Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)P
Posts
127
Comments
432
Joined
2 yr. ago

  • Are you hoping to restart our disagreement through sheer passive-aggressiveness? Okay, sure.

    In my view, this is a Mastodon design flaw (or a user-expectation issue or whatever you want to call it.) I already said that, and you're involved in the unproductive-arguer's pastime of pretending not to understand that that's my position, and just aggressively repeatedly reframing things according to your position and hoping I'll knuckle under to it through sheer force of repetition.

    I'm not super invested in trying to track down each and every software that might manage to expose the "private" statuses in this way. I just know that as things come and go there are guaranteed to be some. If you have an mbin account and Mastodon account, though, we can try a little experiment. I don't know the outcome, I'm just curious after taking a quick look down the FediDB list and a quick grep through mbin's source code. You can be the one to responsibly disclose to mbin how their ActivityPub-conforming behavior is a problem, if indeed it turns out that it is, since you seem to be extremely committed to the idea that the model of "vulnerability" needs to be applied to this particular ActivityPub-conforming behavior. Since you're a security researcher, having that as a CVE you discovered can be an achievement for you. It's all yours, you can have it.

  • Hm... maybe. The exact nature of the problem in Pixelfed means that anyone with a Pixelfed account on a server which is getting private statuses can choose to follow someone who's set to "approve followers" and then read all the private statuses. I do see how that's significantly worse than just the normal lay-of-the-land of the problem, which is a little more random, and laying that out as a little roadmap to read someone else's private statuses before there's been a nice responsible length of time for things to get fixed could be seen as worsening the problem.

    The point that I'm making is that anyone who's posting private statuses to Mastodon and expecting them to stay private is making a bad mistake already. The structure of the protocol is such that they can't be assured of staying private regardless of what Pixelfed did or even if Pixelfed didn't exist. They're getting federated to servers whose behavior is not assured, in a way where a conformant ActivityPub implementation can expose them. People who are posting private statuses need to understand that.

    That whole blog post where the person is talking about her partner writing private statuses, and then the gut-wrenching realization that they were being exposed on Pixelfed... but then the resolution being "Pixelfed fucked up I hate Dansup now" and then continuing to post the private statuses, is wrong. That person's partner needs to stop treating their private posts on Mastodon that way. The timer for responsible disclosure started circa 2017 or whenever Mastodon decided on how to implement their private statuses. It's been and gone.

    Like I say, I get the harm-reduction aspect of saying it would have been better if Dansup was a little more discreet about this particularly bad attack vector until a few more days went by for everyone to upgrade. But it hardly matters. There are still server softwares our there that are going to be exposing people's private Mastodon posts. It's just how federation between untrusted servers works. Giving people the illusion that if Dan had just been more discreet then this harm would have been reduced is lulling them into a false sense of security, in my view.

  • Maybe I’m wrong, but shouldn’t posts only be insecure if they’re propagated to the insecure instance?

    "Insecure" in this case simply means any server that doesn't implement Mastodon's custom handling for "private" posts. With that definition, the answer to your question is yes. It has been mentioned by Mastodon people that this is a significant problem for the ability to actually keep these private posts private in the real world. The chance of it going wrong is small (depending on your follower count) but the potential for harm is very large. I would therefore go further, and say that it's a very bad thing that Mastodon is telling people that these posts are "private" when the mechanism which is supposed to keep them private is so unreliable.

    https://marrus-sh.github.io/mastodon-info/everything-you-need-to-know-about-privacy-v1.3-020170427.html

    https://github.com/mastodon/mastodon/issues/712

    Is any private post visible to people on servers that the poster doesn’t have followers on?

    It is not. If you're sufficiently careful with approving your followers, making sure that each of them is on an instance that's going to handle private posts the way you expect, then you're probably fine.

    Could I curl the uri of a post thats “private” and get the post’s content?

    If it's been federated to an insecure server then yes. If not then I think no.

  • Yeah, you said that stuff before and then you said it again. I do understand what your argument is here. I was trying a couple of different ways of explaining what I was saying in response, but it seems like it's not working. Oh well.

  • I’ve said nothing about any spec violation. That’s not relevant.

    It has everything to do with ActivityPub since if you follow that protocol strictly you will cause this behavior.

    That's what I was going by. I guess I could re-read this now and interpret "this behavior" as Pixelfed's side, instead of Mastodon's side as I initially read it, and decide that you are agreeing with me that Mastodon's behavior was (and is) out of spec? Do I have that right?

    It still doesn’t change that Dansup was told that this caused Bad Things™ and yet he didn’t follow normal procedure in how you handle it.

    It is normal procedure to fix a bug when you are notified about it.

    The design flaw in Mastodon that managed to bite Pixelfed in this situation still exists. People were writing about it back in 2017 when this was all being first implemented. The idea that "normal procedure" needs to include keeping it a secret that Mastodon's "private" statuses can be exposed by any server software that doesn't handle them in the way that's expected, is 100% wrong.

