Mikail Tunç

1.3K posts

Mikail Tunç

Mikail Tunç

@emtunc

I do security things

London, England Katılım Ocak 2017
1.2K Takip Edilen249 Takipçiler
Sabitlenmiş Tweet
Mikail Tunç
Mikail Tunç@emtunc·
Today I am open-sourcing SlackPirate, a tool I developed over the last couple weeks. It's designed to run under a given Workspace token and enumerate + extract sensitive/interesting/confidential data for easy offline viewing - github.com/emtunc/SlackPi…
English
1
8
20
0
Mikail Tunç
Mikail Tunç@emtunc·
@habazzi Let me know if you'd like any pro-bono cyber security advice/consultancy. My DMs are open.
English
0
0
2
11
Hassan Bazzi
Hassan Bazzi@habazzi·
bowelbuddy.app For more info on what I’m building :) Now more motivated than ever to do more with less.
English
8
14
99
16.8K
Hassan Bazzi
Hassan Bazzi@habazzi·
I’ve decided to pull out my application to @ycombinator. I’ve been working silently on a new startup that I think will help millions in the world that struggle with Irritable Bowel Syndrome. It’s been so difficult to make progress given the ongoing genocide in Palestine, and stupid for raising money from organizations that have allowed this to continue. @paulbiggar ‘s brave and needed blog post earlier today was the small push I needed to look elsewhere. If I am to raise, it’ll be “human-aware” money.
English
45
149
923
176.6K
Mikail Tunç
Mikail Tunç@emtunc·
@MishaalRahman you or someone you know might have a clue what's going on here - I share links from Chrome all the time but this is the first time the sharing link (ft dot com) is different from the actual URL of the page. Link to the Ars article in pic: arstechnica.com/security/2023/…
Mikail Tunç tweet media
English
1
0
2
136
Mikail Tunç
Mikail Tunç@emtunc·
@NahamSec @TomNomNom question for y'all - what bug bounty platform are you finding most security-researcher friendly these days? I know a lot of it comes down to the program but the platform as a whole, triage team, etc make a big impact too.
English
1
0
0
37
Mikail Tunç
Mikail Tunç@emtunc·
@MalwareJake Wait until you check out Alfred. It's even snappier and more flexible in terms of config and what "things" are searched and indexed.
English
0
0
0
414
Jake Williams
Jake Williams@MalwareJake·
After using Finder on Mac, Windows Explorer feels prehistoric. I will never understand how it's acceptable in 2023 to fail to find a file in Explorer by typing part of the filename. I should not be wondering "do I go to the shell and ls |grep -i, or is the file just not here?"
English
37
17
471
61.1K
Matt Johansen
Matt Johansen@mattjay·
I heard about a company that is making a "Wall of SHAME" - On it? Team members who fail 3 times in phishing simulations. Let me hear your thoughts on this one.
English
258
24
227
304.2K
Mikail Tunç
Mikail Tunç@emtunc·
@AlecMuffett This "test" uses FaceTec behind the scenes. I have no doubt FaceTec use the imgs & biometrics to train their algs. Also, your phone will immediately start uploading images to their (FaceTec) servers *as soon as* you've given camera permissions before any scans take place!
English
0
0
0
50
Alec Muffett
Alec Muffett@AlecMuffett·
DIGITALLY FINGERPRINT YOUR FACE, FOR THE SAKE OF THE CHILDREN!!! WHAT COULD POSSIBLY GO WRONG??!?
English
4
10
24
3.8K
BSides London
BSides London@BSidesLondon·
For no specific reason ('cough, cough'), but today would be a great time to sign up to our mailing list✅ securitybsides.org.uk/contact.html If you're in, or going to be in Las Vegas at summer camp, please remember to drink lots of water and take care of one another! #BSidesLDN2023
GIF
English
1
8
19
2.6K
Mikail Tunç
Mikail Tunç@emtunc·
@peterfox One reason is to determine authentication policies for the user as different groups of users may have diff policies assigned to them. e.g., userA belongs to a group that is enabled for passwordless logons so a password field for that group isn’t appropriate
English
0
0
1
107
Peter Fox
Peter Fox@peterfox·
Apps that have two steps with the username and password on a separate screen. Why?
GIF
English
69
14
382
149K
Mikail Tunç
Mikail Tunç@emtunc·
@troyhunt Didn’t the Silk Road guy end up getting caught because he was logged in to Skype over Tor?
English
0
0
2
305
Troy Hunt
Troy Hunt@troyhunt·
I’m thinking of writing something up about people who’ve been caught by simple opsec fails. What other ones are there? DPR’s Stack Overflow post, Ubiquiti hacker’s VPN dropping etc. What other noteworthy examples are there?-
Gold Coast, Queensland 🇦🇺 English
15
5
83
40.3K
Mikail Tunç
Mikail Tunç@emtunc·
@Burp_Suite I think 2023.1.2 breaks WebAuthn/security keys in Chromium. They work again for me when I roll back to .1 You can test on webauthn.io to see if it returns an error or not.
English
1
0
0
42
Mikail Tunç
Mikail Tunç@emtunc·
@CircleCI When will audit logs be programmatically available? Q1? Q2?
English
0
0
0
158
CircleCI
CircleCI@CircleCI·
CircleCI Security Alert | Since our last update we have also released a tool for discovering all your secrets on CircleCI. Use it to find an actionable list of items for rotation github.com/CircleCI-Publi… Additionally, we have made Self-Serve Audit Logs available to all customers.
CircleCI tweet media
CircleCI@CircleCI

6 Jan. 2023 Update | #CircleCI Security Alert [4 Jan. 2023] In our ongoing effort to help customers safeguard their data & systems, today's update includes updated instructions for secrets rotation, answers to your most frequently asked questions & more: circleci.com/blog/january-4…

English
3
8
19
9.9K
CircleCI
CircleCI@CircleCI·
@emtunc Perhaps indeed, Mikail 🤔 Perhaps we're in agreement with you about audit log availability, and perhaps we were to have something in the works at this very moment... Stay tuned!
English
1
0
1
1K
CircleCI
CircleCI@CircleCI·
CircleCI Security Alert [4 Jan. 2023] We strongly recommend all CircleCI customers rotate secrets stored on our system. Read more: circleci.com/blog/january-4…
CircleCI tweet media
English
16
558
577
407.4K
Mikail Tunç
Mikail Tunç@emtunc·
@brianwhelton If you're into the home automation space or think you might be in the future then it's probably worth checking which have the best integration with home automation platforms like Home Assistant, etc
English
1
0
1
25