PhilipTheBucket

joined 8 months ago
MODERATOR OF
[–] PhilipTheBucket@ponder.cat 1 points 1 week ago (1 children)

Zero Punctuation as usual gets to the heart of the matter very effectively: https://youtu.be/g4Dw0Z2Dsts

That’s for Shenmue 3. He actually made a separate video reviewing the original, but that one covers more of the history and context. TL;DR It has a devoted cult following of people who basically want a very specific type of gaming experience, but the specific game that was the first to give it to them just objectively is not very good at all as an interactive video game, which is why it has never been all that popular outside that little following. Some people trace to Shenmue the lineage of huge cinematic games that emphasize narrative, which I guess could be valid, but even a super-charitable reading shouldn’t put it anywhere near the coveted number 1 spot.

Oh, you know what happened? I just realized, I hadn’t even read the introductory material and realized it was from a public survey. It’s a “first past the post” problem. Plenty of people had various lists of games they felt passionate about (and you can tell where the boundary is where “I played this game recently and I love it now so it is my favorite” started to distort the placement of some recent games), but anyone who had Shenmue anywhere on their list put it as the number 1 spot. And so, it won by bad voting algorithm. I can almost guarantee that each respondent was only allowed a single choice for most influential game.

I actually think the list, with some exceptions, is remarkably accurate. It definitely isn’t perfect. There are also some big omissions, notably in old PC games that had a big influence or fleshed out new genres that have mutated since then, or gone extinct or something. I think they’re just outside of too many people’s memory at this point.

Off the top of my head:

  • Ultima or Dungeon Master
  • King’s Quest or Monkey Island
  • Civilization
  • Battlefield 1942
  • Halo or Goldeneye
  • Counterstrike
  • Warcraft 2
  • Zelda 1
[–] PhilipTheBucket@ponder.cat 1 points 1 week ago

Yeah. This is absolutely on purpose. What’s that hard-hitting documentary about the 2014 revolution called, it’s definitely “Ukraine on Fire” right?

[–] PhilipTheBucket@ponder.cat 1 points 1 week ago (6 children)
  1. GRAND THEFT AUTO
  2. THE ELDER SCROLLS V: SKYRIM
  3. GRAND THEFT AUTO III

Wow… okay, this is good. It is really rare to see one of these lists that is actually populated with extremely influential games. That’s a good choice of metric, too. Not which ones are “great” but which ones had a lasting impact on the landscape.

  1. WORLD OF WARCRAFT
  2. PONG

I wonder if it might be good to separate by decades or generations or something. These are both obviously ground-breakingly influential and belong on the list but it seems kind of senseless to try to “compare” them.

  1. HALF-LIFE 2

Okay that’s a little weird. We’re getting up into the real high-water heights here and I mean HL2 is good but…

  1. KINGDOM COME: DELIVERANCE 2

Guys? You okay? I haven’t played it but it seems unlikely that it needs to be above WoW and Dark Souls.

  1. MINECRAFT
  2. THE LEGEND OF ZELDA: OCARINA OF TIME
  3. HALF-LIFE

Okay, here we go. You guys found your stride again. These are legit choices yes.

  1. SHENMUE

THE FUCK WHY WHAT

[–] PhilipTheBucket@ponder.cat 2 points 1 week ago* (last edited 1 week ago)

Because it is transparently obvious that it's going to happen.

If you're sending your users' private statuses to an ActivityPub server, and just hoping that it's going to choose to keep them private according to certain parameters even though that's not what the spec stays it needs to do, then you're fucking up. The fact that we know that particular instances of particular software are exposing them is a nice demonstration of the harm, a confirmation that you're fucking up when you're doing that, but it's not really needed. It is the absolutely predictable result of some basic principles of security which, as a security researcher, you should absolutely be aware of.

I've repeatedly explained this. You've repeatedly explained your position. We've both had our say. You seem addicted to the concept of "winning" the conversation and wanting to just go back and forth. In that case I would really encourage you to state your position again, and I can state mine again, and we can both have fun doing that for a while. Want to? It sounds like a productive use of both of our time. It's fun, too.

Edit: Actually, I didn't even realize you are on fedia.io when I was typing this. You can test for yourself whether mbin does this, too, by coordinating with @Irelephant@lemm.ee. Follow his user, then have him post one of those private statuses, then fetch his user profile via fedia.io from an incognito window and see whether the private statuses show up. I have no idea whether they will, but if I had to guess, I would say it's better than even odds.

