Notices by nya~ (neganeko@ryona.agency)
-
@mint @sysrq disoriented? nah refreshed
we're supposed to wake up whenever it is that we're done sleeping. society is what's at fault here
-
@mint @PeterTWeyand @hedoesitforfree lmao yeah that's the one. doesn't come up at all when I account search "weyand" never underestimate the difficulty of arbitrary substring search (does pleroma not bother to maintain something like a trigram index?)
-
@BlinkRape @LukeAlmighty @matrix @fyw321 A770 seems to be the only reasonable price to get 16 GB right now :senko_sigh:
-
@mint @neko :laugh: what is even going on here
> used exec to get better error messages
the fuck
I guess the only redeeming detail is that hopefully CAs are trustworthy so hopefully none of them would take advantage of this RCE vuln so hopefully no actual exploits happened in practice
... or HiCA sold an exploit service. who knows
screenshot_2023-06-25_acmesh_hi…
screenshot_2023-06-25_acmesh_ex…
-
@mint of course you don't even necessarily need that level of sophistication if you grabbed a user's token. you could literally send it in a DM and then attempt to clean up the DM a few seconds later. might not manage to clean it up in time tho
-
@mint I'm unclear about a few things. XSS or do the nostr lookups go via the local fedi server? because (I think) you could exfiltrate info via the search endpoint and also via /accounts/lookup?acct= with a procgen script on the other side to avoid a bunch of fetch errors in the logs
poast already uses an entirely separate subdomain for media so was there a CSP misconfiguration or ... ?
-
@lamp :doge_laugh:
@mint trying to open that page DoS's my browser
screenshot_2023-05-04_fedi-bloc…
-
@hedoesitforfree @mint which handle would that be? can't seem to find it on baest (might just be a tard tho)
-
guy talking shit about someone for not being sufficiently principled regarding freedom of speech. when he defederated all my accounts because he personally dislikes me :hanksmoking:
https://freespeechextremist.com/objects/393aeaf0-b354-48b7-9653-2e52b766f910
-
@mint @get it seems to be fast enough when it works. my beef with it is reliability. no indication to me (the end user) that a message hasn't been delivered to one of the tagged recipients (well their instance, anyway) yet. spotty backfill (that's being generous) when an instance does go down for a while
nya~
- Tags
-
- ActivityPub
- Remote Profile
Statistics
- User ID
- 23239
- Member since
- 14 Apr 2023
- Notices
- 10
- Daily average
- 0