Skip to content
Tech News
← Back to articles

Follow-up to Carrot disclosure: Forgejo

read original get Forgejo GitHub Sticker → more articles
Why This Matters

This ongoing disclosure highlights the complexities and challenges of vulnerability reporting within open-source projects, emphasizing the importance of clear security policies and community engagement. It underscores the need for better communication and trust between security researchers and project maintainers, which is crucial for improving software security in the tech industry and for consumers. The incident also reflects broader debates about responsible disclosure and the role of community moderation in handling security issues.

Key Takeaways

Since I published Carrot disclosure: Forgejo two days ago, numerous things happened:

Friends of mine were reached out to, to "talk to me from a place of trust", or simply to tell them what an horrible person I am, which they found hilarious.

The toot linking to the blogpost was removed from infosec.exchange by an overzealous moderator after it had been reported multiple times by multiple people. I thus moved to mastodon.social, where it was also removed with "Irresponsible disclosure" given as a reason. So I moved back to infosec.exchange, where the toot was restored. In the meantime, friends handed me invitations for various mastodon instances, which I'm grateful for.

Numerous instances of the eternal vulnerabilities disclosure debate spawned.

Some exploit-writer friends of mine complained that I brought unwanted attention to an easy target.

The Netherlands deployed a sovereign software forge in the form of a public forgejo instance.

Everyone had an opinion on mastodon on this, especially on what I should do with the vulnerabilities I found, and was really vocal about it. I also got called a handful vile names.

Forgejo's security policy was copiously made fun of.

I got a tone deaf email from Forgero's moderation team, to my arguably tone-deaf blog post, which I think is funny.

I've learnt that the role of Forgejo security team is to "take care of security vulnerabilities and to handle sensitive security-related issues reported to [email protected] using encryption." Doing anything proactive isn't in their attributions.

... continue reading