i think i found a major security flaw with .
i can log into riot.im using the homeserver url chat.librem.one with ANYONES username and ANY RANDOM PASSWORD and ill enter the account

@purism ips can be grabbed from this. in the security & privacy section of the settings.

Show thread

they're working on fixing it. librem chat is down now.

Show thread

@rae As an update, we've fixed the bug and chat is back up. I am writing up a full report and will publish it after the development team is able to distribute a security patch of their own. Thank you for your responsible disclosure!

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml