I'm looking at @zulip as a possible option for the Asahi Linux chat, but I've already run into something concerning... It seems they trust verified e-mails from all of their authentication providers (GitHub / Gitlab / Google). This means their attack surface is *all* of those.
-
Show this thread
-
So even if you've never logged into
@zulip with@gitlab, if you have a Gitlab account and someone takes over it, they can take over your Zulip. If you don't have a Gitlab account and someone creates one and manages to verify your email on it, they can take over your Zulip.1 reply 0 retweets 14 likesShow this thread -
This seems... suboptimal. Third party log-ins should be linked explicitly, not implicitly via verified e-mails. I was confused, looking for that option in the settings and not finding it... then realized it was automagic via email matching.
2 replies 0 retweets 16 likesShow this thread -
Replying to @marcan42
Does that assume that you can't change the email address on such an account? I've certainly seen services that do that and now I'm shut out from both Kobo and Ingress accounts...


1 reply 0 retweets 1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.