I came across this blogpost regarding Mastodon. I would love to get you guys thoughts. This is from earlier in the year, the authors thoughts may have changed but not likely. Some points make sense others not so much.

  • JoYo 🇺🇸
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    1 year ago

    It’s only a matter of time until there will be a CVE found in the official Mastodon software which will leave a vast majority of instances vulnerable.

    PoC or shut your fucking face.

    • wander1236@sh.itjust.works
      link
      fedilink
      arrow-up
      4
      ·
      1 year ago

      The cool thing about software is that it can be updated, so if someone finds a vulnerability and follows the proper CVE disclosure process, instance admins can just update immediately when it’s disclosed.

      I guess it’s a little trickier because open source software can’t really say “fix a vulnerability that hasn’t been disclosed yet” in a commit message without disclosing the bug, and instances can’t just be silently updated before disclosure, but I’m sure there are other ways to handle CVEs that don’t rely on information obfuscation.