Today I am open-sourcing SlackPirate, a tool I developed over the last couple weeks. It's designed to run under a given Workspace token and enumerate + extract sensitive/interesting/confidential data for easy offline viewing - https://t.co/YGRAskePsn
@MishaalRahman you or someone you know might have a clue what's going on here - I share links from Chrome all the time but this is the first time the sharing link (ft dot com) is different from the actual URL of the page. Link to the Ars article in pic:
https://t.co/YogFyNMcJf
@NahamSec@TomNomNom question for y'all - what bug bounty platform are you finding most security-researcher friendly these days? I know a lot of it comes down to the program but the platform as a whole, triage team, etc make a big impact too.
@AlecMuffett This "test" uses FaceTec behind the scenes. I have no doubt FaceTec use the imgs & biometrics to train their algs. Also, your phone will immediately start uploading images to their (FaceTec) servers *as soon as* you've given camera permissions before any scans take place!
@peterfox One reason is to determine authentication policies for the user as different groups of users may have diff policies assigned to them. e.g., userA belongs to a group that is enabled for passwordless logons so a password field for that group isn’t appropriate
@Burp_Suite I think 2023.1.2 breaks WebAuthn/security keys in Chromium. They work again for me when I roll back to .1
You can test on https://t.co/1VMOwSGGYl to see if it returns an error or not.
@CircleCI I see the audit log docs have been updated which is an improvement https://t.co/EGNHuVFLTv
Are there plans to allow programmatic access to the logs so we can send them to a SIEM?
@brianwhelton If you're into the home automation space or think you might be in the future then it's probably worth checking which have the best integration with home automation platforms like Home Assistant, etc