Bluesky Exploits
github.com
github.com
Bluesky posts have a rich text system, which means links in posts are similar to anchor tags. It’s not a markup; it’s a way to annotate slices of a string with facets such as links or bold or etc. This means you can linkify any text, thus the first concern raised. We intend to create an interstitial warning if the linkified text doesn’t show the domain clearly.
The posts also have an embed system for images, links, and other posts. We currently naively accept the link cards as published, and we need to stop doing that and fetch the link cards on read instead.
Maybe not the vulns. But the interaction with a security researcher. Like this part: "Bluesky has responded to only one of these reports, one time, 4 days after submission, saying "We appreciate the report, and we'll be taking a closer look at the issue.". They did not follow up on that report and they have not responded to any of my other reports."
It shows all signs of a company without a working security process.
<a href="https://evil.com/">good.com</a>
, how much of a response am I owed?"Yes, thank you, we're aware" seems more than adequate to me. Engaging a full-blown vulnerability disclosure process for something like this seems like a waste of time for everyone involved.
The initial email in this case was received on a Friday afternoon, reviewed briefly for severity, and then acknowledged on the following Tuesday. There was a reply from another engineer on Wednesday to a reply by the reporter.
But we certainly could have followed-up better, and we could have been more clear. We're a very small team and the severity was deemed low, but even so we'll try to do better in the future for similar cases.
We do want to handle these kinds of reports better than most companies do. Creating a safe and secure system for users (which include our own families and friends) is something the team very genuinely cares deeply about.
While I appreciate your response, the accuracy of the timeline your provided (Wednesday's email was about documentation), and your comment that "[w]e do want to handle these kinds of reports better", I can't help but point out that even today, Bluesky still hasn't reached out to me about the specifics of these (and other...) vulnerabilities. Bryan Newbold did email me a week after this disclosure to answer a few questions, but it didn't address the vulnerabilities at all; I like Bryan -- the few discussions we've had have been positive -- but he isn't the person that should have emailed me.
Sidenode, https://bsky.app/profile/jacob.gold/post/3k7frqmvhft2b sure did seem personal. The timing suggests that it was made solely to mock the situation. (To be clear, I like and respect @retr0.id a lot; I've bounced some of my ideas off of him and he's the "second security researcher" I referred to in the vuln respository.)
This whole thing has put an extremely bad taste in my mouth.
do you mean, hitting a site every time someone loads a post?
that's going to lead to some obvious issues with hammering sites
I can't help but think that Jack doesn't believe in Blue Sky that much. From what I can find, he doesn't seem to participate or even have an account. Meanwhile, at least Elon and Mark both post regularly on their social media sites.
if you consider it an exploit you should probably consider, say, github issues markdown to be exploitable
the tl;dr is the server shouldn't trust the client and the client shouldn't trust the server to supply accurate link cards or link metadata.
right now it's not a huge deal because there's only one instance and it is invite-only. consider it demo grade software.
I have no idea what this is referring to
If you happen to see this, please check my profile for a working email!
(I have 3 invite codes available if people are still desperate for them)
With Mastodon only a few people tried, and when it didn't get much traction they stopped posting there quickly.
ATProto is a NIH reinvention of the wheel by a "public benefit LLC" of unclear ownership* that has demonstrated time and again its unwillingness to take a seat at the table within a group like the W3C or the IETF in protocol development.
What is ActivityPub, you may ask? https://en.wikipedia.org/wiki/ActivityPub
* EDIT: I completely missed there was Bluesky $8M seed round in July, lol. It's now a public benefit C Corp whatever that means.
https://techcrunch.com/2023/07/05/bluesky-announces-its-8m-s...
Current mailing list items specific to bluesky