They didn't even bother to change the word "toot" on #TruthSocial in the Dutch language

Yes, he did not "build" TruthSocial but took #Mastodon source code and added anoher front end

The current source code is from 2022 meaning that they don't comply with the Mastodon licence OR they run a old version that has critical security flaws

Talk about a major fail..

Ryan Baumann (@[email protected])

I don't know who needs to hear this but #TruthSocial, which is running a forked version of Mastodon, does not from the source code appear to have appropriate mitigations in place for CVE-2023-36460, which theoretically allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution https://nvd.nist.gov/vuln/detail/CVE-2023-36460 (probably other CVE's as well, but some rely on federation which Truth Social doesn't use?) #infosec

digipres.club
@stux I’m surprised yet absolutely not at the same time haha

@stux I don't know why it does this, but if I tell it to open the png in a new tab, it turns into a gif.

https://truthsocial.com/oops.gif

@stux ok, it's supposed to be a gif from the beginning but I got a png the first time. The internet frightens and confuses me.

@stux lol, it's literally just a mastodon instance

does it even federate?

@stux @hexaheximal no - and/or, every other instance blocks it.
@stux Just tried to go to that link using a VPN and Cloudflare blocked me. Either they're using it to block VPNs, or they don't want anyone accessing that link. Same happened with robots dot txt.
@stux Also this OR isn't exclusive, in fact I'd doubt the server stayed unmodified since 2022 given the change of frontend, while not being and up-to-date mastodon server wouldn't surprise me at all.
@stux Those critical security flaws could be an invitation for some.

@stux
And why do you protest??
It is excellent news! They are going to the market now.

If you guys go to the court, there's a HUGE amount of money waiting for you-all

@pthenq1 Because the safety of a loot of people is still at stake

In the past there was contact with the Trump Media group because they didn't published the code at first

It's not about the money

@stux

I understand and respectfully think that money is very very important.

@stux @pthenq1 forget about safety: if they're lying about the licensing of the technology, that's already an SEC problem. if i were the Mastodon Foundation, i would totally ask US/EU lawfedi for pro-bono advice on this. Mastodon might end up with a lumpsum... or TS's stock might drop to pennies faster than it usually does with anything involving Trump. either way, win/win.

@blogdiva @stux @pthenq1 They posted the source code here: https://help.truthsocial.com/legal/open-source/

So, they at least think they’re abiding by the license, but I doubt the SEC cares about whether they’re abiding by an open source license.

Since Mastodon is licensed under the AGPLv3, any changes made to the source of a service using it must also be released under the same terms, and it doesn’t appear they’ve done that, so @Gargron would need to sue.

@blogdiva @stux @pthenq1 @Gargron What’s interesting is that Eugen may not even need to bring the suit. The community might be able to do it, which I think is what happened with @conservancy in the Vizio case.

@stux @pthenq1

understandable, but if you're enough of a dipshit to have your stuff on such a horrendously insecure platform, then you're gonna do a lot of unpitiable Finding Out

@stux A lawsuit could affect that evaluation...
@stux do you plan to block that instance ? 
@rafuru No need, it does not federate 😉
@stux I would say that "major fail" is an apt description of TFG, but that might imply that he actually served in the military....
@stux wait...is that legal? I recognise I'm asking this and I'm a god damn tech lawyer but that should be indicative of my shock and horror!
@bermudianbrit @stux I expect nothing less from anything TFG-related.
@stux Major security flaws, you say.... 😉

@stux

Security flaws?

Anonymous, and you still binge watching Lost? Care to come up for air, and a bit of fuckery?

@stux Would be a shame if someone were to take advantage of the unpatched nature of the code based on what we know of recent patches.
@stux What's funny is that Truth Social is just a Mastodon fork with Alex Gleason's SoapBox frontend grafted back on.

SoapBox itself is a fork of Mastodon's own native single-column interface. Apparently, the dev couldn't get them to use anything other than Mastodon, which is pretty funny.
Truth Social Head of Engineering Leaves for Jack-Dorsey-Backed Alternative, Nostr

Alex Gleason (30), founder of Soapbox Technology, announced his resignation on Monday as Head of Engineering at Truth Social, the Twitter-alternative...

Yahoo Finance

@atomicpoet @deadsuperhero Wow.. can't image Nostr would wanna work with such a racist

With Trump he fitted right in though

Is Nostr also some alt right platform?

@stux @deadsuperhero By itself, Nostr is just a simple protocol that works through relays.

In practice, almost all content there is about Bitcoin, various conspiracy theories, and AI spam.

The reason people gravitate towards Nostr is because they’re under the illusion that Nostr can’t be censored. This isn’t the case, however. Relays can be moderated and they are.

@atomicpoet @deadsuperhero Ahhh that's it!  Yup, that's Alex..

He came from Gab I believe before the Fedi thing, also explains a lot

@stux @deadsuperhero What I think is even more interesting is that Jack Dorsey deliberately gave Alex Gleason a grant so he would work on Nostr.

Thus, anyone who says that Jack Dorsey is a better person than Elon Musk is just plain wrong.

@atomicpoet @stux @deadsuperhero

Thank you.

This is a horrifically ignored, but important point.