https://bsky.app/profile/nih-llamas.bsky.social/post/3komzcim76p26

  • PorkrollPosadist [he/him, they/them]M
    ·
    edit-2
    9 months ago

    There have been several VERY NASTY CVEs since I set up matapacos in 2022.

    Remote code execution: https://github.com/mastodon/mastodon/security/advisories/GHSA-9928-3cp5-93fm A.K.A. "Toot Root"

    Hijacking user accounts: https://github.com/mastodon/mastodon/security/advisories/GHSA-3fjr-858r-92rw

    Among others (there was at least one more really bad one)

      • InevitableSwing [none/use name]
        hexagon
        ·
        9 months ago

        I want to go on record that if Trump suddenly says "I AM YOUR LORD AND SAVIOR OUR BIG WET BOY!" - I had nothing to do with it.

    • ProletarianDictator [none/use name]
      ·
      9 months ago

      you run matapacos? I've been meaning to join, but haven't bc of the email address requirement. Is there a way around that?

      • IMF_DOOM [she/her]
        ·
        9 months ago

        You can just use a disposable email address like I did for my account

        • PorkrollPosadist [he/him, they/them]M
          ·
          edit-2
          9 months ago

          Yeah. Email is baked into the software so a throwaway is needed for technical reasons, but only for registration and password recovery. I don't have any e-mail services blocked. You are encouraged to use a throwaway e-mail service unless you want password recovery and (optional) email notifications to work.

          Recently we added manual account activation due to a spam wave. You don't have to write an essay outlining your ideological beliefs or anything. It is strictly an anti-bot measure.