对胡萝卜披露的后续:Forgejo
Follow-up to Carrot disclosure: Forgejo

原始链接: https://dustri.org/b/follow-up-to-carrot-disclosure-forgejo.html

Forgejo 漏洞披露(“Carrot disclosure”)发布后,作者在 Mastodon/信息安全社区遭受了强烈反弹和争论。最初的帖子因对负责任披露的意见不一,在多个 Mastodon 实例上被反复删除,引发了关于漏洞处理的更广泛讨论。 作者个人受到负面评论的攻击,其披露策略受到了安全专业人士和担心吸引注意力到易受攻击目标的用户的批评。有趣的是,荷兰随后启动了一个主权 Forgejo 实例。 最终,作者向 Forgejo 安全团队发送了一封综合性邮件,包括道歉、其方法背后的理由、加固建议和概念验证漏洞利用。主要目标——改变 Forgejo 安全态度的认知——似乎已部分实现,尽管非常规的披露方法仍然存在争议。

Hacker News 新闻 | 过去 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 关于 Carrot 披露的后续:Forgejo (dustri.org) 4 点 由 homebrewer 40 分钟前 | 隐藏 | 过去 | 收藏 | 2 条评论 帮助 bombcar 1 分钟前 | 下一个 [–] 这是典型的恶搞行为的回应。回复 homebrewer homebrewer 40 分钟前 | 上一个 [–] 之前:https://news.ycombinator.com/item?id=47941590 回复 考虑申请 YC 2026 夏季批次!申请截止至 5 月 4 日 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系方式 搜索:
相关文章

原文

Since I published Carrot disclosure: Forgejo two days ago, numerous things happened:

  • Friends of mine were reached out to, to "talk to me from a place of trust", or simply to tell them what an horrible person I am, which they found hilarious.
  • The toot linking to the blogpost was removed from infosec.exchange by an overzealous moderator after it had been reported multiple times by multiple people. I thus moved to mastodon.social, where it was also removed with "Irresponsible disclosure" given as a reason. So I moved back to infosec.exchange, where the toot was restored. In the meantime, friends handed me invitations for various mastodon instances, which I'm grateful for.
  • Numerous instances of the eternal vulnerabilities disclosure debate spawned.
  • Some exploit-writer friends of mine complained that I brought unwanted attention to an easy target.
  • The Netherlands deployed a sovereign software forge in the form of a public forgejo instance.
  • Everyone had an opinion on mastodon on this, especially on what I should do with the vulnerabilities I found, and was really vocal about it. I also got called a handful vile names.
  • Forgejo's security policy was copiously made fun of.
  • I got a tone deaf email from Forgero's moderation team, to my arguably tone-deaf blog post, which I think is funny.
  • I've learnt that the role of Forgejo security team is to "take care of security vulnerabilities and to handle sensitive security-related issues reported to [email protected] using encryption." Doing anything proactive isn't in their attributions.
  • Various entities, including some with security teams, revised their judgment about what Forgejo is and isn't, which was the main goal of the previous blogpost.

Nonetheless, some productive good faith conversations have been had as well, and it seems that experimenting with odd vulnerability disclosure schemes is frowned upon. So I ended up sending and email to Forgejo security team, containing: an apology, a bit about my reasoning for proceeding with carrot disclosure, recommendations about what to harden/review, and a bunch of commented exploits/proof-of-concepts as attachment. We'll see how it goes.

联系我们 contact @ memedata.com