@CandyKitty49225@RKOtheTruth@Movie_Xtra1 Don’t even need to do that any more! If you call 999/112/911 etc on an Android or iPhone, your phone will automatically send your exact GPS coordinates to the call handler! Called Advanced Mobile Location (AML) ☺️ https://t.co/YOBuzcbZ9u
@MichelGreijmans@anurag_bhatia APT on Linux often runs with HTTP only - things stay secure as it’s often verified with GPG and hashes etc so the only real benefit to https is the privacy aspect… and for a router update that’s pretty unimportant
@weezerOSINT@zack0x01_@astrarce Yes, they were. But they weren't just *right there* in your face. You had to choose Reframe out of all the millions of apps, extract the IPA and go digging through the files to actually find them.
Don't get me wrong - Reframe royally screwed up here! But our job as security(1/2)
@weezerOSINT@zack0x01_@astrarce In those few hours though, you don't know what happened with the keys you exposed.
Before you publicised it, only you knew those keys were there to be found. Sure, they were there but people wouldn't think to look.
Afterwards though? More than enough time to download everything.
@weezerOSINT@zack0x01_@astrarce There are a lot of other ways to reach out to companies for something like this - and in this case, you have to consider the ultimate outcome and harm you could cause to vulnerable people.
It doesn't matter if it takes a year for them to respond.
@weezerOSINT@zack0x01_@astrarce appreciate where you're coming from ("it needs to be fixed asap to protect people"), but other people wouldn't have known this was an issue had you not posted about it (and would likely not have found it).
you've likely caused actual harm to people by publicising this; be careful
@weezerOSINT@zack0x01_@astrarce > i emailed them april 7
that is not a reasonable timeframe for responsible disclosure. 30 days at minimum!
and you told people exactly where to find it (even down to the file in the IPA!) so the fact that you blocked out the personal data/API key doesn't matter.
@ThiccumsNickums@oatmilkin idk, when a killer actively chooses to target one particular player thats pretty shitty.
say they’re chasing two survivors and the survivors fork off in two directions, then the killer stays chasing the one they’ve already hooked twice rather than the one they haven’t at all yet
@PokeRaidApp The Gigantamax Charizard’s white belly makes the text impossible for pokeraid to read 😭 although, using the X app’s text feature I got it to work hahaha