Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. For @ifin folks, I started a discussion about this on the Discourse here: https://discourse.ifin.network/t/carrot-disclosure-forgejo/

For @ifin folks, I started a discussion about this on the Discourse here: https://discourse.ifin.network/t/carrot-disclosure-forgejo/

Scheduled Pinned Locked Moved Uncategorized
7 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • cxiao@infosec.exchangeC This user is from outside of this forum
    cxiao@infosec.exchangeC This user is from outside of this forum
    cxiao@infosec.exchange
    wrote last edited by
    #1

    RE: https://infosec.exchange/@jvoisin/116488420408417722

    For @ifin folks, I started a discussion about this on the Discourse here: https://discourse.ifin.network/t/carrot-disclosure-forgejo/

    My personal thought is that I appreciate, as a defender, knowing this information about a project having a systematic lack of security.

    oilheap@infosec.exchangeO 1 Reply Last reply
    0
    • cxiao@infosec.exchangeC cxiao@infosec.exchange

      RE: https://infosec.exchange/@jvoisin/116488420408417722

      For @ifin folks, I started a discussion about this on the Discourse here: https://discourse.ifin.network/t/carrot-disclosure-forgejo/

      My personal thought is that I appreciate, as a defender, knowing this information about a project having a systematic lack of security.

      oilheap@infosec.exchangeO This user is from outside of this forum
      oilheap@infosec.exchangeO This user is from outside of this forum
      oilheap@infosec.exchange
      wrote last edited by
      #2

      @cxiao @ifin "carrot disclosure" wtf. This is not the most stupid thing I've seen this week, but it's up there. This helps nobody and only inflates the ego of the researcher. The fact that they considered "sellability" of these issues already gives enough insight.

      kouhai@social.treehouse.systemsK 1 Reply Last reply
      0
      • oilheap@infosec.exchangeO oilheap@infosec.exchange

        @cxiao @ifin "carrot disclosure" wtf. This is not the most stupid thing I've seen this week, but it's up there. This helps nobody and only inflates the ego of the researcher. The fact that they considered "sellability" of these issues already gives enough insight.

        kouhai@social.treehouse.systemsK This user is from outside of this forum
        kouhai@social.treehouse.systemsK This user is from outside of this forum
        kouhai@social.treehouse.systems
        wrote last edited by
        #3

        @oilheap @cxiao @ifin for what it’s worth, we (treehouse staff and community) had a productive discussion with the author on discord; hopefully further updates will trickle out over the next days

        cxiao@infosec.exchangeC 1 Reply Last reply
        0
        • kouhai@social.treehouse.systemsK kouhai@social.treehouse.systems

          @oilheap @cxiao @ifin for what it’s worth, we (treehouse staff and community) had a productive discussion with the author on discord; hopefully further updates will trickle out over the next days

          cxiao@infosec.exchangeC This user is from outside of this forum
          cxiao@infosec.exchangeC This user is from outside of this forum
          cxiao@infosec.exchange
          wrote last edited by
          #4

          @kouhai @oilheap @ifin TY! I'm a little surprised by the extreme negative reactions to this TBH. From the perspective of being a Forgejo or other OSS maintainer it sucks to see this. But at the end of the day attackers don't care and aren't going to tell you in this way, or any way, that you have serious issues

          demize@unstable.systemsD kouhai@social.treehouse.systemsK oilheap@infosec.exchangeO 3 Replies Last reply
          0
          • cxiao@infosec.exchangeC cxiao@infosec.exchange

            @kouhai @oilheap @ifin TY! I'm a little surprised by the extreme negative reactions to this TBH. From the perspective of being a Forgejo or other OSS maintainer it sucks to see this. But at the end of the day attackers don't care and aren't going to tell you in this way, or any way, that you have serious issues

            demize@unstable.systemsD This user is from outside of this forum
            demize@unstable.systemsD This user is from outside of this forum
            demize@unstable.systems
            wrote last edited by
            #5

            @cxiao @kouhai I can understand the negative reaction; telling a well-respected and very open source project “you have serious issues but I’m not going to tell you what they actually are” without any attempt to actually flag the issues to them is… not great? it’s not like this is a company that can bring in someone to audit the code, it’s an open source project that would love to fix the issues but is resource constrained by virtue of being an open source project

            it’s an inherently aggressive approach to disclosure and it doesn’t come off as “helpful” nearly as much as “condescending”, and while that’s one thing to direct at a corporation…

            1 Reply Last reply
            1
            0
            • cxiao@infosec.exchangeC cxiao@infosec.exchange

              @kouhai @oilheap @ifin TY! I'm a little surprised by the extreme negative reactions to this TBH. From the perspective of being a Forgejo or other OSS maintainer it sucks to see this. But at the end of the day attackers don't care and aren't going to tell you in this way, or any way, that you have serious issues

              kouhai@social.treehouse.systemsK This user is from outside of this forum
              kouhai@social.treehouse.systemsK This user is from outside of this forum
              kouhai@social.treehouse.systems
              wrote last edited by
              #6

              @cxiao @oilheap @ifin one of the objections I’ve seen is “carrot disclosure doesn’t work when you’re punching downwards or sideways”/ “what additional resources can a volunteer-based project apply?”

              (not focusing on the other objections, because I don’t want to retread the productive discussion from earlier)

              1 Reply Last reply
              0
              • cxiao@infosec.exchangeC cxiao@infosec.exchange

                @kouhai @oilheap @ifin TY! I'm a little surprised by the extreme negative reactions to this TBH. From the perspective of being a Forgejo or other OSS maintainer it sucks to see this. But at the end of the day attackers don't care and aren't going to tell you in this way, or any way, that you have serious issues

                oilheap@infosec.exchangeO This user is from outside of this forum
                oilheap@infosec.exchangeO This user is from outside of this forum
                oilheap@infosec.exchange
                wrote last edited by
                #7

                @cxiao @kouhai @ifin oh, so this is not a researcher but a malicious party? Then we should prosecute them!

                1 Reply Last reply
                0
                • R relay@relay.infosec.exchange shared this topic
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups