Email or username:

Password:

Forgot your password?
58 posts total
zaki

need someone to smith me,,

zaki

oh woah this is still a thing

zaki

some people on reddit and fedi managed to find out who "Nicole the Fediverse Chick" was, and apparently the entire spamming campaign is orchestrated by the stalker of the person in the images.

they're using pictures and video of someone they stalked and pretending to be Nicole.

reddit.com/r/fediverse/comment

zaki

Anonymous poll

Poll

works on my instance
24
0%
does not work on my instance
21
0%
0 people voted.
zaki

I really feel like fedi is disproportionately autistic with comparison to other social media platforms, but I haven't touched any other major ones in years, nor do I have the necessary data, so I don't really know. Poll: do you identify as autistic (not necessarily officially diagnosed, etc, not trying to exclude the experiences of those without necessary medical access or subclinical presentation)?

Anonymous poll

Poll

autism
93
64.1%
notism
52
35.9%
145 people voted.
Voting ended 28 April at 17:40.
zaki

Pixelfed before v0.12.5 has a vulnerability where it could leak your private posts, regardless of whether you are a Pixelfed user or not.
Admins should update ASAP.

When following someone from a different server on the Fediverse, the remote server decides whether you are allowed to do that. This enables features like locked accounts. Due to an implementation mistake, Pixelfed ignores this and allows anyone to follow even private accounts on other servers. If a legitimate user from a Pixelfed instance follows you on your locked account, anyone on that Pixelfed instance can read your private posts.

I wrote a blog post about how I found the vulnerability, how disclosure coordination went and general ramblings about Fediverse safety:
fokus.cool/2025/03/25/pixelfed

#pixelfed #fediverse #activitypub

Pixelfed before v0.12.5 has a vulnerability where it could leak your private posts, regardless of whether you are a Pixelfed user or not.
Admins should update ASAP.

When following someone from a different server on the Fediverse, the remote server decides whether you are allowed to do that. This enables features like locked accounts. Due to an implementation mistake, Pixelfed ignores this and allows anyone to follow even private accounts on other servers. If a legitimate user from a Pixelfed instance...

zaki

pls gib tips on buying maid dress (i am currently in japan)

zaki

im smithing my reens rn. straight up smithereening it rn

zaki

New sensitive breach: Lexipol had 672k email addresses breached last month by self-proclaimed "Puppygirl Hacker Polycule". Data included name, phone and MD5 or SHA-256 password hashes. 23% were already in @haveibeenpwned. Read more: them.us/story/puppygirl-hacker

zaki updated their profile picture:
zaki

FYI if you got a framework 16 prior to november 2024 you should check to see if you having thermal issues and consider requesting a replacement

zaki

i really need to follow more filipinos and filipino furries in particular there are far too little of them on my feeds

Go Up