"mastodon vulnerability", clarification
the vulnerability that's making the rounds is only applicable to glitch-soc. it does not affect mainline mastodon
it only affects you as a user if you are using a password manager that automatically fills your password without any action on your part. and if you have 2FA off
here's the link, which states all of those things https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
Twitter apocalypse
I've seen a lot of people talking what-ifs of, with the new owner firing people at random and unplugging things without first finding out what they do, we might have a major event where Twitter goes down completely for days or something.
But what I haven't seen as much thought about is, what if during this same chaotic period, there is a major security incident? What makes that possibility alarming is *if it happens, we might never know about it*.
Twitter apocalypse
Twitter is high-profile enough that its threat model is not just "somebody publishes an exploit and teenagers wreak havoc for a day or two". Twitter is used by activists, journalists and governments, and the threat model includes "a nation-state penetrates the intranet and hijacks a legitimate employee's credentials". What worries me is a targeted attack, say, scraping a bunch of DMs by local dissidents, who all get mysteriously arrested in two weeks. Chaos makes that easier.
@KitRedgrave that place is falling apart
php has gender constants and wow those sure are genders https://www.php.net/manual/en/class.gender.php
An European rabbit kitten (yes, that's how baby rabbits are called!) licking a plant.
#wildlife #photography #naturephotography
@bunny_jane designed not to stall
Transitioning in mid-life
alt: @confusedcharlot@kolektiva.social
https://confusedcharlotte.tumblr.com
http://quietcarlota.tumblr.com (backup)
https://www.pillowfort.io/charlotte
confusedcharlotte#1650
confusedcharlot@twitter
#nobot