Hi All,

Just a heads up that Piefed.zip has returned!

Now that security fixes have been implemented, I feel Piefed is in a safe place to allow people to use again.

The original disclosure included a bug that allowed an attacker to send unsigned Create activities and have them processed as legitimate. The additional vulnerabilities allowed anyone with an account to ban any other user, and a couple of other attacks that could lead to an attacker gaining control of an account.

While serious, Rimu has fixed these quickly and we’re able to bring Piefed.zip back to life. There will be some time before federation catches back up, please do expect federation delays.

Thanks

Demigodrick