cm0002@literature.cafe to Programmer Humor@programming.dev · 6 days agoI asked Meta’s Muse for its filesystem and it sent me 6.8 GBmouse.devexternal-linkmessage-square11linkfedilinkarrow-up199arrow-down10cross-posted to: programmerhumor@lemmy.ml
arrow-up199arrow-down1external-linkI asked Meta’s Muse for its filesystem and it sent me 6.8 GBmouse.devcm0002@literature.cafe to Programmer Humor@programming.dev · 6 days agomessage-square11linkfedilinkcross-posted to: programmerhumor@lemmy.ml
minus-squaresmeg@feddit.uklinkfedilinkEnglisharrow-up85·6 days ago There were also SSH key files. I’m not publishing the archive, keys, or session logs. I submitted the report and findings using Meta’s bug bounty program. Meta marked the report “Not Applicable.” Guess they don’t care if you publish the SSH keys then?
minus-squaredocktordreh@discuss.tchncs.delinkfedilinkarrow-up21·6 days agoThey’ve probably rotated the keys since they were notified of the security breach. But yes, companies that act this way undermine the resolve to disclose their security vulnerabilities.
minus-squareDr. Moose@lemmy.worldlinkfedilinkEnglisharrow-up11arrow-down1·6 days agoSsh keys to what? If the key is used for user operations, not internal then there’s no security breach here other than deobfuscation.
minus-squaresmeg@feddit.uklinkfedilinkEnglisharrow-up13·6 days agoGuess they’ll have to publish them to find out
Guess they don’t care if you publish the SSH keys then?
They’ve probably rotated the keys since they were notified of the security breach.
But yes, companies that act this way undermine the resolve to disclose their security vulnerabilities.
Ssh keys to what? If the key is used for user operations, not internal then there’s no security breach here other than deobfuscation.
Guess they’ll have to publish them to find out