Interesting vulnerability / disclosure / fallout thread, starting with this yesterday:
Seems that @ms__chief signed up to @joinagiggle (account since protected) which is a women only app. It involves a gender identification process which, apparently, is bypassable:
More significantly, the app contained filters that were trivial to tamper with thus pulling troves of data on other subscribers per the write up done by @DI_Security: research.digitalinterruption.com/2020/09/10/gig…
So far another day on the internet, it’s the disclosure process which @k8em0 summarised well:
In true Streisand style, this has now led to legal threats against @JayHarris_Sec
Read through those threads and form your own opinions, but obviously this has gotten pretty “terse”. IMHO, number one priority here should always be protecting the people using the service and it feels like amongst all the bickering, that has taken a back seat. Comments?
Share this Scrolly Tale with your friends.
A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.