[–] PhilipTheBucket@ponder.cat 8 points 1 week ago (7 children)

https://news-pravda.com/ posts multiple stories every minute, as far as I can tell just at all times. Something like this seems fairly likely.

[–] PhilipTheBucket@ponder.cat 2 points 1 week ago (2 children)

Are you hoping to restart our disagreement through sheer passive-aggressiveness? Okay, sure.

In my view, this is a Mastodon design flaw (or a user-expectation issue or whatever you want to call it.) I already said that, and you're involved in the unproductive-arguer's pastime of pretending not to understand that that's my position, and just aggressively repeatedly reframing things according to your position and hoping I'll knuckle under to it through sheer force of repetition.

I'm not super invested in trying to track down each and every software that might manage to expose the "private" statuses in this way. I just know that as things come and go there are guaranteed to be some. If you have an mbin account and Mastodon account, though, we can try a little experiment. I don't know the outcome, I'm just curious after taking a quick look down the FediDB list and a quick grep through mbin's source code. You can be the one to responsibly disclose to mbin how their ActivityPub-conforming behavior is a problem, if indeed it turns out that it is, since you seem to be extremely committed to the idea that the model of "vulnerability" needs to be applied to this particular ActivityPub-conforming behavior. Since you're a security researcher, having that as a CVE you discovered can be an achievement for you. It's all yours, you can have it.

[–] PhilipTheBucket@ponder.cat 3 points 1 week ago (4 children)

Hm... maybe. The exact nature of the problem in Pixelfed means that anyone with a Pixelfed account on a server which is getting private statuses can choose to follow someone who's set to "approve followers" and then read all the private statuses. I do see how that's significantly worse than just the normal lay-of-the-land of the problem, which is a little more random, and laying that out as a little roadmap to read someone else's private statuses before there's been a nice responsible length of time for things to get fixed could be seen as worsening the problem.

The point that I'm making is that anyone who's posting private statuses to Mastodon and expecting them to stay private is making a bad mistake already. The structure of the protocol is such that they can't be assured of staying private regardless of what Pixelfed did or even if Pixelfed didn't exist. They're getting federated to servers whose behavior is not assured, in a way where a conformant ActivityPub implementation can expose them. People who are posting private statuses need to understand that.

That whole blog post where the person is talking about her partner writing private statuses, and then the gut-wrenching realization that they were being exposed on Pixelfed... but then the resolution being "Pixelfed fucked up I hate Dansup now" and then continuing to post the private statuses, is wrong. That person's partner needs to stop treating their private posts on Mastodon that way. The timer for responsible disclosure started circa 2017 or whenever Mastodon decided on how to implement their private statuses. It's been and gone.

Like I say, I get the harm-reduction aspect of saying it would have been better if Dansup was a little more discreet about this particularly bad attack vector until a few more days went by for everyone to upgrade. But it hardly matters. There are still server softwares our there that are going to be exposing people's private Mastodon posts. It's just how federation between untrusted servers works. Giving people the illusion that if Dan had just been more discreet then this harm would have been reduced is lulling them into a false sense of security, in my view.

[–] PhilipTheBucket@ponder.cat 4 points 1 week ago (1 children)

Maybe I’m wrong, but shouldn’t posts only be insecure if they’re propagated to the insecure instance?

"Insecure" in this case simply means any server that doesn't implement Mastodon's custom handling for "private" posts. With that definition, the answer to your question is yes. It has been mentioned by Mastodon people that this is a significant problem for the ability to actually keep these private posts private in the real world. The chance of it going wrong is small (depending on your follower count) but the potential for harm is very large. I would therefore go further, and say that it's a very bad thing that Mastodon is telling people that these posts are "private" when the mechanism which is supposed to keep them private is so unreliable.

https://marrus-sh.github.io/mastodon-info/everything-you-need-to-know-about-privacy-v1.3-020170427.html

https://github.com/mastodon/mastodon/issues/712

Is any private post visible to people on servers that the poster doesn’t have followers on?

It is not. If you're sufficiently careful with approving your followers, making sure that each of them is on an instance that's going to handle private posts the way you expect, then you're probably fine.

Could I curl the uri of a post thats “private” and get the post’s content?

If it's been federated to an insecure server then yes. If not then I think no.

