We found a way to access Max Verstappen's passport, driver's license, and personal information. Along with every other @Formula1 driver's sensitive data.
It took us 10 minutes using one simple security flaw 🧵
In April, @samwcyo and I discovered a way to bypass airport security via SQL injection in a database of crewmembers. Unfortunately, DHS ghosted us after we disclosed the issue, and the TSA attempted to cover up what we found.
Here is our writeup:
https://t.co/g9orwwgoxt
Security researchers found flaws in Saflok hotel keycard locks, used on 3 million doors in 13,000 properties worldwide, that can be used to open them in seconds. The lockmaker Dormakaba has been working on a fix but told them only 36% of locks are updated. https://t.co/lvjbC7NvxQ
How does one use iCloud for only passkeys along with @1Password? Can’t disable iCloud passwords to only use passkeys and can’t disable passkeys on 1Password makes both experiences terrible. Anyone found a good solution?
The iPhone Dev Team domain iphwn.org expired a few months ago, and two weeks ago was acquired by someone for $1,260 USD at an auction.
The domain now hosts a broken wiki archive, seems to be grabbed from archive.org. Whois indicates the owner is in Illinois.
Who owns this?