    I'll rephrase what I said earlier: Since you're a security researcher, and you apparently think Dan should have played into the idea of keeping it a secret that Mastodon's private statuses are not secret by obfuscating the information about how he was fixing Pixelfed to more effectively hide them, you are bad at your job. In this instance. The fault lies with how private statuses are implemented, and nothing about that needs to be kept secret as would a normal vulnerability, during responsible disclosure. In fact, it is extremely harmful to let users believe that these privacy settings are anything other than vague recommendations, specifically because of the risk they will act accordingly and expose some of their private posts to the world. They should know exactly what's going on with it, and Dan accidentally failing to keep that a secret is in no way causing bad things.

  • It is to the person who discovers the vulnerability. That's fairly normal... how would giving it to someone else motivate the result they're trying to get?

  • Okay. What part of the spec did Pixelfed violate? Where in the spec is Mastodon's implementation of private posts justified?

  • It has everything to do with ActivityPub since if you follow that protocol strictly you will cause this behavior.

    Absolutely not. Which part of the spec? I linked up there to quite a thorough explanation of what the spec does and doesn't dictate in this area, and how Mastodon chooses to behave in its implementation. What part of my explanation did I get wrong? Are they violating 5.1, 5.2, 7.1, some other part? How?

    /cybersec researcher

    I do not believe you. "I'm sending things out which need to be handled carefully in a protocol-nonstandard way by the recipient server software (which could be literally anything), or else my user's private posts will be exposed. If someone talks about that situation and lets people know what's going on, that's irresponsible disclosure."

    If you actually are a cybersec researcher, you are bad at your job.

    1. This is nothing to do with ActivityPub. It's to do with Mastodon's custom implementation of "private" posts.
    2. Making it extremely clear to everyone that random server software can expose Mastodon's "private" posts is absolutely the right way to handle disclosure here. Dan didn't even try to do that, he just fixed the bug, but if he had made a big post saying "hey this is not my fault Mastodon private posts are not private, here's full explanation about what's going on" I think that would have been completely fine. This is not a "vulnerability" in the traditional sense like a buffer overflow, it's just a design flaw in Mastodon which other softwares are by convention agreeing to cater to. I think the culture of security (and the level of clue in general) in the Fediverse has wandered into territory where "let's all pretend that these posts are secure and get mad at anyone who reveals that they are not" is widely accepted now, but that doesn't make it right.
  • Yeah, there's also this:

    A more recent issue came about when Pixelfed’s creator, Daniel Supernault made the details of a vulnerability public before server operators had a chance to update, which would have left the fediverse vulnerable to bad actors, she says. (Supernault has already apologized publicly for his handling of the issue that had affected private accounts.)

    In the case of the Pixelfed issue, for instance, the Hachyderm Mastodon server, which has over 9,500 members, decided it needed to defederate (or disconnect from) other Pixelfed servers that hadn’t been updated in order to protect their users.

    It is weird to spend almost half the words in this, pretending that something in Pixelfed that wasn't a problem on Pixelfed's side was. This is the weirdest "vulnerability" in the world to pick if you want to pick one to hold up extensively as an example.

  • Also Lemmy: Here's a bunch of death threats and pictures of a pig taking a shit because you said democracy was a good idea

  • Yeah. That's one thing I think Piefed is really doing right. They're trying to make it so that normal people will have a fairly pleasant normal-person experience.

    I think Lemmy's core developers including explicit acceptance for toxic online behavior, and some of the original core instances openly celebrating and modeling it, really may ruin the platform for the long term. And yes, you and dubvee are completely right as far as the lack of action in any respect by a lot of people who run the instances to do all that much of substance about the people who seem to want to ruin the experience on those instances.

  • “It’s inappropriate.”

    "To pray?”

    “There’s an appropriate time.”

    “It is the appropriate time.”

    “No, you have to listen to your authorities, which is your pastor.”

    Jesus Christ.

  • I got onto a video chat with a friend-of-a-friend who was not from the US.

    The instant I took the phone and we saw each other for the first time, he scoffed and said “Big fake American smile.”

    It was 100% true. I had a big dopey bullshit “meeting people” smile on. That’s not common in other countries.

  • That's why I say it is bullying.

    He does post trainwreck statuses sometimes, or miss self-imposed deadlines, or something. That's very very different from "incompetent for implementing badly something easy or toxic for federating ignoring what the federation requires" but it gives people a grain of truth to fall back on when the total bullshit they're accusing him of gets called out.

    Some for JordanLund, same for FlyingSquid. People are imperfect. It's okay. If your habit is to use people's imperfections as a reason to make wild accusations at them that have no basis in reality and double down on the legitimate criticisms and pick at them, and generally just be shitty to them, then there is a perfect word for that activity.

  • Yeah. Also, even with the best material and military forces in the world at your disposal, you can still completely fuck it up. The history of war is absolutely filled with empires who had all the advantages and still got clowned on because the leadership just made dumb decisions. And if your MO is similar to Trump’s or Putin’s, none of your trickery works anymore once you get outside of your own little corrupt orbit and have to cope with reality and skilled committed adversaries.

