Andrew Torba / Gab (Gab.com / Gab.ai) / Dissenter (dissenter.com) - An incompetent captain sinking millions of other people's dollars.

Screenshot_2021-02-21 Disclose tv 🚨 on Twitter.png

Repeating myself on Fediverse:
Interesting. I'm aware Gab.com was a fork of Mastodon, but itself was also FOSS. I wonder if Torba introduced vulnerabilities, or if Mastodon itself is vulnerable?

Edit: I've been informed by the fediverse it was a Gab-specific XSS exploit related to rich text.
 
Last edited:
Why? is MFC using pleroma?
Yeah, you can talk to their cam girls on it if you pay for a membership. Their instance is non-federating though, for obvious reasons.

I've been informed by the fediverse it was a Gab-specific XSS exploit related to rich text.
It was the Trends image proxy, not rich text. But yeah, it was going around for a few days, and I know they knew about it. For some reason they just neglected to do anything beforehand.
 
Not really big but nothing else is going on. I think Gab is testing out some primitive automated moderation atm. Not for suspensions, but certain posts with potential spam content won't go through.

They're also rate limiting some stuff, poorly. It's like new Reddit account levels of bad.

There's no communication on this btw, it just shoots you a default error message, they're trying to be sneaky about it but some degree of automation is the only thing I can figure that makes sense for why some things consistently don't work correctly atm.
 
  • Informative
Reactions: Shaka Brah
So @Null said in this clip from 2019 that Gab is hosted in the Netherlands. Is that still true?
 
Last edited:
So @Null said in this clip from 2019 that Gab is hosted in the Netherlands. Is that still true?
I don't know if that's still true. Torba is erratic and does shit at fucking random constantly. He also deletes his Twitter out of shame and that's where most of his correspondence is done.
 
So @Null said in this clip from 2019 that Gab is hosted in the Netherlands. Is that still true?

I don't know if that's still true. Torba is erratic and does shit at fucking random constantly. He also deletes his Twitter out of shame and that's where most of his correspondence is done.
In September, Andy announced that Gab was able to build and ship their own servers. https://news.gab.com/2020/09/30/gab-just-became-resilient-in-a-big-way/

 
Today, Torba made a blog post to respond to an alleged breach of Gab user data.

Blog / Archive

Alleged Data Breach – 26 February 2021​

1614385486014.png



Today we received an inquiry from reporters about an alleged data breach. We have searched high and low for chatter on the breach on the Internet and can find nothing. We can only presume the reporters, who write for a publication that has written many hit pieces on Gab in the past, are in direct contact with the hacker and are essentially assisting the hacker in his efforts to smear our business and hurt you, our users.

The reporter, without providing us with any evidence of the breach or assistance to identify its veracity, alleged that an archive of Gab public posts, private posts, user profiles, hashed passwords for users, DMs, and plaintext passwords for groups have been leaked via a SQL injection attack. We were aware of a vulnerability in this area and patched it last week. We are also proceeding to undertake a full security audit.

We do not currently have independent confirmation that such a breach has actually taken place and are investigating. Much of this information (in particular Gab public posts and public user profiles) is already public.

It is standard practice for passwords to be hashed. If the alleged breach has taken place as described, your passwords have not been revealed. For groups, where passwords are meant to be shared for users to join with, we do not encrypt this information as is noted in our group creation interface. DMs were only live for a few weeks and are not currently a feature supported by the site, so if a breach has in fact occurred in that domain we expect the number of affected accounts to be low.

Gab collects very little from our users in terms of personal information. It is entirely possible for a user of the site to be unidentifiable based on the information they provide at login.
We do not collect health or financial information; we do not collect dates of birth; we do not collect social security numbers; we do not collect telephone numbers; we do not track user searches, queries or browsing history; we do not check who owns an e-mail address before setting up an account (and, in this instance, we have no indication that e-mail addresses were compromised).

Every major tech company – from Facebook to Twitter – has been the target of multiple and continued data breaches. We collect very little personal data so that, in the event of a data breach, the effect on our users will be minimized. As we learn more about this alleged breach, we will notify the community publicly with our findings as required by law.

Andrew Torba
CEO, Gab.com
Jesus is King

TLDR - Torba presumes that reporters are working with hackers to smear Gab. In response, Torba admits having patched a vulnerability and is still working on a full security audit. He then rambles on about how Gab user data is worthless compared to users of Facebook or Twitter.

It makes me wonder if there has been a new data breach or not. :thinking:
 
  • Informative
Reactions: Ged'sForth
Today, Torba made a blog post to respond to an alleged breach of Gab user data.

Blog / Archive

Alleged Data Breach – 26 February 2021​

View attachment 1953301


Today we received an inquiry from reporters about an alleged data breach. We have searched high and low for chatter on the breach on the Internet and can find nothing. We can only presume the reporters, who write for a publication that has written many hit pieces on Gab in the past, are in direct contact with the hacker and are essentially assisting the hacker in his efforts to smear our business and hurt you, our users.

