@seahorse
114M

The master race can’t build master software.

poVoq
44M

It is a Mastodon fork, and I am still waiting to see if this apparent SQL-injection issue will also come up with regular Mastodon instances.

@lorabe
104M

Well at least Eugene has stated that the vulnerability doesn’t seem to be related to mastodon’s codebase, and that GAB wouldn’t even install the security patches.

Does this also apply to postgresql? That’s the default recommended for vanilla masto.

Ephera
54M

There’s basically no details on the SQL injection attack, so it’s hard to tell. SQL injection attacks in general can occur independent of the database, but yeah, we don’t even know if it even applies to Mastodon.

FWIW, some of the people involved have suggested that Gab introduced vulnerabilities while modifying the Mastodon code.

See here.

Ephera
24M

Oh boy, that’s a lot of hand-written SQL, and they even just commented out the old code.

poVoq
24M

No idea, sorry.

@someone
04M

Most Mastodon users are pseudonymous, so in theory it shouldn’t be as bad there. Probably I’m just being naive tho.

@lorabe
34M

Gab’s CEO is NOT happy.

I repeat. Gab’s CEO IS NOT HAPPY.

i left gab a while ago i could not stand the lag they where going to get more servers but still

I created an account not knowing what kind of site it was, and now my email is in someone list…

QuentinCallaghan
creator
14M

Same.

Subscribe to see more stories about technology on your homepage


  • 0 users online
  • 8 users / day
  • 35 users / week
  • 127 users / month
  • 455 users / 6 months
  • 2830 subscribers
  • 1226 Posts
  • 3000 Comments
  • Modlog