The reading comprehension on this one was so bad that I still laugh
https://bsky.app/profile/hackthedev.bsky.social/post/3mf3xkld6vs2z
The reading comprehension on this one was so bad that I still laugh
https://bsky.app/profile/hackthedev.bsky.social/post/3mf3xkld6vs2z
Some of their other posts, for context, since blocking breaks the threads:
They made two more replies:
So I said: https://bsky.app/profile/soatok.bsky.social/post/3mf3tap3utk2g
And then they posted that, then blocked me.
Of course, they also said this to someone else who criticized the app they're spamming everywhere: https://bsky.app/profile/hackthedev.bsky.social/post/3mezoxedp3k2f
There's a lot of people trying to self-promote in the wake of the Discord ID verification news.
@soatok yeah, but you're just trying to be a drama person :drgn_blep:
@malachai clearly
@soatok@furry.engineer I started looking into their app and immediately ran into this pre-compiled EXE that's vendored into the source tree. It has an included readme, but the wording is... odd, to say the least.
@hazelnoot electron moment
@soatok@furry.engineer eyyy and it's also got the exact same CSS injection vuln I reported in Misskey last year :neofox_laugh_tears:
@hazelnoot rofl
@soatok@furry.engineer I'm 99% sure there's at least one XSS vuln in here, since the client seems to use innerHTML all over the place
@soatok@furry.engineer yep, just found one :neofox_woozy:
@soatok@furry.engineer preliminary audit report:Do not use this.
Fin.
@soatok@furry.engineer one-click arbitrary HTML injection with no CSP
@gimmechocolate @soatok BITE EM BITE EM BITE EM!!!!! :dragnyellcowboy:
@soatok
Bite em!!!!
@hazelnoot I don't interpret your thread as dunking on them for being a novice, but for being an asshole lol
@soatok@furry.engineer ok since I don't want to bash on someone who's probably a novice developer trying their best, I want to applaud them for working so hard on this. They've clearly put in a lot of effort and I don't see any signs of AI slop. This project certainly could become something in the future, but right now it should remain a personal learning project. It's just not ready for production use.
@soatok @hazelnoot this is when I love @hailey.at’s Bluesky labeler…
@hazelnoot This is totally unsurprising. It kind of sucks to see though: Promoting their own thing so hard but not listening to any criticism that could make them more secure. Oh well.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.