Elektrine lite

← Feed

@unusnemo@friendica.rogueproject.org

Post #4046298

2026-07-23 21:08 UTC

@zer0unplanned This really sounds like a bunch of scare mongering to me. Though if there is any semblance of truth in it then it is clear that sites need to stop relying on so many modules and do more coding themselves. There are so many known issues with many standard PHP modules that they can hardly be called zero day attacks when they are exploited. If anything these AI LLMs are hopefully waking site maintainers up to the fact that the day of gluing together some modules and calling it a site is over. I am absolutely certain there are many security issues in Mastodon, Friendica and the whole suite of Fediverse servers. The fact is we really need to rewrite a lot of these modules with: Domain specific only what you need features. Security enhancements included in the latest PHP implementations. Better security minded coding practices (better DevOP). It is a well known fact that the more complexity the more likely a bug is going to exist. We need to simplify and stop trying to do to much in one module. I know it is already a nightmare with how many modules are in a modern project. Though security is not optional.

Replies (1)

  • @unusnemo I agree but it makes the news headlines even here, just the fact that it did something autonomously and on top hacked another platform. Maybe it is fearmongering as you say to get more regulations as result, true. I agree with all the rest.

    Open ##4061268