I'm looking at @zulip as a possible option for the Asahi Linux chat, but I've already run into something concerning... It seems they trust verified e-mails from all of their authentication providers (GitHub / Gitlab / Google). This means their attack surface is *all* of those.
-
-
Probably say... 5-whatever years ago I was annoyed when some services wouldn't automatically approve of SSO logins from other providers if it was the same email I signed up for and I quickly learned how that was a very bad thing when I had to implement the same thing for someone
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
What’s your threat model? An adversary takes over an account, now what bad can they do?
-
That, or someone somewhere has a different idea than you about email canonicalization. Or a service gets compromised and that now affects people who aren't users. Like, if Gitlab gets owned the attacker can take over *all*
@zulip accounts, not just those of Gitlab users.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.