Rust dev, I enjoy reading and playing games, I also usually like to spend time with friends.

You can reach me on mastodon @[email protected] or telegram @sukhmel@tg

  • 0 Posts
  • 155 Comments
Joined 3 years ago
cake
Cake day: July 3rd, 2023

help-circle
  • In O’Reilly’s Clawdbot research, he identified hundreds of exposed control panels reachable over the public internet, some lacking any authentication. These interfaces provided access to full conversation histories, API keys, OAuth tokens, and command execution features across services including Slack, Telegram, Discord, WhatsApp, and Signal. In several instances, Signal device-pairing data was stored in plaintext, enabling attackers to take over accounts remotely.

    Sounds like people can set it up on their own in any OS, but I admit that I didn’t exactly understand what that control panels are






  • When you log into Windows with a Microsoft account, your recovery key is often automatically uploaded to Microsoft’s servers as a backup in case you forget your password. Legally, this means Microsoft owns the key and must surrender it under the U.S. CLOUD Act.

    Experts like Matt Green of Johns Hopkins University warn that, unlike Apple or Google, Microsoft does not encrypt these keys in a way that makes them unreadable even to the company itself. The result is a fundamental breach of data sovereignty