You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
With all the fallout today from Huntarr's "disappearance", I wanted to be very clear with everyone that MeshMonitor is a 99+% "Vibe Coded" application using Claude Code. I do my best to keep it secure and stable, but it's mainly me overseeing Claude as he works.
To try and make this clear and allay any fears of the system:
There is a new SECURITY.md file in the root of the repo covering this.
The cliffnotes of the findings are Pretty Positive.
In the Final Report, the only real finding was one of "Horizontal Authorization Bypass on Telemetry Endpoint", meaning they were able to load telemetry for a node without authentication. That's exactly how the system is configured right now, with the Info tab public for anonymous, so it's not a true findings.
There are other findings in the Authz report that discuss how permissions are not granular to specific nodes, just to broad permissions.. Which again, is exactly how the system is designed so it's not a true finding.
If people find this useful I'll try to make it a regular thing, but please note that:
I'm one guy.
I'm not a security expert, although I have a little bit of knowledge and experience in the area.
This isn't meant to be DOD level infrastructure, it's just a fun hobbyist project for a fun open-source community.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
-
With all the fallout today from Huntarr's "disappearance", I wanted to be very clear with everyone that MeshMonitor is a 99+% "Vibe Coded" application using Claude Code. I do my best to keep it secure and stable, but it's mainly me overseeing Claude as he works.
To try and make this clear and allay any fears of the system:
The cliffnotes of the findings are Pretty Positive.
If people find this useful I'll try to make it a regular thing, but please note that:
Beta Was this translation helpful? Give feedback.
All reactions