Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

FòrumCAT

  1. Home
  2. Uncategorized
  3. So @pixelfed still hasn't fully acknowledged nor fixed the security vulnerability from earlier this year, despite multiple people asking for updates over the past ~6 months.

So @pixelfed still hasn't fully acknowledged nor fixed the security vulnerability from earlier this year, despite multiple people asking for updates over the past ~6 months.

Scheduled Pinned Locked Moved Uncategorized
47 Posts 10 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

    @chad @dansup @deadsuperhero and that's kinda the problem isn't it? Doing multiple large things isn't sustainable, and it means that stuff like this drags on. If he wants to focus on loops, great, find someone to lead pixelfed, but trying to be the leader of multiple projects but not actually doing the things a leader should be doing isn't good for the fediverse.

    One person alone shouldn't be attempting to build everything for the fediverse, others might build things if they think there's space for them to build, but instead Dan says he's going to do XYZ repeatedly and then fails to deliver.

    Focus is a good thing, especially when the complexity we have is involved, and it's not like people haven't been trying to get answers on this. Posting publicly wasn't my first choice months ago.

    chad@mstdn.caC This user is from outside of this forum
    chad@mstdn.caC This user is from outside of this forum
    chad@mstdn.ca
    wrote last edited by
    #26

    @thisismissem @dansup @deadsuperhero so who else that has the talent, time, and treasure is going to step up and do it?

    thisismissem@hachyderm.ioT 1 Reply Last reply
    0
    • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

      @chad @dansup @deadsuperhero and that's kinda the problem isn't it? Doing multiple large things isn't sustainable, and it means that stuff like this drags on. If he wants to focus on loops, great, find someone to lead pixelfed, but trying to be the leader of multiple projects but not actually doing the things a leader should be doing isn't good for the fediverse.

      One person alone shouldn't be attempting to build everything for the fediverse, others might build things if they think there's space for them to build, but instead Dan says he's going to do XYZ repeatedly and then fails to deliver.

      Focus is a good thing, especially when the complexity we have is involved, and it's not like people haven't been trying to get answers on this. Posting publicly wasn't my first choice months ago.

      thisismissem@hachyderm.ioT This user is from outside of this forum
      thisismissem@hachyderm.ioT This user is from outside of this forum
      thisismissem@hachyderm.io
      wrote last edited by
      #27

      @chad @dansup @deadsuperhero trying to do everything often leads to doing all things poorly.

      The blossoming fedi software is all ones where the folks are actually focused on just that project, whether that's the mastodon team with mastodon, rimu's team with piefed, julian and nodebb, bonfire and bonfire social.

      Meanwhile Dan somehow things he can build a TikTok and a Instagram and a WhatsApp competitor all at once with fairly minimal team — he's the outlier here, and I don't think this behaviour should necessarily be encouraged because it is giving poor results and underdelivering to people.

      chad@mstdn.caC 1 Reply Last reply
      0
      • chad@mstdn.caC chad@mstdn.ca

        @thisismissem @dansup @deadsuperhero so who else that has the talent, time, and treasure is going to step up and do it?

        thisismissem@hachyderm.ioT This user is from outside of this forum
        thisismissem@hachyderm.ioT This user is from outside of this forum
        thisismissem@hachyderm.io
        wrote last edited by
        #28

        @chad @dansup @deadsuperhero plenty of people, there's countless projects across the fedi for all sorts of things, dan doesn't need to be a one man army.

        He could, if he wanted to, find a new lead developer for pixelfed if his interests are in loops now.

        chad@mstdn.caC 1 Reply Last reply
        0
        • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

          @chad @dansup @deadsuperhero trying to do everything often leads to doing all things poorly.

          The blossoming fedi software is all ones where the folks are actually focused on just that project, whether that's the mastodon team with mastodon, rimu's team with piefed, julian and nodebb, bonfire and bonfire social.

          Meanwhile Dan somehow things he can build a TikTok and a Instagram and a WhatsApp competitor all at once with fairly minimal team — he's the outlier here, and I don't think this behaviour should necessarily be encouraged because it is giving poor results and underdelivering to people.

          chad@mstdn.caC This user is from outside of this forum
          chad@mstdn.caC This user is from outside of this forum
          chad@mstdn.ca
          wrote last edited by
          #29

          @thisismissem @dansup @deadsuperhero "he's building things but not at the rate I would approve" is quite the take considering he's currently a one man band and I'm sure Eugen was at some point.

