5 ms·
I wouldn't recommend Slime to ANYONE because the developers do not care about security. The issue[0] of a gaping security hole has been open for going on two ye
by cadillackness 9y ago
I wouldn't recommend Slime to ANYONE because the developers do not care about security. The issue[0] of a gaping security hole has been open for going on two years.
- dasyatidprime 9y agoDid you forget the link?
- PuercoPop 9y agoThey are talking about this issue https://github.com/slime/slime/issues/286 https://github.com/slime/slime/issues/286 If it has being left unaddressed because no one thinks it is enough of a problem. That is how free software works
- mbrock 9y agoThat actually scares me enough to disable Swank on my laptop. Actually, to disable all localhost services that could by any stretch of the imagination execute code. Tl;dr: web sites can send requests to localhost TCP sockets despite origin restrictions using a trick called DNS rebinding.
- PuercoPop 9y agoYes, it certainly a gaping security hope. Yet I cant bring myself to submit a patch