Co-Founder @ Hashbang,
Infra @manifestcyber // formerly @turnkeyhq, @spekitapp and @BitGo
PGP: 0xC92FE5A3FBD58DD3EC5AA26BB10116B8193F2DBD
Thoughts are my own
.@OryCorp, IDK how you expect a customer to reach out to you for support besides openly on the internet when you gate both your support page and slack to authenticated users. If only my issue wasn't around authentication🙃
#TapToPay on $sui with native secure element and tee support and multisig. Strongbox backed petty cash wallet for super quick transactions. Haven't decided if I should publish it anywhere 🤔 QR based backup and maybe give iOS a shot. Too bad that won't be able to support Tap 🤡
The White House App has OneSignal's full GPS pipeline compiled in, polling your location every 4.5 minutes, syncing your exact coordinates to a third party server.
> be cow
> cow, but online
> IoT? IoC
> Internet of Cow
> no security
> cows compromised
> cow botnet
> use cows for ddos attacks
> critical infrastructure taken down by cows
> hijack cow sensor
> tell cows to attack at dawn
> open front door
> 1000 cows pooping outside house
Another reminder as to why politicians should not be allowed to trade while in office. Serve your constituents, not your wallet @DWStweets
https://t.co/sCFyipVMQU
Show your ID to protect kids
Show your ID to protect kid
Show your ID to protect ki
Show your ID to protect k
Show your ID to protect
Show your ID to protec
Show your ID to prote
Show your ID to prot
Show your ID to pro
Show your ID to pr
Show your ID to p
Show your ID to
Show your ID t
Show your ID
Show your I
Show your
Show you
Show yo
Show y
Show
Sho
Sh
S
Su
Suc
Suck
Suck m
Suck my
Suck my b
Suck my ba
Suck my bal
Suck my ball
Suck my balls
Suck my balls P
Suck my balls Pa
Suck my balls Pal
Suck my balls Pala
Suck my balls Palan
Suck my balls Palant
Suck my balls Palanti
Suck my balls Palantir
Some time ago our team discovered the MilkSad vulnerability.
One of our colleagues carries on the torch and has continued research in this area which can be found at https://t.co/K3n1Xv3SwL.
Here is the CCC presentation the team did last year: https://t.co/0hg3STxLMp
‼️ China's biggest cybersecurity company, Qihoo 360 (461M users), just leaked their own wildcard SSL private key inside the public installer for their new AI assistant "360 Security Claw."
The private key for *.myclaw.360.cn was bundled directly in the download package under /namiclaw/components/OpenClaw/openclaw.7z/credentials. The cert is valid until April 2027.
Attackers can now impersonate their servers, intercept user traffic, and forge login pages.
Fun fact: the founder promised the product would "never leak passwords."
Members of public office must been barred from participating in the stock market while in office. You're service is to the people, not your wallet
https://t.co/mXILZqq6sN
Broadcasters that are running hoaxes and news distortions - also known as the fake news - have a chance now to correct course before their license renewals come up.
The law is clear. Broadcasters must operate in the public interest, and they will lose their licenses if they do not.
And frankly, changing course is in their own business interests since trust in legacy media has now fallen to an all time low of just 9% and are ratings disasters.
The American people have subsidized broadcasters to the tune of billions of dollars by providing free access to the nation’s airwaves.
It is very important to bring trust back into media, which has earned itself the label of fake news.
When a political candidate is able to win a landslide election victory after in the face of hoaxes and distortions, there is something very wrong. It means the public has lost faith and confidence in the media. And we can’t allow that to happen.
Time for change!
In the latest example of the set of Zcash contributors rapidly expanding and decentralizing, some new (to me) folks have shown up with a new (to me) full-source bootstrapped reproducible toolchain called StageX and are hardening major components.
Especially crucial as supply chain attacks ramp up!
The recent npm supply chain attacks are a wake-up call for how vulnerable the software ecosystem remains.
This isn’t just about reacting to one incident. It’s about rethinking how we build trust and security into the software supply chain.
https://t.co/dN2yerikzT
@UPS Reminder, not everyone can get packages delivered to their homes. Not giving someone an alternative pick-up option when they don't have a choice in provider is ridiculous
My dear dear friends at @UPS once again showed up to my post office and denied delivery of a package. I can't always control which provider companies use to ship me things. But I've been systematically calling providers and asking them to blacklist using @UPS for my orders.