Toot

Written by Tilde Lowengrimm on 2025-01-31 at 15:57

@TheGymNerd @dansup @pixelfed @shnoorg "You can just run your own server." should be all the illustration needed for why these two things are not equivalent. But alas, that does not actually solve the issue. Even if you're using your own server, any channels hosted on other servers are vulnerable to those servers' manipulation. You need to rely on every server you have channels on. And if you don't have conversations on other servers, well, now it's just worse than Signal and you have to host it yourself, still no federation.

That issue I pointed out is not only so much worse than you characterize, but fundamentally indicative of poor development practices which produce many more problems which the developers are not well-suited to detect. Read the whole article. Which is why I'm not pointing at that issue as an active unfixed vulnerability, but as a "code smell" indicative of deeper and more pervasive issues.

=> More informations about this toot | View the thread | More toots from tilde@infosec.town

Mentions

=> View dansup@mastodon.social profile | View PixelFed@pixelfed.social profile | View TheGymNerd@mastodon.social profile | View shnoorg@infosec.exchange profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113923788489450275
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
236.369297 milliseconds
Gemini-to-HTML Time
0.618411 milliseconds

This content has been proxied by September (3851b).