I'm looking at @zulip as a possible option for the Asahi Linux chat, but I've already run into something concerning... It seems they trust verified e-mails from all of their authentication providers (GitHub / Gitlab / Google). This means their attack surface is *all* of those.
-
-
This seems... suboptimal. Third party log-ins should be linked explicitly, not implicitly via verified e-mails. I was confused, looking for that option in the settings and not finding it... then realized it was automagic via email matching.
Show this thread -
Something something email canonicalization. Here be dragons.
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.