• 0 Posts
  • 22 Comments
Joined 1 year ago
cake
Cake day: July 18th, 2023

help-circle











  • I’m a fan of the swiss cheese model of safety. While blindly blocking arbitrary characters is a bit silly, not filtering/encoding the data even on the output from web services can end up in disaster.

    It’s an open API that serves publicly-sourced data. I’d not want to serve up anything more than markup content even if every single API call had perfect handling. At least not without a lot more sophisticated filtering in front of it. Even certain totally valid arrangements of HTML can be vulnerable as all hell.

    Even certain markup systems have problems, but I doubt this one has huge vulnerabilities to exploit. Certain wiki systems in the past had to be completely retired over such things.






  • I don’t think they’re entirely different. Enshittification is just a specific type. Yes, of course it has distinguishing qualities or we’d be having a totally different convo.

    IMO, it’s more important to realize enshittification is not a new development! It’s just way, WAY more obvious now that the ruling class has allowed effective monopolies to rise again. When only one or two companies control an entire market, their shitty tactics become way, way more obvious and painful for consumers.