onlyTrustedInfo.comonlyTrustedInfo.comonlyTrustedInfo.com
Notification
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Reading: A new security fund opens up to help protect the fediverse
Share
onlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Search
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
  • Advertise
  • Advertise
© 2025 OnlyTrustedInfo.com . All Rights Reserved.
Tech

A new security fund opens up to help protect the fediverse

Last updated: April 2, 2025 11:20 am
Oliver James
Share
4 Min Read
A new security fund opens up to help protect the fediverse
SHARE

The fediverse, also known as the open social web that includes Mastodon, Meta’s Threads, Pixelfed, and other apps, is ramping up its security. On Wednesday, a nonprofit focused on bringing governance to open source projects, the Nivenly Foundation, announced the launch of a new security fund that will pay those who responsibly disclose security vulnerabilities that affect fediverse apps and services.

While all software can have security issues, Mastodon — an open source and decentralized alternative to X — has fixed numerous bugs over the years, leading to the need for such a program. Another issue found in the fediverse is that many servers are run by independent operators who don’t necessarily have a security background or understand best practices.

Already, the Nivenly Foundation has helped a few fediverse projects set up their basic security vulnerability reporting process, and now it’s looking to distribute small payouts to anyone who responsibly discloses other security vulnerabilities that may still be in the wild.

The payouts will total $250 for vulnerabilities with a vulnerability severity score (known as CVSS) of 7.0-8.9 and $500 for more critical vulnerabilities with a CVSS score of 9.0 or greater. The funds for the payouts come from the foundation, which is supported directly by members that includes individuals as well as other trade organizations.

The vulnerabilities themselves are validated by acceptance from the fediverse project leads as well as public records in vulnerability disclosure (CVE) databases.

The fund is currently in a limited trial after the discovery of a security vulnerability in the decentralized Instagram alternative, Pixelfed. Open source contributor Emelia Smith came across the issue, and the Nivenly Foundation paid her to fix it, she explains.

The issue was complicated by the fact that Pixelfed’s creator, Daniel Supernault had made the details public before server operators had a chance to update, which would have left the fediverse vulnerable to bad actors, she says. (Supernault has already apologized publicly for his handling of the issue that had affected private accounts.)

“Part of the program is…education for project leads, helping them understand why responsible disclosure practices for security vulnerabilities are important,” Smith told TechCrunch. “We came across several projects that just said ‘file security vulnerabilities in our public issue tracker,’ which absolutely isn’t safe, as any malicious actor watching that repository would now be able to attack instances of that software,” she added.

Typically, the common practice is to disclose minimal information about a vulnerability, giving server operators time to upgrade, Smith said. However, this requires that project leads understand security best practices.

In the case of the Pixelfed issue, for instance, the Hachyderm Mastodon server, which has over 9,500 members, decided it needed to defederate (or disconnect from) other Pixelfed servers that hadn’t been updated in order to protect their users.

With this new program designed to follow best practices around the disclosure of vulnerabilities, the need to defederate to protect users may become less common.

You Might Also Like

Heavy rain threatens flash flooding for millions across much of the US

Tracking heat: Here’s where it will feel like 110 degrees

Prime Video just launched a big new Apple TV app update

New images reveal treasures aboard ‘holy grail’ shipwreck

Parasail says its fleet of on-demand GPUs is larger than Oracle’s entire cloud

Share This Article
Facebook X Copy Link Print
Share
Previous Article Anthropic launches an AI chatbot plan for colleges and universities Anthropic launches an AI chatbot plan for colleges and universities
Next Article Several Colorado students’ visas revoked at CU and CSU, universities say Several Colorado students’ visas revoked at CU and CSU, universities say

Latest News

Marcus Morris arrest: Brother Markieff confirms situation, agent claims issue stems from unpaid casino debt
Marcus Morris arrest: Brother Markieff confirms situation, agent claims issue stems from unpaid casino debt
Sports July 29, 2025
Chicago Cubs lose a franchise icon with the death of Ryne Sandberg
Chicago Cubs lose a franchise icon with the death of Ryne Sandberg
Sports July 29, 2025
Longtime Cubs star, Hall of Famer Ryne Sandberg dies after cancer battle
Longtime Cubs star, Hall of Famer Ryne Sandberg dies after cancer battle
Sports July 29, 2025
X-rays negative after Diamondbacks All-Star Eugenio Suárez gets hit on hand by a fastball
X-rays negative after Diamondbacks All-Star Eugenio Suárez gets hit on hand by a fastball
Sports July 29, 2025
//
  • About Us
  • Contact US
  • Privacy Policy
onlyTrustedInfo.comonlyTrustedInfo.com
© 2025 OnlyTrustedInfo.com . All Rights Reserved.