@molly0xfff@hachyderm.io
@molly0xfff@hachyderm.io avatar

molly0xfff

@molly0xfff@hachyderm.io

crypto researcher & critic, software engineer, wikipedian • https://indieweb.social/@web3isgreat creator • subscribe to my newsletter at http://citationneeded.news/
she/her • :QueerCat_Bisexual:

This profile is from a federated server and may be incomplete. Browse more on the original instance.

molly0xfff, to random
@molly0xfff@hachyderm.io avatar

"Establishing that AI training requires a copyright license will not stop AI from being used to erode the wages and working conditions of creative workers. ... Our path to better working conditions lies through organizing and striking, not through helping our bosses sue other giant multinational corporations for the right to bleed us out." –
@pluralistic

https://pluralistic.net/2024/06/21/off-the-menu/

molly0xfff, to random
@molly0xfff@hachyderm.io avatar

back in my day we called this spyware

molly0xfff, to random
@molly0xfff@hachyderm.io avatar

twitter not paying whitehats. what could go wrong?

this one recently disclosed a vulnerability that would have allowed people to gain control of the twitter accounts of users who merely clicked malicious links

Chaofan Shou @shoucccc 10h And we got the full JS exploit to chain with this XSS vulnerability! In another word, visiting this link earlier today would take over your account: Chaofan Shou @shoucccc 10h It is highly irresponsible for Twitter to ignore these security issues and not pay the whitehats. The architecture and design patterns also need to be corrected.
x_austin X (Formerly Twitter) staff closed the report and changed the status to Resolved. Updated 6 hours ago X (Formerly Twitter) has decided that this report is not eligible for a bounty. 6 hours ago No award due to program ban
rabbit @rabbit_2333 I submitted this bug report and didn't receive a bounty. You told me that this bug has existed for a year. Seeing that you haven't fixed it for so long, it seems that this bug is not important, so I made it public. Screenshot of conversation from HackerOne: x_austin X (Formerly Twitter) staff posted a comment. a minute ago @rabbit2333 why are you publicly disclosing security issues instead of submitting them to our bug bounty program? Would you mind deleting this post? This is something we're aware of and are addressing. Image F2918855: image.png 26.90 KIB

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • Hentai
  • doujinshi
  • announcements
  • general
  • All magazines