Important - Piefed.zip down due to security maintenance (Resolved)

Edit: see pinned comment for update

Hello All,

Due to the incredibly irresponsible disclosure of a security vulnerability for Piefed, we've had to take Piefed.zip offline until a fix can be put in place.

I'll update more once I have more information.

Many thanks

Demigodrick

138 points · 24 comments · view on lemmy.world

24 Comments

fiat_lux@lemmy.zip · 34 pts · 111d (4 replies)

A few months ago I mentioned in a thread about Piefed there were questionable system design choices that indicated that other parts of the system should be carefully examined for how they’re handling and sanitizing input. I'm assuming someone discovered one of the places that this was actively exploitable.

From what I've seen of the code, although Python is not my specialty, it might be worth delaying reactivation until it can demonstrate that it is at least somewhat resistant to the OWASP Top 10, especially Injection.

Irresponsible disclosure is annoying, but vastly better than discovery and exploitation by those who aren't going to disclose at all.

Blaze@lemmy.zip · 2 pts · 110d (2 replies)

You can look at https://codeberg.org/rimu/pyfedi/releases/tag/v1.6.25 to see the changes.

Basically, the 0-day was mostly someone running an LLM and trying to discover vulnerabilities without double checking them. Most of the things reported were not applicable (mentioning functions that don’t even exist), others were not applicable but led to some tangent hardening.

Lemmy also had a SSRF vulnerability a month ago: https://github.com/LemmyNet/lemmy/security/advisories/GHSA-q537-8fr5-cw35

fiat_lux@lemmy.zip · 2 pts · 109d (1 reply)

The raw changes are interesting but not particularly descriptive of the problem(s?) it intends to resolve, so I can't gauge whether it achieves the goal from this. The description of the version bump as simply "security improvements" doesn't help me determine if any of these changes add dedicated tests or anything else to prevent future occurrences (and I'm not traversing the repository on my phone). Additionally, the issue acknowledged via inline comment: "This will probably break PeerTube federation" is odd to omit from even the briefest changelog. In my opinion, this is not that reassuring an update.

The LLM generated report of Lemmy's vulnerability, which I note requires an entire DNS configuration to exploit, is a little ironic to point to as an authoritative source while characterizing the Piefed exploit discovery as "someone running an LLM and trying to discover vulnerabilities without double checking them".

But I don't think it's necessary or helpful to have a competitive security score-card situation between packages either - I would much prefer that each ActivityPub implementation is meaningfully improving their development lifecycle processes, especially around security risk mitigation, even if they don't go quite as far as having a formal "security posture".

Blaze@lemmy.zip · 1 pts · 108d

As you seem knowledgeable about the security hardening process, could you maybe try to help Piefe on that topic?

The development team is small and could probably use some help

Blaze@piefed.social · -4 pts · 110d

You can look at https://codeberg.org/rimu/pyfedi/releases/tag/v1.6.25 to see the changes.

Basically, the 0-day was mostly someone running an LLM and trying to discover vulnerabilities without double checking them. Most of the things reported were not applicable (mentioning functions that don't even exist), others were not applicable but led to some tangent hardening.

Lemmy also had a SSRF vulnerability a month ago: https://github.com/LemmyNet/lemmy/security/advisories/GHSA-q537-8fr5-cw35

Demigodrick@lemmy.zip MOD · 30 pts · 110d (1 reply)

Update: there are additional reported vulnerabilities that I have been made aware of.

These have been shared with the Piefed Dev but no fixes yet in place.

Given this knowledge and the fact these exploits could be used to target vulnerable users and potentially access account data, I feel it is sensible to keep the instance offline until further fixes are in place.

Blaze@lemmy.zip · 11 pts · 110d

Makes sense, thank you!

YoiksAndAway@lemmy.zip · 18 pts · 111d

Thanks, as always, Demigodrick. I'll use my lemmy.zip alt until things are sorted.

Schwim@lemmy.zip · 13 pts · 111d

EDIT: This has been resolved thanks to the helpful people on the matrix channel. For anyone else having problems, I just exported my lemmy profile, prettified both json files and manually moved over my blocks and subs then re-imported the modified lemmy file.

Hi there @Demigodrick@lemmy.zip , is there any way to use the piefed.zip export to import to lemmy.zip? I tried since it was mentioned in the email but it just states that the import failed when I try.

Just wondering if I can modify or remove some elements of the file so I can use it to get the blocks and subs imported from my piefed account.

Thanks!

rumba@lemmy.zip · 10 pts · 111d

GOAT

Most admins would stick their head in the sand. Thank you!

FrederikNJS@lemmy.zip · 9 pts · 111d (2 replies)

Thank you for taking proactive measures. I hope it gets resolved soon.

Are there any information around the nature of the vulnerability or the status of a fix?

huppakee@lemmy.world · 4 pts · 111d (1 reply)

According to this comment https://piefed.social/comment/11352527 fix is expected to take a day.

TachyonTele@piefed.social · 6 pts · 111d

It was like 40 minutes in the end.

Blaze@lemmy.zip · 8 pts · 111d

Thank you!

U7826391786239@lemmy.zip · 7 pts · 110d (7 replies)
[ removed ]
frongt@lemmy.zip · -1 pts · 110d (6 replies)

I'm on my phone so I can't review the issues, but I'm guessing they're mostly about the web interface. I would just not expose that to the world, only expose the necessary federation API endpoints.

U7826391786239@lemmy.zip · 7 pts · 110d (5 replies)
[ removed ]
Blaze@lemmy.zip · 1 pts · 109d

lemmy

the dev rimu banning people and people getting mad about it

Let's be honest, Lemmy devs are also known to be banning a lot.

If you were not using the Piefed features (personal feeds, crossposts comments consolidation, flairs, instance blocking) then going back to Lemmy makes sense.

It doesn't really matter in the end, all the communities are still available on all sides (with Mbin)

Kierunkowy74@lemmy.zip · 1 pts · 110d (3 replies)

Rimu has banned then from the flagship .social instance.

Do anyone care, that the Lemmy flagship is technically .ml?

BrikoX@lemmy.zip · 3 pts · 110d (2 replies)

Technically lemmy.ml is canonical, but I wouldn't classify it as flagship.

Lemmy also doesn't feature their own instance, unlike Mastodon or PieFed.

Kierunkowy74@lemmy.zip · 0 pts · 110d (1 reply)

Few more dramas and the same we will say about piefed.social /s

Yes, lemmy.ml is featured. Change the language to English. It's .world which is omitted because of its size.

U7826391786239@lemmy.zip · 2 pts · 109d
[ removed ]
sirxdaemon@lemmy.ca · 3 pts · 110d

Appreciate the email on this. I don't think I got an email from Piefed.social either. Heck I don't remember getting any from Lemmy.ca for Lemmy downtime. But perhaps they haven't ran into a similar situation.

RickyRigatoni@retrolemmy.com · 1 pts · 111d

1Fuji2Taka3Nasubi@lemmy.zip · 1 pts · 110d

Thanks for the heads up.

Az_1@piefed.social · -1 pts · 110d (3 replies)
[ removed ]
Blaze@piefed.social · 6 pts · 110d (2 replies)

It's Saturday, I would give the .zip team some time

Az_1@piefed.social · 3 pts · 110d (1 reply)
[ removed ]
Blaze@piefed.social · 2 pts · 110d

No worries!