6 ms·
Solution is also on the works like use /.well-known/, so this is more like funny, rather than a big problem. Key to trick was to have bucket named "xrpc" and s
by Ciantic 3y ago
Solution is also on the works like use /.well-known/, so this is more like funny, rather than a big problem.
Key to trick was to have bucket named "xrpc" and store a file there: https://s3.amazonaws.com/xrpc/com.atproto.identity.resolveHandle https://s3.amazonaws.com/xrpc/com.atproto.identity.resolveHa...
There is also another funny thing in the image, the user posting about is sending one from "retr0-id.translate.goog", which is odd. Somehow he has got https://retr0-id.translate.goog/xrpc/com.atproto.identity.resolveHandle https://retr0-id.translate.goog/xrpc/com.atproto.identity.re... to redirect to his page, and gotten that handle as well.
- matoro 3y agoGoogle Translate recently moved translated web pages to domains like this. If you plug a webpage into GT it will put the translated content under <domain>-<tld>.translate.goog. This user's actual domain is https://retr0.id https://retr0.id
- dbmnt 3y agoOof. This will not be the last time that decision causes a problem.
- chrismorgan 3y agoEh, it’s worse than just funny; it’s concerning, because they should have known about and easily avoided this kind of vulnerability, it’s standard stuff you have to think about. So what else have they missed?
- steveklabnik 3y agoThis is a private beta. Nobody is suggesting that any of this be used for anything serious just yet. Development happens out in the open, you can go find out what else they've missed by doing the work, or by waiting until others you trust have done so. I myself have had an account for like a month now, but only started really using it a week ago, because that calculus changed for me, personally. Like, it's not even possible to truly delete posts at the moment. This all needs to be treated as a playground until things mature. This isn't even the first "scandal" related to this feature already!!!! There is another hole in what currently exists that allowed someone to temporarily impersonate a Japanese magazine a few weeks back.
- YtvwlD 3y agoOkay, yes, but this indicates that they didn't read the ActivityPub before developing their own new shiny protocol.
- steveklabnik 3y agoI don't personally believe that one mistake indicates ignorance of an entire topic.
- seba_dos1 3y agoIn general - no, but this kind of fundamental mistake might.
- steveklabnik 3y agoI hope I never work on software you folks use. The grand claims about something that is not even hard to fix is just wild to me.
- gowld 3y agoWhat about the next 500 easy-to-fix bugs? Is there a public test suite?
- steveklabnik 3y ago> Is there a public test suite? The entire specification (which is admittedly incomplete) and implementation are open source. I am not aware of a dedicated test suite for alternative implementations. It's too early, IMHO. I personally would much prefer the team to focus their time elsewhere for the time being.
- ShroudedNight 3y agoMy instincts may be way off-base, but if I was developing a protocol at the core of my product vision, even if there was only one implementation, I would a want an authoritative test suite. I wouldn't trust myself not to integrate load-bearing idiosyncrasies (and bugs, honestly) otherwise.
- capableweb 3y agoWouldn't be funny if it was a public beta that they want people to use for serious stuff. But it's neither serious, a beta or public, but basically a private alpha for playing around, so i'd be a bit lenient on screwups.
- vidarh 3y agoFor me, the worst thing about it is that they didn't just use webfinger. So webfinger isn't perfect, but it's there and in use. When they choose to invent new mechanisms for things there are perfectly serviceable options for, it makes me instantly sceptical of the rest.
- bombcar 3y agoReminds me of people taking the username “admin” or “hostmaster” at a free email service and being able to get domain verification emails.
- btown 3y agoWait - nobody had ever created a bucket named xrpc before, ever? I would have imagined that short s3 buckets were squatted similar to domain names. (Or maybe they were, and it's this person who did so!)
- lyschoening 3y agoThere's an account bucket limit, so you'd need to create a huge number of AWS accounts with no immediate benefit.