[–] PhilipTheBucket@ponder.cat 2 points 1 week ago

Yeah, you said that stuff before and then you said it again. I do understand what your argument is here. I was trying a couple of different ways of explaining what I was saying in response, but it seems like it's not working. Oh well.

[–] PhilipTheBucket@ponder.cat 2 points 1 week ago* (last edited 1 week ago) (2 children)

I’ve said nothing about any spec violation. That’s not relevant.

It has everything to do with ActivityPub since if you follow that protocol strictly you will cause this behavior.

That's what I was going by. I guess I could re-read this now and interpret "this behavior" as Pixelfed's side, instead of Mastodon's side as I initially read it, and decide that you are agreeing with me that Mastodon's behavior was (and is) out of spec? Do I have that right?

It still doesn’t change that Dansup was told that this caused Bad Things™ and yet he didn’t follow normal procedure in how you handle it.

It is normal procedure to fix a bug when you are notified about it.

The design flaw in Mastodon that managed to bite Pixelfed in this situation still exists. People were writing about it back in 2017 when this was all being first implemented. The idea that "normal procedure" needs to include keeping it a secret that Mastodon's "private" statuses can be exposed by any server software that doesn't handle them in the way that's expected, is 100% wrong.

I'll rephrase what I said earlier: Since you're a security researcher, and you apparently think Dan should have played into the idea of keeping it a secret that Mastodon's private statuses are not secret by obfuscating the information about how he was fixing Pixelfed to more effectively hide them, you are bad at your job. In this instance. The fault lies with how private statuses are implemented, and nothing about that needs to be kept secret as would a normal vulnerability, during responsible disclosure. In fact, it is extremely harmful to let users believe that these privacy settings are anything other than vague recommendations, specifically because of the risk they will act accordingly and expose some of their private posts to the world. They should know exactly what's going on with it, and Dan accidentally failing to keep that a secret is in no way causing bad things.

[–] PhilipTheBucket@ponder.cat 3 points 1 week ago* (last edited 1 week ago)

It is to the person who discovers the vulnerability. That's fairly normal... how would giving it to someone else motivate the result they're trying to get?

[–] PhilipTheBucket@ponder.cat 4 points 1 week ago (4 children)

Okay. What part of the spec did Pixelfed violate? Where in the spec is Mastodon's implementation of private posts justified?

 

So check it out: Mastodon decided to implement follower-only posts for their users. All good. They did it in a way where they were still broadcasting those posts (described as "private") in a format that other servers could easily wind up erroneously showing them to random people. That's not ideal.

Probably the clearest explanation of the root of the problem is this:

Something you may not know about Mastodon's privacy settings is that they are recommendations, not demands. This means that it is up to each individual server whether or not it chooses to enforce them. For example, you may mark your post with unlisted, which indicates that servers shouldn't display the post on their global timelines, but servers which don't implement the unlisted privacy setting still can (and do).

Servers don't necessarily disregard Mastodon's privacy settings for malicious reasons. Mastodon's privacy settings aren't a part of the original OStatus protocol, and servers which don't run a recent version of the Mastodon software simply aren't configured to recognize them. This means that unlisted, private, or even direct posts may end up in places you didn't expect on one of these servers—like in the public timeline, or a user's reblogs.

That is super relevant for "private" posts by Mastodon. They fall into the same category as how you've been voting on Lemmy posts and comments: This stuff seems private, because it's being hidden in your UI, but it's actually being broadcasted out to random untrusted servers behind the scenes, and some server software is going to expose it. It's simply going to happen. You need to be aware of that. Even if it's not shown in your UI, it is available.

Anyway, Pixelfed had a bug in its handling of those types of posts, which meant that in some circumstances it would show them to everyone. Somebody wrote on her blog about how her partner has been posting sensitive information as "private," and Pixelfed was exposing it, and how it's a massive problem. For some reason, Dansup (Pixelfed author) taking it seriously and fixing the problem and pushing out a new version within a few days only made this person more upset, because in her (IMO incorrect) opinion, the way Dansup had done it was wrong.

I think the blog-writer is just mistaken about some of the technical issues involved. It sounds like she's planning on telling her partner that it's still okay to be posting her private stuff on Mastodon, marked "private," now that Pixelfed and only Pixelfed has fixed the issue. I think that's a huge mistake for reasons that should be obvious. It sounds like she's very upset that Dansup made it explicit that he was fixing this issue, thinking that even exposing it in commit comments (which as we know get way more readership than blog posts) would mean people knew about it, and the less people that knew about it, the safer her partner's information would be since she is continuing to do this apparently. You will not be surprised to discover that I think that type of thinking is also a mistake.

