this post was submitted on 02 Mar 2021
39 points (100.0% liked)

Technology

35689 readers
288 users here now

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

founded 5 years ago
MODERATORS
top 14 comments
sorted by: hot top controversial new old
[–] [email protected] 11 points 3 years ago (1 children)

The master race can't build master software.

[–] [email protected] 4 points 3 years ago (3 children)

It is a Mastodon fork, and I am still waiting to see if this apparent SQL-injection issue will also come up with regular Mastodon instances.

[–] [email protected] 10 points 3 years ago

Well at least Eugene has stated that the vulnerability doesn't seem to be related to mastodon's codebase, and that GAB wouldn't even install the security patches.

[–] [email protected] 2 points 3 years ago (2 children)

Does this also apply to postgresql? That's the default recommended for vanilla masto.

[–] [email protected] 5 points 3 years ago (2 children)

There's basically no details on the SQL injection attack, so it's hard to tell. SQL injection attacks in general can occur independent of the database, but yeah, we don't even know if it even applies to Mastodon.

[–] [email protected] 5 points 3 years ago

FWIW, some of the people involved have suggested that Gab introduced vulnerabilities while modifying the Mastodon code.

See here.

[–] [email protected] 4 points 3 years ago (1 children)
[–] [email protected] 2 points 3 years ago

Oh boy, that's a lot of hand-written SQL, and they even just commented out the old code.

[–] [email protected] 2 points 3 years ago

No idea, sorry.

[–] [email protected] 0 points 3 years ago

Most Mastodon users are pseudonymous, so in theory it shouldn't be as bad there. Probably I'm just being naive tho.

[–] [email protected] 3 points 3 years ago

Gab's CEO is NOT happy.

I repeat. Gab's CEO IS NOT HAPPY.

[–] [email protected] 2 points 3 years ago

i left gab a while ago i could not stand the lag they where going to get more servers but still

[–] [email protected] 1 points 3 years ago (1 children)

I created an account not knowing what kind of site it was, and now my email is in someone list...

[–] [email protected] 1 points 3 years ago