          I'm really not subscribing to this as really, the fediverse is in its infancy and this exclusionism is exactly what is inhibiting its growth.

          Again, appreciate what you do writ large, but I'm not behind this take.

          thisismissem@hachyderm.ioT 1 Reply Last reply
          0
          • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

            @chad @dansup @deadsuperhero plenty of people, there's countless projects across the fedi for all sorts of things, dan doesn't need to be a one man army.

            He could, if he wanted to, find a new lead developer for pixelfed if his interests are in loops now.

            chad@mstdn.caC This user is from outside of this forum
            chad@mstdn.caC This user is from outside of this forum
            chad@mstdn.ca
            wrote last edited by
            #30

            @thisismissem @dansup @deadsuperhero why would he need a new lead dev if he's perfectly capable of being in that role?

            Where are others offering PRs?

            thisismissem@hachyderm.ioT 1 Reply Last reply
            0
            • chad@mstdn.caC chad@mstdn.ca

              @thisismissem @dansup @deadsuperhero "he's building things but not at the rate I would approve" is quite the take considering he's currently a one man band and I'm sure Eugen was at some point.

              I'm really not subscribing to this as really, the fediverse is in its infancy and this exclusionism is exactly what is inhibiting its growth.

              Again, appreciate what you do writ large, but I'm not behind this take.

              thisismissem@hachyderm.ioT This user is from outside of this forum
              thisismissem@hachyderm.ioT This user is from outside of this forum
              thisismissem@hachyderm.io
              wrote last edited by
              #31

              @chad @dansup @deadsuperhero yes, Eugen was a one man band at one point, but he focused on one thing instead of trying to do everything. He also accepted help when it was given, he worked with pull requests instead of in isolation.

              And it's not that it's a "rate I would approve", it's him saying "yeah, I'm almost done with that" and then crickets for months. Or "yeah, I'm going to build this and write a FEP", and then nothing materialises.

              Dan has also alienated a tonne of people who at one point or another wanted to help him.

              People rely on Dan's software, and he does a lot of marketing, so people's expectations are set high. If you say you're going to do something, do it, or explain why you're not, with something better than "I'm distracted by my other three projects"

              chad@mstdn.caC 1 Reply Last reply
              0
              • chad@mstdn.caC chad@mstdn.ca

                @thisismissem @dansup @deadsuperhero why would he need a new lead dev if he's perfectly capable of being in that role?

                Where are others offering PRs?

                thisismissem@hachyderm.ioT This user is from outside of this forum
                thisismissem@hachyderm.ioT This user is from outside of this forum
                thisismissem@hachyderm.io
                wrote last edited by
                #32

                @chad @dansup @deadsuperhero If he's not actually doing the leading then that's a problem. Where are the people doing PRs? He chased them all off, I can think of at least 3 people that wanted to contribute actively to his projects and he pissed them off by being completely unpredictable to work with.

                hiphopheaven@mastodon.socialH 1 Reply Last reply
                0
                • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

                  @chad @dansup @deadsuperhero yes, Eugen was a one man band at one point, but he focused on one thing instead of trying to do everything. He also accepted help when it was given, he worked with pull requests instead of in isolation.

                  And it's not that it's a "rate I would approve", it's him saying "yeah, I'm almost done with that" and then crickets for months. Or "yeah, I'm going to build this and write a FEP", and then nothing materialises.

                  Dan has also alienated a tonne of people who at one point or another wanted to help him.

                  People rely on Dan's software, and he does a lot of marketing, so people's expectations are set high. If you say you're going to do something, do it, or explain why you're not, with something better than "I'm distracted by my other three projects"

                  chad@mstdn.caC This user is from outside of this forum
                  chad@mstdn.caC This user is from outside of this forum
                  chad@mstdn.ca
                  wrote last edited by
                  #33

                  @thisismissem @dansup @deadsuperhero all those words are great, and I align with many of them, but I still haven't seen anyone offer a PR for any of his projects.

                  Honestly, and I'm sorry to say, this is a step up or shut up situation.

                  "He created too much too quickly" really isn't aligned with any of the values many of us hold in the hopes of growth of the fediverse.

                  thisismissem@hachyderm.ioT julian@community.nodebb.orgJ 2 Replies Last reply
                  0
                  • chad@mstdn.caC chad@mstdn.ca

                    @thisismissem @dansup @deadsuperhero all those words are great, and I align with many of them, but I still haven't seen anyone offer a PR for any of his projects.

