:mima_rule: Mima-sama<p><a href="https://makai.chaotic.ninja/tags/Sharkey" rel="nofollow noopener" target="_blank">#Sharkey</a><span>'s recent vulnerability and their handling of it is still miles better than </span><a href="https://makai.chaotic.ninja/tags/Lemmy" rel="nofollow noopener" target="_blank">#Lemmy</a><span>'s </span><a href="https://makai.chaotic.ninja/tags/XSS" rel="nofollow noopener" target="_blank">#XSS</a><span> exploit which actually took down a big instance and is something even more elementary than what Sharkey experienced.<br><br>Like seriously, the first thing you do when </span><a href="https://makai.chaotic.ninja/tags/Markdown" rel="nofollow noopener" target="_blank">#Markdown</a><span> parsing is involved is to sanitize the hell out of it, both in the Markdown input and the HTML output. And you put up a strict </span><a href="https://makai.chaotic.ninja/tags/CSP" rel="nofollow noopener" target="_blank">#CSP</a><span> for good measure. Lemmy spectacularly failed on both counts, despite existing as a project for </span><i><span>years</span></i><span> and a lot more instances (and therefore users, which rivals </span><a href="https://makai.chaotic.ninja/tags/Mastodon" rel="nofollow noopener" target="_blank">#Mastodon</a><span>) using their software!<br><br>I can cut some slack for the Sharkey devs here because:<br><br>- they're relatively new (only months since the project started)<br>- it only affected </span><i><span>note imports</span></i><span> from </span><a href="https://makai.chaotic.ninja/tags/Twitter" rel="nofollow noopener" target="_blank">#Twitter</a><span> which is already niche enough<br>- it was easy to mitigate (just disable note import)<br>- it didn't affect single-user instances IIUC<br>- I haven't seen any Sharkey instance get actually exploited by this<br>- they're taking steps to make sure this shit doesn't happen again (haven't seen this from Lemmy yet, and last I checked their CSP is still shit)<br><br>So this is not worth blowing over in the </span><a href="https://makai.chaotic.ninja/tags/fediverse" rel="nofollow noopener" target="_blank">#fediverse</a><span>. Your assessment is exaggerated, this energy could've been spent somewhere else, and you owe the Sharkey devs an apology.<br><br></span><a href="https://makai.chaotic.ninja/tags/fediversemeta" rel="nofollow noopener" target="_blank">#fediversemeta</a><span> </span><a href="https://makai.chaotic.ninja/tags/security" rel="nofollow noopener" target="_blank">#security</a><span><br><br>RE: </span><a href="https://meowcity.club/fedi/tetra/p/1706812792.496325" rel="nofollow noopener" target="_blank">https://meowcity.club/fedi/tetra/p/1706812792.496325</a></p>