The reporter, without providing us with any evidence of the breach or assistance to identify its veracity, alleged that an archive of Gab public posts, private posts, user profiles, hashed passwords for users, DMs, and plaintext passwords for groups have been leaked via a SQL injection attack. We were aware of a vulnerability in this area and patched it last week. We are also proceeding to undertake a full security audit.

We do not currently have independent confirmation that such a breach has actually taken place and are investigating. Much of this information (in particular Gab public posts and public user profiles) is already public.

It is standard practice for passwords to be hashed. If the alleged breach has taken place as described, your passwords have not been revealed. For groups, where passwords are meant to be shared for users to join with, we do not encrypt this information as is noted in our group creation interface. DMs were only live for a few weeks and are not currently a feature supported by the site, so if a breach has in fact occurred in that domain we expect the number of affected accounts to be low.

Gab collects very little from our users in terms of personal information. It is entirely possible for a user of the site to be unidentifiable based on the information they provide at login.
We do not collect health or financial information; we do not collect dates of birth; we do not collect social security numbers; we do not collect telephone numbers; we do not track user searches, queries or browsing history; we do not check who owns an e-mail address before setting up an account (and, in this instance, we have no indication that e-mail addresses were compromised).

Every major tech company – from Facebook to Twitter – has been the target of multiple and continued data breaches. We collect very little personal data so that, in the event of a data breach, the effect on our users will be minimized. As we learn more about this alleged breach, we will notify the community publicly with our findings as required by law.

Andrew Torba
CEO, Gab.com
Jesus is King

TLDR - Torba presumes that reporters are working with hackers to smear Gab. In response, Torba admits having patched a vulnerability and is still working on a full security audit. He then rambles on about how Gab user data is worthless compared to users of Facebook or Twitter.

It makes me wonder if there has been a new data breach or not. :thinking:
Emma Best of DDoSecrets claims to have the data, and plans on releasing it.
https://twitter.com/NatSecGeek/status/1365412813657812997
 
Blab has been simping hard for Strike. Is that a crypto exchange or something? I don't know anything about it.

I'm guessing this is what they're using for their Marketplace.
 
Libtards -including one potential lolcow (Kirtaner) teased a Gab breach. It was also mentioned in Shareblue hack group DDoSecrets.

Blab appeared to be offline for a while (about 30 seconds) until Torba was able to round up his IT trained honeybees
 

Attachments

  • D7E0AF88-4CAE-45CB-85C6-10656F64D987.jpeg
    D7E0AF88-4CAE-45CB-85C6-10656F64D987.jpeg
    523.8 KB · Views: 68
  • Thunk-Provoking
Reactions: Shaka Brah
So @Null said in this clip from 2019 that Gab is hosted in the Netherlands. Is that still true?
No, they self host everything on their own hardware in the US.

Emma Best of DDoSecrets claims to have the data, and plans on releasing it.
https://twitter.com/NatSecGeek/status/1365412813657812997
Probably a nothingburger, but it'll be funny if they got anything important. Most likely the only non-public thing will be group passwords.
 
Last edited:
No, they self host everything on their own hardware in the US.


Probably a nothingburger, but it'll be funny if they got anything important. Most likely the only non-public thing will be group passwords.
Email addresses will prob be the worst thing that will leak. But I would assume that most people on Gab use an email address that wouldn't expose their true identity anyways.

Torba is somewhat right when he says Gab collects relatively little personal information. It doesn't require Phone Number & ID like Parler.
 
Last edited:
Libtards -including one potential lolcow (Kirtaner) teased a Gab breach. It was also mentioned in Shareblue hack group DDoSecrets.

Blab appeared to be offline for a while (about 30 seconds) until Torba was able to round up his IT trained honeybees

Email addresses will prob be the worst thing that will leak. But I would assume that most people on Gab use an email address that wouldn't expose their true identity anyways.

Torba is somewhat right when he says Gab collects relatively little personal information. It doesn't require Phone Number & ID like Parler.
So they're after more cancellations. What else is new?
 
I have no doubt that Gab has shit security, but any stolen info probaby just consists of username/password/emails. Really no big deal for the end user unless you were retarded enough to sign up to Gab with your main email or a username/password you use elsewhere. Still, it's further evidence that Gab is not worth using, if you for some reason needed any more.
 
I have no doubt that Gab has shit security, but any stolen info probaby just consists of username/password/emails. Really no big deal for the end user unless you were retarded enough to sign up to Gab with your main email or a username/password you use elsewhere. Still, it's further evidence that Gab is not worth using, if you for some reason needed any more.
I mean, whatever wave Gab was riding has died out. Now, these raids on security are just leftists going after the MAGA crowd in an attempt to eradicate the Trump menace once and for all.
 
  • Agree
Reactions: Shaka Brah
Back