PSA i can spoof any email and it will pass all DKIM/SPF/etc. checks. here's an email i sent to myself pretending to be a famous MIT-affiliated podcaster - thanks gmail for auto-inserting the profile pic :)
MIT may fix this someday but in the meantime beware that it's trivial for any account to send mail as any other account!
i discovered this because i received a VERY convincing phishing email sent from "me". it turns out the attacker compromised another acct and was using it to send email as arbitrary users. that acct has been reported and
no idea how many other legacy SMTP setups have the same issue but it's easy to detect in this case; just inspect the email headers and check if the "authenticated as" user is the same as the address in the "from" field.
in january 2023, i had a simple ultrasound done at SimonMed. they sent me 4 bills totaling $5137 for it.
after a year of emails and phone calls, they finally admitted today that i only owed $140.53 and are mailing me a refund check!
here's how i did it 🧵
2/ the first bill they sent was for $484.92, which i paid promptly. a few months later they sent a bill for $3378.69! i contacted my insurance and they sent me an updated EOB saying i only owed an additional $140.53.
3/ i emailed simonmed and attached the EOB. they said they would look into it. shortly after i got a new bill for $140.53 in the mail which i paid.
then i noticed the 484.92 amount wasn't counted in my insurance deductible so i contacted my insurance asking why
my friend sophie got fired from her job at Facebook and turned down a $64,000 severance package in order to leak this, so u better read it.…
my biggest takeaway from this article is that FB could be doing a lot more to prevent politically-motivated bot activity, but they choose not to because they don't see any immediate revenue or PR benefit from doing so.
clarification: in order to leak this *internally* at Facebook
why is it not common knowledge that u can make perfect japanese-style croissants from scratch with like 20min of effort?? thx @MimeeXu for enlightening me
(recipe in thread👇)
1/ mix 400g bread flour & 6g salt
microwave 240g milk for 30s
dissolve 8g dry yeast in it
add 50g honey
add 40g softened butter
mix together
mix wet mix into dry mix to form a well-combined dough
cover and rest overnight in fridge
2/ 1. form 12 balls of dough 2. roll each dough as shown below, wrapping a piece of butter and pinch of salt at the center of each roll 3. lay rolls on parchment paper and rest for 40min in a slightly warm place (ex: warming drawer of oven, or an oven with the light on)
1/ in this thread i'll summarize some differences between SameSite=Lax (Chrome's new proposed default policy; see… for more technical details) and third party cookie blocking (Brave's default policy unless user turns it off for a site)
2/ SameSite=Lax is more strict than 3p cookie blocking in the sense that it also blocks requests using unsafe HTTP methods. For instance if X contains a form that POSTs to Y, cookies to Y would be blocked by SameSite=Lax but not most 3p cookie block implementations AFAIK
3/ SameSite=Lax is less strict than 3p cookie blocking in the sense that a site can override it with SameSite=None. But unless a site does that, both SameSite=Lax and 3p cookie blocking will block 3rd party cookies on subresource requests.