That's not even what I want to talk about, though. I have done security-related work professionally before, so maybe I look at this stuff from a different perspective than this lady does. What I want to talk about is this type of comments on Lemmy, when this situation got posted here under the title "Pixelfed leaks private posts from other Fediverse instances":

Non-malicious servers aren’t supposed to do what Pixelfed did.

Pixelfed got caught with its pants down

rtfm and do NOT give a rest to bad behaving software

dansup remains either incompetent for implementing badly something easy or toxic for federating ignoring what the federation requires

i completely blame pixelfed here: it breaks trust in transit and that’s unacceptable because it makes the system untrustworthy

periodic reminder to not touch dansup software and to move away from pixelfed and loops

dansup is not competent and quite problematic and it’s not even over

developers with less funding (even 0) contributed way more to fedi, they’re just less vocal

dansup is all bark no bite, stop falling for it

dansup showed quite some incompetence in handling security, delivering features, communicating clearly and honestly and treating properly third party devs

I sort of started out in the ensuing conversation just explaining the issues involved, because they are subtle, but there are people who are still sending me messages a day later insisting that Dansup is a big piece of shit and he broke the internet on purpose. They're also consistently upset, among other reasons, that he's getting paid because people like the stuff he made and gave away, and chose to back his Kickstarter. Very upset. I keep hearing about it.

This is not the first time, or even the first time with Dansup. From time to time, I see this with some kind of person on the Fediverse who's doing something. Usually someone who's giving away their time to do something for everyone else. Then there's some giant outcry that they are "problematic" or awful on purpose in some way. With Dansup at least, every time I've looked at it, it's mostly been trumped-up nonsense. The worst it ever is, in actuality, is "he got mad and posted an angry status HOW DARE HE." Usually it is based more or less on nothing.

Dansup isn't just a person making free software, who sometimes posts angry unreasonable statuses or gets embroiled in drama for some reason because he is human and has human emotions. He's the worst. He is toxic and unhinged. He is keeping his Loops code secret and breaking his promises. He makes money. He broke privacy for everyone (no don't tell me any details about the protocol or why he didn't he broke it for everyone) (and don't tell me he fixed it in a few days and pushed out a new version that just makes it worse because he put it in the notes and it'll be hard for people to upgrade anyway so it doesn't count)

And so on.

Some particular moderator isn't just a person who sometimes makes poor moderation decisions and then doubles down on them. No, he is:

a racist and a zionist and will do whatever he can to delete pro-Palestinian posts, or posts that criticize Israel.

a vile, racist, zionist piece of shit, and anyone who defends or supports him is sitting at the table with him and accepts those labels for themselves.

And so on. The exact same pattern happened with a different lemmy.world mod who was extensively harassed for months for various made-up bullshit, all the way up until the time where he (related or not) decided to stop modding altogether.

It's weird. Why are people so vindictive and personal, and why do they double down so enthusiastically about taking it to this personal place where this person involved is being bad on purpose and needs to be attacked for being horrible, instead of just being a normal person with a variety of normal human failings as we all have? Why are people so un-amenable to someone trying to say "actually it's not that simple", to the point that a day later my inbox is still getting peppered with insistences that Dansup is the worst on this private-posts issue, and I'm completely wrong and incompetent for thinking otherwise and all the references I've been digging up and sending to try to illustrate the point are just more proof that I'm horrible?

Guys: Chill out.

I would just recommend, if you are one of these people that likes to double down on all this stuff and get all amped-up about how some particular fediverse person is "problematic" or "toxic" or various other vague insinuations, or you feel the need to bring up all kinds of past drama any time anything at all happens with the person, that you not.

I am probably guilty of this sometimes. I definitely like to give people hell sometimes, if in my opinion they are doing something that's causing a problem. But the extent to which the fediverse seems to like to do this stuff just seems really extreme to me, and a lot of times what it's based on is just weird petty bullying nonsense.

Just take it it with a grain of salt, too, if you see it, is also what I'm saying. Whether it comes from me or whoever. A lot of times, the issue doesn't look like such a huge deal once you strip away the histrionics and the assumption that everyone's being malicious on purpose. Doubly so if the emotion and the innuendo is running way ahead of what the actual facts are.

view more: ‹ prev next ›