north,

Fuck it. #YOLO

#Bluesky continues to be entirely non-responsive to the numerous security vulnerabilities I've reported to them, so I spent the evening writing up a nice README and a framework with exploit modules, and just made it all public.

Have fun.

https://github.com/qwell/bsky-exploits

#infosec #security

north,

Paul Frazee, a developer at Bluesky, has publicly responded to somebody about this issue (...they still have not contacted me, however).

I could not disagree more, but there you have it.

proactiveservices,
@proactiveservices@fosstodon.org avatar

@north Similar priorities as Yahoo! then.

stux,
@stux@mstdn.social avatar

@north Wow.

That's such a "great" response from a social media dev you never wanna hear :nkoFacepalm2:

Andres,
@Andres@mastodon.hardcoredevs.com avatar

@stux @north
The priority is the ultra critical security vulnerabilities \s

stux,
@stux@mstdn.social avatar

@Andres @north Ofc! but how many do they have? :amaze:

If this is not "prio enough" i don't wanna know how many more worse things are open right now

Andres,
@Andres@mastodon.hardcoredevs.com avatar

@stux @north
Come on! they will never disclose how many ultra critical priorities BlueSky has, but the full team is working on mitigations around the clock \j

stux,
@stux@mstdn.social avatar

@Andres @north :blobcatgiggle: i certainlly hope not indeed! haha!

It's more about the reply that was not needed in such a way and prompt reponses like mine :ablobwink:

Take mine with a grain of salt but certainly more people will start to think it, if they just had said "working on it" or "added" it was done :blobcatgiggle:

Andres,
@Andres@mastodon.hardcoredevs.com avatar

@stux @north
True true!

north,

@stux @Andres The dismissive response isn't great, but if they had ever responded to me by saying "we don't think this is important", it would have opened the opportunity to explain the ways it could be abused, that they weren't considering.

What bothers me most is the lack of response. It shuts down any possibility of that explanation and gives the impression that it's your efforts that are what isn't important to them.

As to the question of worse issues existing - I can confidently say yes.

podkaynelives,

@north This sounds like an invitation to mayhem 😎

darkuncle,

@north the only way that could be true is if there are so few people on bsky or relying on it for info, that the impact of disinfo is negligible. So … maybe?

neilcar,

@north Taking care of security researchers pays dividends. NOT taking care of security researchers can be pretty damaging.

jhwgh1968,
@jhwgh1968@chaos.social avatar

@neilcar exactly

Another example of why everyone with even modestly sized pockets (by corp standards) should run a bug bounty program

I wonder what @north would have gotten paid for this one...

north,

@jhwgh1968 @neilcar I actually inquired whether they had one (they obviously don't) and suggested that they consider it.

The creation of bug bounties has made a huge impact on the amount of abuse that vulns see. If it's worth more for somebody that would have otherwise used/sold a vuln to instead report it, that's an easy win for all parties.

I quoted Neil's comment here to some friends, because they absolutely nailed it, and said it so succinctly.

Edent,
@Edent@mastodon.social avatar

@north Ha! I reported the exact same thing to Twitter 4 years ago.
https://shkspr.mobi/blog/2019/03/scammers-abusing-twitter-cards-via-redirects/
Wankers.

north,

@Edent Nice!
That attack is actually kinda clever.

On Bluesky, they don't even bother sending a request to the site -- they just let you tell them what it says.

Edent,
@Edent@mastodon.social avatar

@north
FFS!

jbzfn,
@jbzfn@mastodon.social avatar

@Edent @north from what I expect from those accelerationists, it sounds like a feature not a bug.

SinclairSpeccy,

@north Kinda funny to think that one of the people who hates me uses BlueSky… I could mess with them if I really wanted to :P

kevinteljeur,
@kevinteljeur@mastodon.online avatar

@north I said this before but they have very few developers, and get pulled between ‘nice to have’ user features, user safety, and security. The whole thing is years away from being ready for the public at any scale. This is another good example of it.

kevinteljeur,
@kevinteljeur@mastodon.online avatar

@north This isn't an implied criticism of you, by the way, because it is a clear flaw, and not even a criticism of the developers either, because I think that if they're even halfway professional, then their priority is probably big stuff that we don't know about (which could be quite bad). They just shouldn't have launched yet.

shreyan,

@north You.. are wrong.

jonny,
@jonny@neuromatch.social avatar

@north
Omfg I found the link card one too and didnt even bother reporting it because they also didn't respond to my raising alarms about abuse potential in their tagging and feed building systems. Total security trainwreck - their federation sandbox actively prohibits redteaming which is fuckin preposterous

Ulrich_the_Elder,
@Ulrich_the_Elder@mastodon.social avatar

@north If you are engaging with any of the nazi social media sites I will block you. Please confirm you engage with bluesky. Thanks.

tavi,

@Ulrich_the_Elder @north calling bluesky a nazi site is a bit nuts. the people on there are mostly good. Lots of furries and queer people

Ulrich_the_Elder,
@Ulrich_the_Elder@mastodon.social avatar

@tavi @north how about if the owner of the site is a nazi?

takelgryph,

@Ulrich_the_Elder @tavi @north apparently jack deleted his bluesky account yesterday -- pretty sure he doesn't care about bluesky anymore and prefers to hang out with the other coinfuckers on nostr

vitriolix,
@vitriolix@mastodon.social avatar

@takelgryph @Ulrich_the_Elder @tavi @north do you have a source for that? big if true

takelgryph,
north,

Fun bonus fact: There are two little secrets hiding in plain sight on that screenshot.

  1. There are RTL character shenanigans that cause my name to wrap around my handle.

  2. My handle is literally not valid. It's technically @https.s3.aws.amazon.com (😏), but they changed it in part of the system to @handle.invalid, which makes the site put in that nice ugly "⚠️Invalid Handle" text.

realhackhistory,
@realhackhistory@chaos.social avatar

@north how do the rtl characters create that effect? I’ve been playing around with the profile fields and can’t replicate.

north,

@realhackhistory I set it months ago, and I don't remember which specific RTL character I used, but IIRC is was something in the realm of:

<RTL>Jason Parker<SPACE><RTL>@ဪ.com

(I don't think the ဪ matters, but it might. I used it because I own ဪ.com and it's hilarious.)

You could probably just copy the string from the element. Editing is a bit weird since stuff will shift on you as you move the cursor.

realhackhistory,
@realhackhistory@chaos.social avatar

@north I noticed that last part haha, thanks!

bryansmart,

@north @HNguyenLy Noiiice! Nothing draws attention to a problem better than making it a bigger problem.

BigMcLargeHuge,

@north

Thanks for making it public. Their lack of action is typical because who gives a shit about the customers after the bill is paid.

stux,
@stux@mstdn.social avatar

@north Haha you did it :blobcathighfive: :blobcathearts:

Ah well, you tried mate! At some point they gotta learn the hard way

BigMcLargeHuge,

deleted_by_author

  • Loading...
  • Archnemysis,
    @Archnemysis@mastodon.social avatar

    @BigMcLargeHuge @stux @north That is not true! Here, have 6 months of free credit monitoring so you know how much we care.

    BigMcLargeHuge,

    @Archnemysis @stux @north

    Sweet.. I should be able to change my date of birth in less than 90 days.

    EAT THAT, HACKERS!

    kkarhan,

    @north olease let me know.if they start so others can spare the time and effort to contact them and just sell the code to and other buyers...

  • All
  • Subscribed
  • Moderated
  • Favorites
  • bluesky
  • DreamBathrooms
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • GTA5RPClips
  • JUstTest
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • megavids
  • lostlight
  • All magazines