"Traitor packages up a bunch of methods to exploit local misconfigurations and vulnerabilities (including most of GTFOBins) in order to pop a root shell."


Together with the Internet Society, we have written an open letter to the EU to explain why an encryption backdoor for the 'good guys only' is simply impossible. Keep fighting for a secure internet with us! 💪👇

What is it that makes logout's with and token revocation such a minefield? Are logout's deprecated?

Die Tickets zum #rC3 werden für den Logged-In-Bereich benötigt: Interaktionen zwischen den Teilnehmenden, Workshops, Entdecken der Assemblies-Flächen und ein paar Überraschungen events.ccc.de/2020/12/03/rc3-t

SSOs gave me so many identity crisis this year. Always sign any and message completely.

Conviced them to use authorization code flow with pkce instead.

Why would anybody use Resource Owner Password Credential Grant with Basic Auth in a mobile app developed in 2020?

Hello Fosstodon, I'm alcastronic. OpenSource user and fulltime hacker. Doing pentests and forensics. Found one or two bugs in OpenSource projects and hope to be of help fixing such.

