What is Nostr?
Semisol 👨‍💻
npub1226…grkj
2024-04-28 19:52:43

Semisol 👨‍💻 on Nostr: LNbits has no interest in fixing vulnerabilities. They have postponed fixes for all ...

LNbits has no interest in fixing vulnerabilities. They have
postponed fixes for all reports I have made before (an SQLi
vulnerability for a few months, and a few weeks for improper access
control on SatsDice that was most likely why Super Testnet's wallet got
drained) and have called me a "FUDer" for posting a link to the
vulnerability report (only visible to logged in collaborators) in the
chat to inform developers that I filed a report.

I have no other choice. The validation of this vulnerability was done with the permission of the operators of said instances.

Author Public Key
npub12262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7s6cgrkj