\

Sourcehut account takeover via build logs (XSS in ansi2html)

43 points - today at 7:54 PM

Source
  • bstsb

    today at 10:18 PM

    haven’t been properly rickrolled in years, wasn’t expecting that!

    • JamesCoyne

      today at 8:55 PM

      Really commendable work fixing up the upstream python project. I don't think there's anything to be embarrassed about in the timeline.

      • serhack_

        today at 9:23 PM

        I love sourcehut, and I can't really think anything to replace it. But here's my shot. It's a popular myth that independently from the project size, someone should always take the main stream product in the field than small projects because most of the people would use the main stream product and there's an higher chance that vulnerabilities get already exploited/recognized/fixed. Is that true or not? TL;DR: in the evaluation of such products (sourcehut but even self hosted stuff), should we also take account about the project history and the exposition to threats?

        • rvz

          today at 9:22 PM

          HN hug of death, strikes again.