โ€” FSB ๐Ÿ˜‚)

                  esk@hachyderm.ioE This user is from outside of this forum
                  esk@hachyderm.ioE This user is from outside of this forum
                  esk@hachyderm.io
                  wrote on last edited by
                  #24

                  i feel like we missed an opportunity here @thisismissem by not choosing powers of two

                  love it @julian

                  thisismissem@hachyderm.ioT 1 Reply Last reply
                  0
                  • esk@hachyderm.ioE esk@hachyderm.io

                    i feel like we missed an opportunity here @thisismissem by not choosing powers of two

                    love it @julian

                    thisismissem@hachyderm.ioT This user is from outside of this forum
                    thisismissem@hachyderm.ioT This user is from outside of this forum
                    thisismissem@hachyderm.io
                    wrote on last edited by
                    #25

                    @esk @julian do you wanna adjust? because we can ^_^

                    1 Reply Last reply
                    0
                    • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

                      aaand aaah, TechCrunch have covered the announcement! Thanks @Sarahp!

                      Link Preview Image
                      A new security fund opens up to help protect the fediverse | TechCrunch

                      A new security fund aims to help apps in the fediverse โ€” like Mastodon, Threads, and Pixelfed โ€” to pay researchers for disclosing security bugs.

                      favicon

                      TechCrunch (techcrunch.com)

                      liaizon@social.wake.stL This user is from outside of this forum
                      liaizon@social.wake.stL This user is from outside of this forum
                      liaizon@social.wake.st
                      wrote on last edited by
                      #26

                      @thisismissem damn @Sarahp killing it with the fediverse coverage lately!

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups