GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by ret2bed is hacking web apps :verified: (ret2bed@infosec.exchange)

  1. Embed this notice
    ret2bed is hacking web apps :verified: (ret2bed@infosec.exchange)'s status on Thursday, 04-Jan-2024 06:24:01 JST ret2bed is hacking web apps :verified: ret2bed is hacking web apps :verified:
    in reply to
    • feld
    • jomo
    • Lorenzo Franceschi-Bicchierai

    @feld @jomo @lorenzofb what do you mean? It states that your ancestry reports as well as additional information "including genetic variants related to health" are shared with genetic relatives if you enable the related feature.

    How even the most basic ancestry information can be used in the wrong hands is not that hard to imagine.

    https://www.wired.com/story/23andme-credential-stuffing-data-stolen/

    And I would think the fact that it states only genetic relatives receive this kind of data would be enough to reassure users that the data was reasonably safe.

    Again imo access to that feature should have been restricted to user accounts with a certain minimum level of security, including 2FA.

    In conversation Thursday, 04-Jan-2024 06:24:01 JST from infosec.exchange permalink
  2. Embed this notice
    ret2bed is hacking web apps :verified: (ret2bed@infosec.exchange)'s status on Thursday, 04-Jan-2024 05:06:31 JST ret2bed is hacking web apps :verified: ret2bed is hacking web apps :verified:
    in reply to
    • feld
    • jomo
    • Lorenzo Franceschi-Bicchierai

    @feld @jomo @lorenzofb I disagree. Maybe if the data of the affected user was the only data available when logging into an account but they have broken into a bunch of accounts and then stole further data from genetic matches iirc.

    Not preventing that kind of data theft when one of the parties did not have 2fa enabled is hardly the fault of the user but completely on the platform. This should not have been possible for accounts that don't have basic 2FA enabled.

    In conversation Thursday, 04-Jan-2024 05:06:31 JST from infosec.exchange permalink
  3. Embed this notice
    ret2bed is hacking web apps :verified: (ret2bed@infosec.exchange)'s status on Thursday, 23-Mar-2023 22:38:23 JST ret2bed is hacking web apps :verified: ret2bed is hacking web apps :verified:
    in reply to
    • Technology Connections

    @TechConnectify I've long been complaining about the missing creativity of hackers these days. Everything is now a crypto scam. Why can't we have nice defacements and the occasional Max Headroom incident anymore?

    In conversation Thursday, 23-Mar-2023 22:38:23 JST from infosec.exchange permalink

User actions

    ret2bed is hacking web apps :verified:

    ret2bed is hacking web apps :verified:

    Bug Hunter ? | Sharing leet vulns & tricks | Doing Security Research and Hacking | #kaeferjaeger | only followed by cool people ✌️

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          109227
          Member since
          23 Mar 2023
          Notices
          3
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.