36
submitted 2 years ago by KinNectar@kbin.run to c/fediverse@lemmy.world

Hey all, I'm fairly new to the Fediverse.

I'm just wondering what is preventing mallard from being shared on Lemmy, K.Bin, etc. via images or other embeds? Is there some file vetting happening under the hood?

all 17 comments
sorted by: hot top controversial new old
[-] bernieecclestoned@sh.itjust.works 48 points 2 years ago

Duck sharing is prohibited

[-] 9point6@lemmy.world 26 points 2 years ago
[-] kakes@sh.itjust.works 10 points 2 years ago

We've been infiltrated.

[-] SatanicNotMessianic@lemmy.ml 15 points 2 years ago

Lemmy is actually full of quack addicts.

[-] Karlos_Cantana@sopuli.xyz 6 points 2 years ago

Phew! That's a load off my mind. I've been worried about that for a long time.

[-] Blaze@discuss.tchncs.de 14 points 2 years ago

Welcome,

There were issues a while back, which were fixed in security patches.

[-] CorrodedCranium@leminal.space 9 points 2 years ago

Wasn't work done not too long ago with emojis or something?

[-] ram@bookwormstory.social 3 points 2 years ago

Custom emoji was one, and another one in July(?) was in sidebars not being sanitized

[-] CorrodedCranium@leminal.space 1 points 2 years ago

What do you mean by sanitized?

[-] ram@bookwormstory.social 2 points 2 years ago

Stripped of executable code. IIRC the issue in particular was that sidebars observed HTML and you could put an iframe with potentially malicious code into them.

[-] CorrodedCranium@leminal.space 2 points 2 years ago

Interesting. Once the development of Lemmy slows down a couple years from now it would be interesting to see a video detailing the hiccups around its growth

[-] Carighan@lemmy.world 9 points 2 years ago

Yes, all your mallards should be thoroughly vetted.

[-] Synthead@lemmy.world 8 points 2 years ago

Hopefully you're not using an image reader that's shitty enough to have vulnerabilities like this 🤨

[-] KinNectar@kbin.run 3 points 2 years ago
[-] Synthead@lemmy.world 5 points 2 years ago

I wouldn't worry about Chrome having vulnerabilities in its image readers.

[-] llii@feddit.de 1 points 2 years ago

I would say that a zero-day for chrome would be far too valuable. Except you're the target of an entity that has a few millions to spare.

this post was submitted on 18 Oct 2023
36 points (100.0% liked)

Fediverse

35425 readers
822 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)

founded 2 years ago
MODERATORS