Der Kipppunkt für Boreale Wälder wurde ursprünglich bei 3C angesetzt, dann auf 1,5C vorgezogen. Jetzt sehen wir sie bei 1,2-1,3C in großem Stil abbrennen. Regel bestätigt: im Klimanotstand kommt fast alles früher & heftiger als angenommen, nicht umgekehrt https://t.co/t6KOzSj7tb
A Korean developer released an open source app called "Pixel IMS" that enables VoLTE (and with version 1.1.2, VoWiFi) on select Pixel devices in "unsupported" regions. Best part? It DOESN'T REQUIRE ROOT.
https://t.co/ak261C2Cyo
Smartphones für Kids unterm Weihnachtsbaum? Achtung bei Kinderschutz-Apps - Forscher von @sec_consult haben da bei allen getesteten Modellen Lücken gefunden. https://t.co/yVfAWPQ5Gp
Here is our long-term review and proof-of-concept by @divercinety on #privacy issues in @EufyOfficial security cams since 2020. Reconsidering your #blackfriday shopping plans? As @Paul_Reviews puts it: These cams are only "supposedly private". https://t.co/H3fk4sXySc
Here is our long-term review and proof-of-concept by @divercinety on #privacy issues in @EufyOfficial security cams since 2020. Reconsidering your #blackfriday shopping plans? As @Paul_Reviews puts it: These cams are only "supposedly private". https://t.co/H3fk4sXySc
@Paul_Reviews@EufyOfficial Stay tuned for our upcoming blog post on this topic which confirms that security got strengthened over the past two years but EufyCam is still leaking data to the cloud #Homebase
I found a vulnerability that allowed me to unlock any @Google Pixel phone without knowing the passcode. This may be my most impactful bug so far.
Google fixed the issue in the November 5, 2022 security patch. Update your devices!
https://t.co/LUwSvEMF3w
@sus_ond Falls es ein Android Gerät ist, kannst du einfach eine Tastatur und Maus über USB anschließen und damit dann den PIN eingeben. Danach die Datenübertragung aktivieren in der Benachrichtigungsleiste und per USB mit Computer verbinden.
Meine Mama, 72, hat seit Jahrzehnten einen @A1Telekom-Handyvertrag. Sie hat 12.000 Mobilpoints, bezahlt 50€ im Monat, will ein neues Handy und einen niedrigeren Tarif. Ein Thread.
@zornsllama @tobycmurray SameSite was set to Lax for the cookies and would have prevented it, but changing the request method to GET moving all the params to the URL, still bypasses this
@zornsllama @tobycmurray Can't disclose anything specific unfortunately. I just recently found this CSRF vulnerability where you were able to perform critical actions via a POST request that didn't require a CSRF token.
@suka_hiroaki I guess it actually really isn't legal under the GDPR. From my understanding you would need to get permission from every single contact in your address book before using WhatsApp & similar apps.
We're now 2 yrs into the decisive decade. Emissions should be in an unprecedented fall, instead we're seeing the 2nd biggest rise ever recorded. We're wasting invaluable time pretending we can solve this crisis without treating it like a crisis. World leaders are still in denial.
@Stadt_Wien + ein ziviler First Responder via Lebensretter-App sprintet auch dort hin. Patient wurde zum Glück wieder bei Bewusstsein und stehend angetroffen! :)
So I tried out the Android 12 Beta and just hope that this won't make it into the final build. 😵💫 There is a good reason why <marquee> is deprecated. @Android
Personal experience: Broken access control is the #1 critical vulnerability that I found during the last few months of pentesting all kinds of web-apps.
I am amazed everytime when I simply change an ID in the URL from 999 to 998 and it just gives me other people's data. :)