![ππ¬πππππͺπβ°ππ¦πβΌ Profile](https://pbs.twimg.com/profile_images/968732433192488960/hbU8r08F_x96.jpg)
ππ¬πππππͺπβ°ππ¦πβΌ
@mcmahoniel
Followers
267
Following
502
Statuses
2K
@[email protected] // #infosec // #research // #bugbounty // ViBndWJodHVnIGp1bmcgVidxIHFiIGpuZiwgVidxIGNlcmdyYXEgViBqbmYgYmFyIGJzIGd1YmZyIHFybnMtemhncmYu
::1
Joined March 2007
iβm a big fan of #1password but anything that leaks private information from your vault should be an opt in. even worse, the icons themselves werenβt encrypted until recently (the linked support article still says they arenβt). so local access also leaks vault data.
0
0
0
want to use totp #twofactorauthentication on @Twitch? you must attach a phone number to your account and consent to receiving phone calls and texts from twitch. don't trust twitch and want to remove your phone number after you set it up? you'll lose totp 2fa. π
0
0
0
interesting caveats for #apple #visionpro / #visionOS 1.0.* international early adopters hoping to buy in the #us (from : it only supports us english, requires a us apple id, and zeiss will not accept optical prescriptions from non-us opticians (βΌοΈ).
0
0
0
a third #phishing tweet just got posted, not even going to waste my time with a screenshot this time. how is this account still around? cc/ @steam_support
round 2! same tweet, new url. old tweet deleted. #phishing sites now behind @cloudflare. same functionality: <url>/invite works, redirs to a single char substitution. all others throw a fake 404 page, including dev tools. new #twitter #x #verification enables credential theft.
0
0
0
@NahamSec looks like rapid7 has gotten into the brand protection game: π hopefully it wonβt take long for them to realize this is a false positive, but i suspect weβll see this from more companies in the future.
0
0
8
round 2! same tweet, new url. old tweet deleted. #phishing sites now behind @cloudflare. same functionality: <url>/invite works, redirs to a single char substitution. all others throw a fake 404 page, including dev tools. new #twitter #x #verification enables credential theft.
"verified" account β
linking to #steam account #phishing page β
algorithmically recommended to me β
clearly the system works. #twitter #x #xitter
0
0
0
@maldr0id i also had this happen. i didn't have to update my profile but it looks like i was flagged for being on number of new networks/in a new region.
0
0
1
.@newrelic is being acquired by private equity. 5 months ago, they wrote a blog post warning @sumologic users that they can't trust the company/product after it was acquired... by the same pe firm. π€£ unsurprisingly, said blog post has now been scrubbed.
4
74
338
blocking single-use/disposable credit cards is a dark pattern. β οΈ #discord doesn't allow single-use cards for #discordnitro, doesn't facilitate one-time payments, and auto-renews without warning when your free trial/month/year subscription is up.
0
0
0