Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Etesync removal (at least tell to user to be wary and check it themselve) #731

Closed
BirdInFire opened this issue Mar 17, 2022 · 10 comments
Closed
Labels
c:software self-hosted/decentralized software and related topics t:correction content corrections or errors

Comments

@BirdInFire
Copy link

BirdInFire commented Mar 17, 2022

Description

Etesync isn't updated anymore, i tried to ask them but they close the issue as fast as possible and restrict any answer from me, and even listing the number of update they haven't done (with countaine hight to low security issue, only have pushed them to close and tell i mislead user (without any proof of course),

but the fact that their server app and ios app isn't updated for more than a year remain, so you musn't lead user to their fall with an unsecure services.

URL of affected page: https://www.privacyguides.org/software/calendar-contacts/

proof of their intentional lie :
etesync/server@056d685

witch correct what i have reported (there is another security issue but not in the django library) and they haven't corrected it.

and their git page you can see nearly all repo aren't updated for month (year in the worst case) : https://github.com/etesync

@ph00lt0
Copy link
Contributor

ph00lt0 commented Mar 17, 2022

Perhaps you didn't read the reply you have gotten: etesync/server#122 (comment)

@BirdInFire
Copy link
Author

Perhaps you didn't read the reply you have gotten: etesync/server#122 (comment)

yeah but why tell i misslead user by telling there are vulnérable library who isn't updated, and try to shut me ?

instead of just list them to update them later ?

@BirdInFire
Copy link
Author

BirdInFire commented Mar 17, 2022

it's not the fact they do not it imedatly, it the fact they say is not true, update it and block me from report all the security issue i have found out.

Edit because if it's false why have they updated it after my report ?

@ph00lt0
Copy link
Contributor

ph00lt0 commented Mar 17, 2022

Sometimes things can be vulnerable but in the way that they are used not have any effect. It's better practice to keep things updated, but from what I am reading the developer gives good arguments.

@BirdInFire
Copy link
Author

Sometimes things can be vulnerable but in the way that they are used not have any effect. It's better practice to keep things updated, but from what I am reading the developer gives good arguments.

True but again why tell i lie, and block me (without even checking all their library update just in case ?
Their reaction isn't normal at all.

@BirdInFire
Copy link
Author

Sometimes things can be vulnerable but in the way that they are used not have any effect. It's better practice to keep things updated, but from what I am reading the developer gives good arguments.

And for an app who use crypto library who have a shitload of security update every month, a year without update isn't normal, and if they tell that none of their library had update i can safely tell they lie.

@BirdInFire BirdInFire changed the title Etesync removal Etesync removal edit : or at least tell to user to be wary and check it themselve Mar 17, 2022
@BirdInFire BirdInFire changed the title Etesync removal edit : or at least tell to user to be wary and check it themselve Etesync removal (at least tell to user to be wary and check it themselve) Mar 17, 2022
@BirdInFire
Copy link
Author

BirdInFire commented Mar 17, 2022

@ph00lt0 But at least add a warning to check because: not updated = be carful, their strange reaction to my report (update and block, carful x 2.

I do not say they are breached uninstall it imedatly i just say user must be warned that something is strange.

Edit : I Wanted to install it, and like always i have done an healthy check (updates time and so on) i report this to be sure all it secure before using it and i have the impression you all see my like the bad guy who want to close them....

Is that strange that a concerned future user want them to be secure as much as possible ?

@victor-rds
Copy link

@ph00lt0 There are more responses on etesync/server#123

While I do agree the lack of update is concerning, I have reported issues in the past because new versions of python, I also think is valid to report it here, the tone was complete unnecessary, no need to open issues like "Not updated, not secured, nightmare !! update your library !!!!" and " hiding youself behind it's work from decade blabla" in a open- source project Stop using it and report, no need for drama.

@BirdInFire
Copy link
Author

BirdInFire commented Mar 17, 2022

@ph00lt0 There are more responses on etesync/server#123

While I do agree the lack of update is concerning, I have reported issues in the past because new versions of python, I also think is valid to report it here, the tone was complete unnecessary, no need to open issues like "Not updated, not secured, nightmare !! update your library !!!!" and " hiding youself behind it's work from decade blabla" in a open- source project Stop using it and report, no need for drama.

its very true and it was my fault for that and i had excused and modified it myself if they wasn't closing and of course blocking me nearly immediately.

Edit : again if i had reported it it was for use it myself, but they just ignored and closed, and when i'm more harsh they silently update it... so yeah will never use it and report it here to at least have a warning (directed to admin who want to self host to check themselve).

Edit 2: now i will stop respond for this matter and will just create a module to my own server software (witch i do not publish and only use for myself on my own network (for transparency since some can tell i wan to take their place) just wanted to host them subscript to release tag ans forget to not recreate the wheel)

@victor-rds
Copy link

@BirdInFire I do understand both of you in this case, although the block was too fast for my taste, I do understand that in bad day I too would block out of rage.

Good luck mate!

@dngray dngray closed this as completed Mar 18, 2022
@dngray dngray added c:software self-hosted/decentralized software and related topics t:correction content corrections or errors labels Mar 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c:software self-hosted/decentralized software and related topics t:correction content corrections or errors
Projects
None yet
Development

No branches or pull requests

4 participants