Does this passwordless future still involve getting a cookie in your browser that can be stolen and used from an attackers machine? If so, we still have a problem to fix.
Suing a journalist is not a good look. I wonder what other vendors out there will take up some market share from them after this nonsense is over. Hopefully this in the end this turns into a net positive for Krebs.
Maybe I missed it but did they cover logging all keystrokes entered by users over the bastion? (In the case where you need to log into it first vs merely doing port forwarding)
When I looked mine up I could see just about every job I’ve ever had. It also showed who pulled this report over the past 24 months. I see that my credit card companies pulled it, a background check company that my current job used, and also some random “TEST Batch Account” whatever that is.
SSN + DOB and you can find out how much money I made on my w2 for many years of my life. Nice.
I am debating on doing a ccpa delete on this data. I wonder if future employers will give me a hard time when negotiating pay if they can’t verify my salary this way? Also, will I have to delete it every time that an employer sends them this data? Awesome.
I’ve had a super old DVD player connect to the internet over an hdmi cable to my blue ray/surround sound system device that had Ethernet connected. It used the connection to patch itself, didn’t even ask if I wanted to.
If nothing else, reject stripe offers to avoid this one year grant scam. It decreases your potential upside, and saves them money, lowering your earning potential vastly. Some companies who do this argue it will protect you from downside. But you know what else does? Getting a new offer elsewhere (with signing bonus).
I have over heard that snap, lyft, coinbase, and stripe are doing one year grants. Avoid them like the plague!
So much this. It’s insanely annoying when they say something isn’t a risk and then they fix it shortly after. Google should improve this problem over new webpages.
I disagree and this was far too much writing to get your point across. Signal isn’t Facebook; they don’t have to act (or try to be) politically correct. Cellebrite deserved what they got, and if this writer understood how painful vuln reporting is they would understand why a (semi) full disclosure release works and when to use it.