                    Honestly, and I'm sorry to say, this is a step up or shut up situation.

                    "He created too much too quickly" really isn't aligned with any of the values many of us hold in the hopes of growth of the fediverse.

                    thisismissem@hachyderm.ioT This user is from outside of this forum
                    thisismissem@hachyderm.ioT This user is from outside of this forum
                    thisismissem@hachyderm.io
                    wrote last edited by
                    #34

                    @chad @dansup @deadsuperhero he literally chased away all the people who wanted to contribute, like seriously, no other fedi dev had had a letter like this written: https://dansup-open-letter.github.io

                    Ask dan about how he works sometimes, because last I knew he tended to have thousands of untracked files where he was doing too many changes at once, but not finishing any of them or working in branches such that he could cleanly switch tasks — that's what leads to those massive "do all the things" merges.

                    If he hadn't chased others away from his projects it'd be a different matter.

                    chad@mstdn.caC thisismissem@hachyderm.ioT 2 Replies Last reply
                    0
                    • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

                      @chad @dansup @deadsuperhero he literally chased away all the people who wanted to contribute, like seriously, no other fedi dev had had a letter like this written: https://dansup-open-letter.github.io

                      Ask dan about how he works sometimes, because last I knew he tended to have thousands of untracked files where he was doing too many changes at once, but not finishing any of them or working in branches such that he could cleanly switch tasks — that's what leads to those massive "do all the things" merges.

                      If he hadn't chased others away from his projects it'd be a different matter.

                      chad@mstdn.caC This user is from outside of this forum
                      chad@mstdn.caC This user is from outside of this forum
                      chad@mstdn.ca
                      wrote last edited by
                      #35

                      @thisismissem @dansup @deadsuperhero this conversation has progressed to the point where I think Dan is owed an opportunity to weigh in.

                      rey@toot.catR 1 Reply Last reply
                      0
                      • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

                        @chad @dansup @deadsuperhero he literally chased away all the people who wanted to contribute, like seriously, no other fedi dev had had a letter like this written: https://dansup-open-letter.github.io

                        Ask dan about how he works sometimes, because last I knew he tended to have thousands of untracked files where he was doing too many changes at once, but not finishing any of them or working in branches such that he could cleanly switch tasks — that's what leads to those massive "do all the things" merges.

                        If he hadn't chased others away from his projects it'd be a different matter.

                        thisismissem@hachyderm.ioT This user is from outside of this forum
                        thisismissem@hachyderm.ioT This user is from outside of this forum
                        thisismissem@hachyderm.io
                        wrote last edited by
                        #36

                        @chad @dansup @deadsuperhero his repeated response to issues raised is "fake news" or "misinformation", when what's being said is easily provable. He is the marker of his current situation, and only he can do the work to rectify it.

                        1 Reply Last reply
                        0
                        • chad@mstdn.caC chad@mstdn.ca

                          @thisismissem @dansup @deadsuperhero this conversation has progressed to the point where I think Dan is owed an opportunity to weigh in.

                          rey@toot.catR This user is from outside of this forum
                          rey@toot.catR This user is from outside of this forum
                          rey@toot.cat
                          wrote last edited by
                          #37

                          @chad @thisismissem @dansup @deadsuperhero he's been tagged on this entire thread

                          chad@mstdn.caC 1 Reply Last reply
                          0
                          • rey@toot.catR rey@toot.cat

                            @chad @thisismissem @dansup @deadsuperhero he's been tagged on this entire thread

                            chad@mstdn.caC This user is from outside of this forum
                            chad@mstdn.caC This user is from outside of this forum
                            chad@mstdn.ca
                            wrote last edited by
                            #38

                            @rey @thisismissem @dansup @deadsuperhero I'm aware. It's also 6am MDT.

                            rey@toot.catR 1 Reply Last reply
                            0
                            • chad@mstdn.caC chad@mstdn.ca

                              @rey @thisismissem @dansup @deadsuperhero I'm aware. It's also 6am MDT.

