the los angeles metro 2040 plan is a beautiful vision of a future that we can have, if we build it
@sungo @rabcyr I just ran the ImageTragick PoC test suite from https://github.com/ImageTragick/PoCs on the toot-lab server, reports safe:
sundog@toot-lab:~/repos/PoCs$ ./test.sh
testing read
SAFE
testing delete
SAFE
testing http with local port: 33517
SAFE
testing http with nonce: a5de7659
SAFE
testing rce1
SAFE
testing rce2
SAFE
testing MSL
SAFE
I could use some extra eyes on some Masto code that is striking me as a security concern.
Look at https://www.dropbox.com/s/i0h8yg4z2oril0u/wtf.txt?dl=0 which is a log snippet
From what I can see, every time masto gets a file, incl profile images and headers from federated instances, it shells out to imagemagick to resize and convert it.
Part of that is here https://github.com/tootsuite/mastodon/blob/master/lib/paperclip/gif_transcoder.rb
Given https://imagetragick.com this seems ... bad
I'm a PhD student in Computational Social Science. Have been involved in/am interested in public policy, w/ background in defense and military issues. These days increasingly interested in computation and impact on society writ large.
Cyber-Clausewitz avi sort of mixture of "old" and "new" me even if both always interests I've had. I'll toot about mixture of natsec, tech, and cultural topics. And of course Harambe (RIP).
A good way to get the most mileage out of Mastodon is to continue to use other social media while tooting here, and seeing what features this place has you find you really miss off-site. Being able to default to "not public to the entire universe" for my posts was a godsend, as is stuff like the CW toggles and NSFW image blockeroo!
I have my list of Possible Changes but it's way, way less than certain other sites I could name.
I spent most of the day writing quasi-#introduction to mastodon - exploring how I relate to the platform and key details that I wish someone had shared with me.
https://medium.com/scat-sense/playing-with-hairy-elephants-ce338a2e41e3
Props to @b_cavello's and their artwork which helped give me hope this platform will be a great place to create - I've been lacking that on twitter for a few months now.
Thank you @Gargron helping give so many people hope back and introducing us to the fediverse.
“Obviously it’d be hard for me to pay the bills if literally everyone decided to use the mastodon.social instance only.” :joy: oops
https://medium.com/scat-sense/playing-with-hairy-elephants-ce338a2e41e3
https://anticapitalist.party/@b_cavello
activist, aspiring-polymath, problematic feminist working to better this world