DataDrivenMD,
@DataDrivenMD@fedified.com avatar

@GossiTheDog @jerry @untitaker Can confirm that it pings every instance— even those that have been explicitly blocked or limited by the host instance unless the blocked instance has also been added to the "unavailable" table, which isn't automatic upon blocking/limiting

jerry,
@jerry@infosec.exchange avatar

@DataDrivenMD @GossiTheDog @untitaker yikes. I was unaware. Does that happen when I suspend them too?

DataDrivenMD,
@DataDrivenMD@fedified.com avatar

@jerry @GossiTheDog @untitaker If you're referring to suspending an account on your instance: yes. That's how I uncovered this particular data/privacy leak— I suspended a test account, and noticed my Sidekiq Retries fill up with errors from my Push queue. The errors stemmed from my WAF blocking inbound webfinger probes triggered in response to the outbound message sent by my instance.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • Ask_kbincafe
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines