A couple of weeks back I found a possible exploit in the Polygon Miden VM internals. Today a friend of mine managed to turn it into an actual exploit.

github.com/0xPolygonMiden/mide

It seemed appropriate (and somewhat funnier) to convey the result first to the team in the form of an actual zero-knowledge proof before we set to fixing it.

@pee_zombie If I click through from the "useless middle page" to their server to see their profile, I can't add them there, because that page isn't on this server and I'm not logged in on whatever other server they are on, so I have to bail out of there after checking that yep I know them and/or that they are a real person I might care to interact with, and then I can add them back on the "useless middle page" or I can add them by clicking on the + back in the notification page.

@pee_zombie I think I understand the 'why' of it all, but clicking to a local profile, then going down to the bottom to click on their remote profile, which opens in a new window, closing that window, then going backwards to add is just the sort of bad design-by-committee UX I was fearing coming over here to try this out.

I wonder if I can't skip the local page and new window for the remote one with a scriptmonkey or chrome script of some sort, as that middle page is positively useless.

@ciphergoth So far it is, sadly, almost exactly what I expected.

Fortunately, the chief twit seems to have finally realized _quite_ how unpopular the no-outbound-links policy was and didn't immediately double down on it, like Freenode did during its own alt-right implosion, so I'm not forced to spend all my time here, but yeesh.

Is it just me or is the fact that the click-through link for someone's profile that you get when notified that someone has followed you on Mastodon leads to some useless page that doesn't show _any_ of their posts, requiring yet another hop off some link on the bottom of the page incredibly frustrating UX?

"Oh look, 50 new followers! 250+ clicks to see if i should follow them back or if they are just going for volume! (2 forward, 2 back, 1 to add) 50x."

Twitter: 1 to profile, 1 to add, 1 back

Mastodon

a Schelling point for those who seek one