Linux_Is_Best,
@Linux_Is_Best@mstdn.social avatar

Att Fediverse

The flagship instance of Fire Fish is now OFFLINE.

The significance of this event is many of the Fire Fish Developers have previously come forward claiming the lead developer vanished. Unfortunately, the lead developer treated their project as a centralized project, meaning that they were the sole person making decisions, giving no access to accounts or code changes or even donations, despite having a team behind them.

1 of 2

Linux_Is_Best,
@Linux_Is_Best@mstdn.social avatar

2 of 2

Fire Fish is now a dead project with the lead developer missing for more than half a year, the remaining developers disbanding, and today, the flagship instance Fire Fish dot Social going OFFLINE.

It is strongly recommended that you migrate your instance to another platform.

You have options

  • Sharkey
  • Misskey
  • Mastodon

Please consider Fire Fish no longer receives updates, including security.

tetra,
@tetra@meowcity.club avatar

!! IMPORTANT NOTE !!
Sharkey just had a security vulnerability due to evaluating JSON (instead of parsing it), so the trustworthiness of the project is dubious

minneyar,
@minneyar@fuzzyfox.social avatar

@tetra This sucks, but security vulnerabilities can happen to literally any project. Coincidentally, Mastodon also just released a fix for a critical security vulnerability.

They disclosed the vulnerability and released both a workaround and a fix for it nearly immediately after it was reported, which I think says a lot more about the trustworthiness of the project than the fact that a vulnerability existed.

tetra,
@tetra@meowcity.club avatar

It's not about the fact that there was a vulnerability, it's the fact that it was caused by evaluating JSON

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • meta
  • Macbeth
  • All magazines