                              rey@toot.catR This user is from outside of this forum
                              rey@toot.catR This user is from outside of this forum
                              rey@toot.cat
                              wrote last edited by
                              #39

                              @chad @thisismissem @dansup @deadsuperhero this thread started three days ago and he has, apparently, already responded to it

                              thisismissem@hachyderm.ioT 1 Reply Last reply
                              0
                              • rey@toot.catR rey@toot.cat

                                @chad @thisismissem @dansup @deadsuperhero this thread started three days ago and he has, apparently, already responded to it

                                thisismissem@hachyderm.ioT This user is from outside of this forum
                                thisismissem@hachyderm.ioT This user is from outside of this forum
                                thisismissem@hachyderm.io
                                wrote last edited by
                                #40

                                @rey @chad @dansup @deadsuperhero yes, and the only response has been an accusation of spread misinformation which was easily disproven

                                chad@mstdn.caC 1 Reply Last reply
                                0
                                • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

                                  @rey @chad @dansup @deadsuperhero yes, and the only response has been an accusation of spread misinformation which was easily disproven

                                  chad@mstdn.caC This user is from outside of this forum
                                  chad@mstdn.caC This user is from outside of this forum
                                  chad@mstdn.ca
                                  wrote last edited by
                                  #41

                                  @thisismissem @rey @dansup @deadsuperhero I feel that given the overall careful discussion here, an accusation of misinformation is a great departure.

                                  thisismissem@hachyderm.ioT 1 Reply Last reply
                                  0
                                  • thisismissem@hachyderm.ioT thisismissem@hachyderm.io

                                    @chad @dansup @deadsuperhero If he's not actually doing the leading then that's a problem. Where are the people doing PRs? He chased them all off, I can think of at least 3 people that wanted to contribute actively to his projects and he pissed them off by being completely unpredictable to work with.

                                    hiphopheaven@mastodon.socialH This user is from outside of this forum
                                    hiphopheaven@mastodon.socialH This user is from outside of this forum
                                    hiphopheaven@mastodon.social
                                    wrote last edited by
                                    #42

                                    @thisismissem @chad @dansup @deadsuperhero why do they not create an alternative? This ia suppose to be the power of open source you can fork projects and create new wonderful things

                                    chad@mstdn.caC 1 Reply Last reply
                                    0
                                    • hiphopheaven@mastodon.socialH hiphopheaven@mastodon.social

                                      @thisismissem @chad @dansup @deadsuperhero why do they not create an alternative? This ia suppose to be the power of open source you can fork projects and create new wonderful things

                                      chad@mstdn.caC This user is from outside of this forum
                                      chad@mstdn.caC This user is from outside of this forum
                                      chad@mstdn.ca
                                      wrote last edited by
                                      #43

                                      @hiphopheaven @thisismissem @dansup @deadsuperhero there's no one stopping anyone from forking Dan's projects.

                                      thisismissem@hachyderm.ioT 1 Reply Last reply
                                      0
                                      • chad@mstdn.caC chad@mstdn.ca

                                        @thisismissem @rey @dansup @deadsuperhero I feel that given the overall careful discussion here, an accusation of misinformation is a great departure.

                                        thisismissem@hachyderm.ioT This user is from outside of this forum
                                        thisismissem@hachyderm.ioT This user is from outside of this forum
                                        thisismissem@hachyderm.io
                                        wrote last edited by
                                        #44

                                        @chad @rey @dansup @deadsuperhero that was *his* accusation. Not mine. I then spent the time to review the changes, and was fully prepared to update as resolved, only, it wasn't & the changes where thousands of lines of unrelated code. I spent quite some time checking.

                                        1 Reply Last reply
                                        0
                                        • chad@mstdn.caC chad@mstdn.ca

                                          @hiphopheaven @thisismissem @dansup @deadsuperhero there's no one stopping anyone from forking Dan's projects.

                                          thisismissem@hachyderm.ioT This user is from outside of this forum
                                          thisismissem@hachyderm.ioT This user is from outside of this forum
                                          thisismissem@hachyderm.io
                                          wrote last edited by
                                          #45

                                          @chad @hiphopheaven @dansup @deadsuperhero it's hard when he'll actively fight against you, iirc, he got extremely mad when pixelfed-glitch was started, and threatened a trademark lawsuit. That probably killed that person's energy to work on it.

                                          He also went after the developer of Vernissage a while back too, when they decided to do their own thing away from pixelfed.

                                          Meanwhile he raises 100k for pixelfed, but it seems like all the energy is going into his other projects.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups