Comment on Here is a more polished release of nanogram. Fully compatible on raspberry pi now.

<- View Parent
savvywolf@pawb.social ⁨6⁩ ⁨days⁩ ago
  1. You list “Activist/journalist secure communication” as a use case. Not all countries have freedom of press.

  2. Looks like you name images based on a random uuid, so that should protect against filename attacks. But if you do have a filename you can tell whether the image has been an image or not.

Also, looks like all uploads are converted to jpg, regardless as to whether the original image was a jpg (or even an image) or not. Don’t do that.

  1. Can you point to where in code this invariant is enforced?

source
Sort:hotnewtop