    I dug up the actual article, because it says it better than I can: https://snyder.substack.com/p/the-weak-strongman

  • I think you are overestimating both of their ability to execute.

    I’m not saying there is not an enormous danger on the horizon depending on what happens. But as long as Trump stays in charge, maybe even as long as Musk stays in charge, their ability to do real damage will be limited somewhat by their incompetence and their many personal failings. The American system is so corrupt at this point that people can take control of vast elements of the output and power of the system even if they couldn’t pour water out of a boot. But that doesn’t always carry over to their ability to influence things outside of their little weakened environment. Tim Snyder wrote about it in “The Weak Strongman.”

  • Ha, all good. Glad it worked out, let me know anything else I can do.

  • Done.

    Also, I can see the posts on lemm.ee. I think you might have a user setting configured to not show you bot posts. What's it say under Settings -> Show Bot Accounts?

  • Trump Watch @lemm.ee

    Trump Targets WilmerHale, Citing Law Firm’s Connection to Robert Mueller

    www.nytimes.com /2025/03/27/us/politics/trump-wilmerhale-law-firm-mueller.html
  • World News @quokk.au

    Renewables surged in 2024 — but so did fossil fuels

    grist.org /climate-energy/renewables-surged-2024-iea-nuclear/
  • World News @quokk.au

    France announces $2 billion military aid package for Ukraine

    kyivindependent.com /france-announces-2-billion-military-aid-package-for-ukraine
  • Trump Watch @lemm.ee

    Trump Administration Considers Money for Pardoned Jan. 6 Rioters

    www.nytimes.com /2025/03/26/us/politics/trumo-jan6-rioters-compensation.html
  • Trump Watch @lemm.ee

    FCC’s Carr Openly Admits He’ll Block Mergers Of Companies That Refuse To Kiss Trump Ass

    www.techdirt.com /2025/03/26/fccs-carr-openly-admits-hell-block-mergers-of-companies-that-refuse-to-kiss-trump-ass/
  • Trump Watch @lemm.ee

    Trump ally seeks to topple pipeline safety enforcement

    www.eenews.net /articles/trump-ally-seeks-to-topple-pipeline-safety-enforcement/
  • World News @quokk.au

    Ukraine’s Security Service detains two Russian agents who planned to plant bomb near military enlistment office

    www.pravda.com.ua /eng/news/2025/03/26/7504621/
  • World News @quokk.au

    Moscow sets far-reaching conditions for implementing US-brokered Black Sea ceasefire

    www.cnn.com /2025/03/25/europe/russia-us-ukraine-deal-intl-hnk/index.html
  • Trump Watch @lemm.ee

    Trump administration moves to shutter mine safety offices in coal country

    grist.org /accountability/trump-administration-moves-to-shutter-mine-safety-offices-in-coal-country/
  • Books @lemmy.ml

    Ray Nayler's "Where the Axe Is Buried" is an intense, claustrophobic novel of a world run by "rational" AIs that purport to solve all of our political problems with empirical, neutral mathematics

    pluralistic.net /2025/03/20/birchpunk/
  • Actually Infuriating @lemmy.world

    Stephen Miller doing quite a good imitation of a Lemmy troll, on CNN

    www.thedailybeast.com /cnn-host-brianna-keilar-asks-fuming-trump-aide-stephen-miller-to-calm-down-in-live-interview/
  • Not The Onion @lemmy.world

    Vance says Zelensky is 'badmouthing' Trump, calls it counterproductive

    kyivindependent.com /vance-says-zelensky-badmouthing-trump-calls-it-counterproductive/
  • Offbeat @lemmy.ca

    Couples Exchange Bacteria During Intercourse. It Might Help Track Down Sexual Assault Perpetrators.

    www.smithsonianmag.com /smart-news/couples-exchange-bacteria-during-intercourse-known-as-the-sexome-it-might-help-track-down-sexual-assault-perpetrators-180986068/
  • Actually Infuriating @lemmy.world

    Trump Considers Paving Grass at White House Rose Garden to Match Mar-a-Lago

    www.nytimes.com /2025/02/14/us/politics/mar-a-lago-trump-grass-rose-garden.html
  • Fediverse @lemmy.world

    Is there some type of "unfinished business" community?

  • Actually Infuriating @lemmy.world

    Russians refuse selling insulin and other vital medicines to Ukrainians in occupied territories, reports Ukrainian intelligence

    www.pravda.com.ua /eng/news/2025/02/7/7497200/
  • Not The Onion @lemmy.world

    Workers at NASA Told to ‘Drop Everything’ to Scrub Mentions of Indigenous People, Women from Its Websites

    www.404media.co /nasa-dei-drop-everything-executive-order/
  • cats @lemmy.world

    Louis enjoys his morning kayaking

  • Leopards Ate My Face @lemm.ee

    "Uncommitted" co-founder Abbas Alawieh, visibly upset that Mike Huckabee is about to be in charge, says "You've got to do something about this, President Biden!"

    x.com /atrupar/status/1856786479793766549
  • Fediverse @lemmy.world