Software with crosshairs on its back practicing garbage security practices will be pwnd the same regardless of it’s open-ness.
Honestly. With a lot of the tools out there these days. I question if it’s even faster to hunt security bugs by reading the source rather than just attempting common exploits via tooling.
I'm not really convinced by Postgres either, software like that inherently exposes very little attack surface unless the attackers already have access. Nobody is interested in exploiting Postgres.
https://www.theverge.com/2019/7/12/20691957/mastodon-decentr...
ofc there is that whole discussion about whether open sourcing actually affects application security, having your security model assume that attackers already have access to the source code, etc. Not to mention it looks like they did make quite extensive modifications on top of the mastodon code. Some of the code that people have discovered lying around in the gab codebase is really embarrassing.
For instance, in this case a group with sufficient security research skills politically opposed to some of the gab users seem to have utilized the source-code to find a vulnerability the Gab team had not discovered yet.