I heard allot of buzz around the security issues with diaspora, can someone summarize what they were?
They've since patched many of them, but really the whole project was a mess of nearly every web-based security exploit in the book. Here's a quick rundown of the problems from day one of their alpha code release:
/image/123/delete/
to delete an image of their own (whose ID happened to be 123), they could just manually type in the URL /image/1/delete/
to delete the image with an ID of 1, even if that image wasn't their's.If you're curious about the technical details, feel free to educate yourself.