@TransIP Ik zie dat jullie een phishingswaarschuwing in het controlepanel laten zien, met de aanbeveling 2FA in te stellen. TOTP 2FA codes zijn ook gewoon phishbaar (en dat is gebeurd in grote hacks; zie NPM), dus zijn er plannen om FIDO2 / webauthn / etc te ondersteunen?
Hmm, when adding a new hardware key to my X account months later, it gives me the same recovery key as before? You guys store that in plain text? @XComms@X.
@obvionhypotheek Ik kreeg die melding inderdaad nog na het weekend, vlak voordat ik het meldde hier op X. Maar, nu lijkt het verholpen. Ik kan weer inloggen.
Hallo @obvionhypotheek. De Mijn Obvion is al een tijdje niet operationeel. Momenteel krijg een HTTP 500 error (internal server error / "Er is iets niet goed gegaan!") bij login op de URL: https://t.co/YHaOPGUis5
Hello @Transport_CBR Is it possible to change the train check-in system to show a different note when checking in vs checking out? Now it both says 'accepted', and this can get confusing if you forget or don't see whether you did it correctly (like when in a hurry):
Hey @evilsocket nice work on the find. So far, the snap package of cups, installed with Chromium, is ignored, fix wise. I created a bug report: https://t.co/pRiq1NABEx. Just, FYI.
@ServicesGovAU The mygov platform has a bug that prevents removing an old 2FA device. Under the hood it says 'Grant for this device does not exist.' but the website doesn't register this and goes in circles. Check the logs for an attempt at 'Mon 2024-Sep-23 18:40:15 AEST'
Hi @myGovau. Can you tell your software developers about the inability to remove 2FA devices from mygov? The website says it worked, but under the hood it says: {"httpStatusCode":"400","message":"Grant for this device does not exist."}. Also see https://t.co/6tRxX3z965
@myGovau the 2FA device configuration is buggy and devices can't be removed. Can you contact the software developers, have them scan the logs for and fix "'{"httpStatusCode":"400","message":"Grant for this device does not exist."}' error? Also see: https://t.co/6tRxX3z965
About Terrapin SSH vulnerbility @TrueSkrillor @lambdafu@JoergSchwenk . You say that client and server need strict key exchange support to be safe? But a MITM will always claim it doesn't support it? So the answer to "I patched my SSH client/server, am I safe now" is always no?
@krakensupport Alright done. As I said in the DM, the link goes to https://t.co/nEmEtoRtGu and e-mail DKIM is valid, but sending people e-mail to verify their account is kind of like training people to fall for phishing. If anything, the e-mail should not have included links.
Hey @krakenfx , you seem to be sending 'verify my account' e-mails? The only thing that makes this not look like phishing is the domain it's going to, but it's an extremely dodgy e-mail. Can you confirm? @krakensupport
Hey @SamsungMobile are you going to address CVE-2023-4863 (#WebP exploit, critical) in older phones like the S10? Without it, it's now a brick. #android.
@GoogleAds I only ever paid pre-paid and now I got an e-mail saying my account was cancelled with an open balance of $0.89. I am not going to pay for bugs in your transaction handling.
Hey @delta. Would it be possible for you to offer a vegan/plant based meal as one of the alternatives? Some options may already be, but the choices of 'dairy free', 'vegetarian' etc, are ambiguous.
@Fortinet Can you update your Debian/Ubuntu VPN download instructions to not make me trust your GPG key globally? This format is insecure. The proper way is a 'signed-by' stanza in the sources.list. BTW don't use the system /etc/apt/sources.list, but rather a .d dir.
@SeatGeek what with this 'mobile only' events that you have to use the app on your phone for? If you're abroad and don't have internet roaming, you can't do that. Why do you no longer just send the QR code in e-mail?