{"id":159618,"date":"2025-04-02T15:20:00","date_gmt":"2025-04-02T15:20:00","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/04\/02\/a-new-security-fund-opens-up-to-help-protect-the-fediverse-techcrunch\/"},"modified":"2025-04-02T15:20:00","modified_gmt":"2025-04-02T15:20:00","slug":"a-new-security-fund-opens-up-to-help-protect-the-fediverse-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/04\/02\/a-new-security-fund-opens-up-to-help-protect-the-fediverse-techcrunch\/","title":{"rendered":"A new security fund opens up to help protect the fediverse | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">The <a href=\"https:\/\/techcrunch.com\/2024\/06\/25\/welcome-to-the-fediverse-your-guide-to-mastodon-threads-bluesky-and-more\/\" target=\"_blank\" rel=\"noopener\">fediverse<\/a>, also known as the open social web that includes <a href=\"https:\/\/techcrunch.com\/2023\/07\/24\/what-is-mastodon\/\" target=\"_blank\" rel=\"noopener\">Mastodon<\/a>, Meta\u2019s <a href=\"https:\/\/techcrunch.com\/2024\/06\/25\/all-threads-users-can-now-share-to-the-open-social-web-aka-the-fediverse\/\" target=\"_blank\" rel=\"noopener\">Threads<\/a>, <a href=\"https:\/\/techcrunch.com\/2025\/01\/14\/decentralized-instagram-alternative-pixelfed-launches-mobile-apps\/\" target=\"_blank\" rel=\"noopener\">Pixelfed<\/a>, and other apps, is ramping up its security. On Wednesday, a nonprofit focused on bringing governance to open source projects, the <a rel=\"nofollow noopener\" href=\"https:\/\/nivenly.org\/\" target=\"_blank\">Nivenly Foundation<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/hachyderm.io\/@nivenly\/114268491892140498\" target=\"_blank\">announced<\/a> the launch of a new security fund that will pay those who responsibly disclose security vulnerabilities that affect fediverse apps and services.<\/p>\n<p class=\"wp-block-paragraph\">While all software can have security issues, Mastodon \u2014 an open source and decentralized alternative to X \u2014 has fixed <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/mastodon\/mastodon\/security\/advisories?state=published\" target=\"_blank\">numerous bugs over the years<\/a>, leading to the need for such a program. Another issue found in the fediverse is that many servers are run by independent operators who don\u2019t necessarily have a security background or understand best practices.<\/p>\n<p class=\"wp-block-paragraph\">Already, the Nivenly Foundation has helped a few fediverse projects set up their basic security vulnerability reporting process, and now it\u2019s looking to distribute small payouts to anyone who responsibly discloses other security vulnerabilities that may still be in the wild.<\/p>\n<p class=\"wp-block-paragraph\">The payouts will total $250 for vulnerabilities with a vulnerability severity score (known as CVSS) of 7.0-8.9 and $500 for more critical vulnerabilities with a CVSS score of 9.0 or greater. The funds for the payouts come from the foundation, which is supported directly by <a rel=\"nofollow noopener\" href=\"https:\/\/nivenly.org\/governance\/\" target=\"_blank\">members<\/a> that includes individuals as well as other trade organizations.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerabilities themselves are validated by acceptance from the fediverse project leads as well as public records in vulnerability disclosure (CVE) databases.<\/p>\n<p class=\"wp-block-paragraph\">The fund is currently in a limited trial after the discovery of a <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/pixelfed\/pixelfed\/security\/advisories\/GHSA-gccq-h3xj-jgvf\" target=\"_blank\">security vulnerability<\/a> in the <a href=\"https:\/\/techcrunch.com\/2025\/01\/14\/decentralized-instagram-alternative-pixelfed-launches-mobile-apps\/\" target=\"_blank\" rel=\"noopener\">decentralized Instagram alternative<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/pixelfed.org\/\" target=\"_blank\">Pixelfed<\/a>. Open source contributor <a rel=\"nofollow noopener\" href=\"https:\/\/hachyderm.io\/@thisismissem\" target=\"_blank\">Emelia Smith<\/a> came across the <a rel=\"nofollow noopener\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-25108\" target=\"_blank\">issue<\/a>, and the Nivenly Foundation paid her to fix it, she explains.<\/p>\n<p class=\"wp-block-paragraph\">A more recent <a rel=\"nofollow noopener\" href=\"https:\/\/fokus.cool\/2025\/03\/25\/pixelfed-vulnerability.html\" target=\"_blank\">issue<\/a> came about when Pixelfed\u2019s creator, <a rel=\"nofollow noopener\" href=\"https:\/\/hachyderm.io\/@dansup@mastodon.social\/\" target=\"_blank\">Daniel Supernault<\/a> made the details of a vulnerability public before server operators had a chance to update, which would have left the fediverse vulnerable to bad actors, she says. (Supernault has already <a rel=\"nofollow noopener\" href=\"https:\/\/hachyderm.io\/@dansup@mastodon.social\/114228383063920732\" target=\"_blank\">apologized publicly<\/a> for his handling of the issue that had affected private accounts.)<\/p>\n<p class=\"wp-block-paragraph\">\u201cPart of the program is\u2026education for project leads, helping them understand why responsible disclosure practices for security vulnerabilities are important,\u201d Smith told TechCrunch. \u201cWe came across several projects that just said \u2018file security vulnerabilities in our public issue tracker,\u2019 which absolutely isn\u2019t safe, as any malicious actor watching that repository would now be able to attack instances of that software,\u201d she added.<\/p>\n<p class=\"wp-block-paragraph\">Typically, the common practice is to disclose minimal information about a vulnerability, giving server operators time to upgrade, Smith said. However, this requires that project leads understand security best practices. <\/p>\n<p class=\"wp-block-paragraph\">In the case of the Pixelfed issue, for instance, the <a rel=\"nofollow noopener\" href=\"https:\/\/hachyderm.io\/@hachyderm\/114266848944858666\" target=\"_blank\">Hachyderm Mastodon server<\/a>, which has over 9,500 members, decided it needed to defederate (or disconnect from) other Pixelfed servers that hadn\u2019t been updated in order to protect their users. <\/p>\n<p class=\"wp-block-paragraph\">With this new program designed to follow best practices around the disclosure of vulnerabilities, the need to defederate to protect users may become less common.<\/p>\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-techcrunch wp-block-embed-techcrunch\"\/>\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-techcrunch wp-block-embed-techcrunch\"\/>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/04\/02\/a-new-security-fund-opens-up-to-help-protect-the-fediverse\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The fediverse, also known as the open social web that includes Mastodon, Meta\u2019s Threads, Pixelfed, and other apps, is ramping up its security. On Wednesday, a nonprofit focused on bringing governance to open source projects, the Nivenly Foundation, announced the launch of a new security fund that will pay those who responsibly disclose security vulnerabilities [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":159619,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-159618","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/159618","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=159618"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/159618\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/159619"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=159618"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=159618"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=159618"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}