Mikael Thalen Profile picture
Feb 20, 2022 12 tweets 7 min read Read on X
SCOOP: Tried the Truth Social beta.

But not the one Trump & his fans are testing, the one used internally by his team, which left the site publicly accessible online (again).

Registered @realDonaldTrump & found a user praising dictator Augusto Pinochet dailydot.com/debug/truth-so…
Again, this is not the mobile beta being discussed online but the internal beta that TMTG's dev team uses to find bugs before updating the app.

Found the page online in Oct. & was tipped by @WhiskeyNeon that a verification page for registrations was open. dailydot.com/debug/truth-so…
The dev team didn't disable the handle @realDonaldTrump, which Trump is currently using on the mobile app.

I was able to upload the same profile image & banner as Trump. To be clear, this would not affect Trump's account on the mobile beta.

dailydot.com/debug/truth-so…
I found all sorts of content openly posted to the publicly accessible internal beta.

Pics from devs that showed usernames & passwords as well as other identifying info (which I will obviously not be publishing).

Raises serious security questions.

dailydot.com/debug/truth-so…
I also found several moderation accounts that were used to teach Truth Social's systems how to flag banned content such as porn, images from execution videos, and racial slurs.

Interestingly, the system was also being trained how to spot pics of firearms. dailydot.com/debug/truth-so…
Another account posted memes & statements praising Chilean dictator Augusto Pinochet.

It's unclear if the account was run by a moderator attempting to teach Truth Social's systems to flag such imagery or merely a fan page from someone at TMTG.

dailydot.com/debug/truth-so…
As you may remember, after Trump announced his plans for Truth Social in Oct., a site hosting the mobile beta was quickly found. Myself as well as @drewharwell were able to register accounts for Trump & Pence.

Devs on the internal beta weren't impressed. dailydot.com/debug/truth-so…
As reported by Reuters, the Truth Social app will possibly be released tomorrow.

As of writing this thread, I’ve lost access to my account. But excited try out the app tomorrow if it does drop!

reuters.com/world/us/exclu…
Another interesting point. A moderator, whose job is to train Truth Social's systems to recognize banned content, shared posts about Jan. 6.

Does this mean TMTG is opposed to the Capitol riot or that it won't allow users to rally for similar events? dailydot.com/debug/truth-so…
Apple has begun sending out emails and notifications alerting users that Truth Social is available for download.

Once downloaded on the App Store, users are informed that Truth Social is “coming soon.”
Truth Social can now be downloaded from the Apple App Store but attempting to register an account produces an error message.
For the record, Truth Social only pulled down one domain for the internal beta site that I was able to register an account on last night.

Another domain still remains (which I won't be publishing), which shows that the site is ready for launch.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Mikael Thalen

Mikael Thalen Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @MikaelThalen

Jan 19, 2023
NEW: The federal No Fly List was exposed on an open server discovered by a security researcher last week.

The list, which was being stored by the US airline CommuteAir, contained over 1.5 million rows of data including names, aliases, & birth dates. dailydot.com/debug/no-fly-l…
The server, discovered by hacker @_nyancrimew, was secured prior to publication.

CommuteAir says the list was a version from 2019.

The Daily Dot was able to find numerous high-profile figures including the recently-freed Russian arms dealer Viktor Bout & at least 16 aliases.
The infrastructure, described by CommuteAir as a development server, also contained the names, addresses, phone numbers & passport numbers of over 900 CommuteAir staff including pilots & crew.

CommuteAir says an initial investigation shows that no customer data was exposed.
Read 5 tweets
Dec 16, 2022
After banning @elonjet, which he said he wouldn’t, Musk has now banned @joinmastodon after it tweeted that users could follow the jet-tracking account on their platform.
It appears Washington Post journalist @drewharwell was suspended as well for pointing out that Mastodon was suspended for promoting ElonJet, which I also just did in the above tweet.
New York Times journalist Ryan Mac has now been suspended for merely mentioning Musk’s suspension of Mastodon and ElonJet.
Read 12 tweets
Oct 28, 2022
A blog run by David Depape, the Berkley man accused of attacking Paul Pelosi with a hammer, has articles titled 'Hitler did nothing wrong,' 'Black pilled,' and 'Pedophile normalization.' Image
Correction: 'Hitlery' was autocorrected to 'Hitler.'

The specific blog post in question is referring to former Secretary of State Hillary Clinton.
Read 6 tweets
Oct 28, 2022
A fake statement from Donald Trump congratulating Elon Musk on his acquisition of Twitter is spreading online.

The fabricated quote claims Trump's account will be reinstated Monday & that the ex-president is "Happy to be able to engage with an African-American owned business." twitter.com/i/web/status/1…
It appears the Independent briefly ran with the false claim but has since changed the article's headline.

The incorrect article has already been aggregated by Yahoo News.

webcache.googleusercontent.com/search?q=cache…
Read 4 tweets
Jul 25, 2022
NEW: An anti-vaccine dating website that allows users to donate “mRNA FREE” semen left its users’ personal data exposed online.

dailydot.com/debug/anti-vax…
The site that was leaking user data, known as 'Unjected,' is similar in design to Twitter but is often referred to as the “Tinder for anti-vaxxers.”

Users can advertise their 'mRNA FREE' blood, sperm, or eggs to one another.
dailydot.com/debug/anti-vax…
Security researcher @GeopJr1312 discovered that Unjected's web application framework had been left in debug mode.

From there they were able to find the private email addresses for the site's roughly 3,500 members.

dailydot.com/debug/anti-vax…
Read 6 tweets
Feb 28, 2022
NEW: Despite the significant uptick of hacking & leaking amid Russia's invasion of Ukraine, every single method offered by WikiLeaks to submit them documents is broken.

Every submission option featured by WikiLeaks leads to broken sites & errors.

dailydot.com/debug/submitti…
On WikiLeaks submission page, users are asked to visit their onion service on the dark web to securely provide them leaks...

Yet their server isn't even online. dailydot.com/debug/submitti…
WikiLeaks also offers a clearnet webchat where users can be assisted in accessing the tor network in order to securely provide them with leaks.

Yet the domain is 502. dailydot.com/debug/submitti…
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(