lefty155🌻

2.5K posts

lefty155🌻

lefty155🌻

@lefty155

Just another leftist (most of the time) He/him

Katılım Ocak 2021
164 Takip Edilen26 Takipçiler
Sabitlenmiş Tweet
lefty155🌻
lefty155🌻@lefty155·
I am quote tweeting this, so that I can make it my pinned tweet
English
0
0
0
0
lefty155🌻
lefty155🌻@lefty155·
@Future_proof7 @ICPsimp @jonahseguin Because that provides literally no protection if the developer's API keys are compromised? Specific versions of packages on NPM are also immutable (well unless NPM themselves get compromised, but then we have bigger problems)
English
1
0
0
21
Space-Bar
Space-Bar@Future_proof7·
@lefty155 @ICPsimp @jonahseguin I feel like that should just be standard anyway Great if you’ve pinned the correct package, but even worse if malware Why would you not want packages hosted by something that’s tamperproof, auditable and cryptographically verifiable? Seems like a no brainer
English
1
0
0
21
jonah
jonah@jonahseguin·
Can someone please explain to me why we are still waiting until AFTER a package is published and distributed to take action? Why doesn’t npm scan packages with Socket or similar before allowing them to be distributed?
Socket@SocketSecurity

🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io. Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems. TrapDoor targets #crypto, #DeFi, AI, and security developers, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, env vars, and API keys. Socket detected releases with a median detection time of 5 minutes, 27 seconds. The fastest detection occurred 58 seconds after publication.

English
36
37
943
141.9K
vx-underground
vx-underground@vxunderground·
Big shenanigans on social media. The big question is now, who owns content? The answer: whoever can watermark first or best X employee Big Nick (that's what everyone calls him) goes schizo on some dork with a bunch of followers. Big Nick asserts big account steals content from little account no one has heard of. However, it turns out little account (operating under a VPN, wink wink), yt-dlp's content from TikTok, YouTube, Instagram, etc. and adds his own watermark on top of it. Big Nick, seemingly aware of this, acknowledges this theft of content but will award small account for "bringing it to the platform" and "add his watermark". Chaos has ensued because big account has been actively aggregating slop to X (formally Twitter) since 2014 and has 4M followers, BUT HAS NOT been watermarking it. The new guy has been actively aggregating slop (but adding his own watermark!) since 2020 and has 20,000 followers. tldr bring content to platform (yt-dlp someone's stuff), add watermark, complain someone without watermark stole it, take their ad revenue Chat, it's the great slop wars of 2026
vx-underground tweet media
English
30
33
464
16.2K
ICPsimp ☁️∞
ICPsimp ☁️∞@ICPsimp·
Can someone explain why we're still not talking about using the Internet Computer Protocol to fix these attack surfaces? Instead of relying on the centralized npm registries that get compromised through maintainer accounts or supply chain worms, you could host immutable, tamper-proof packages directly on ICP canisters. The code and data run inside the protocol itself. Which is protected by math, replicated across independent nodes, with no traditional server for attackers to target. You could even layer on something like Orbit.global for secure, multi-approval key management and access control. That removes the centralized points of failure, insecure endpoints, and single points of compromise that keep biting us. The tech exists. Why aren't we leveraging it for something this critical? Or at least talking about it. I mean the attackers, like TeamPCP, are even leveraging the tech to orchestrate a lot of these attacks.
English
2
6
14
531
Arakay
Arakay@funnyaralyn86·
is yt dlp fucekd
Arakay tweet media
English
1
0
1
54
lefty155🌻
lefty155🌻@lefty155·
@Snakesan @IntCyberDigest The website was supposed to show, it wants you to follow the instructions so you install malware And yes, the website is cursed. I think it got hacked, that’s why it’s currently down
English
1
0
0
12
Snakesan
Snakesan@Snakesan·
I just want to know the signals that kept it from popping. Can't be some local resource collision, this was meant to not show for a reason l. I'm used to seeing circumvention, this is just new to me. Hope to read a writeup over this one. I'd assume the entire based apparel site is cursed.
English
1
0
0
36
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 BREAKING: Kash Patel's apparel website is reportedly hosting ClickFix malware, according to multiple visitors. A fake Cloudflare verification page is tricking users into pasting OS-specific "verification" commands that execute malware. The macOS path fetches an infostealer targeting Keychain, browser data, session tokens, and crypto wallets. Source: @dm4uz3
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
76
421
2.4K
532.9K
lefty155🌻
lefty155🌻@lefty155·
@old_ass_nerd @0hour1 "gun in banner" and refers to people as "it". No wonder @old_ass_nerd refuses to believe that a website telling them to open the terminal and run a command is malware
English
0
0
6
47
Old Ass Nerd 🇺🇸
Old Ass Nerd 🇺🇸@old_ass_nerd·
@0hour1 "23" followed by "please be over 16"... no wonder it's concerned about an "infostealer"
English
2
0
2
1.5K
lefty155🌻
lefty155🌻@lefty155·
@Snakesan @IntCyberDigest Its a fake Cloudflare gate. Cloudflare never ask you to open terminal and run a command that's literal malware Meaning Kash Patel's website must have been hacked (and has potentially been fixed now)
English
2
0
4
95
Snakesan
Snakesan@Snakesan·
@IntCyberDigest If you attempt to navigate to this on windows with a clean useragent showing macos it won't pass through the cloudflare gate. This usually doesn't happen. Interested to hear why this happens.
English
1
1
7
2.7K
lefty155🌻
lefty155🌻@lefty155·
@sensibleman88 Any captcha that tells you to open a terminal is malware. Google "ClickFix" if you don't believe me
English
0
0
2
53
lefty155🌻
lefty155🌻@lefty155·
@PaulChr30241052 @MartinLZinn @MyLordBebo I think Grok is designed to analyse the user's tweets and imitate their political views. Which is terrible, because its basically a personal echo chamber that always tells you you're correct I think its echoing back the views of ProLeataria (whose tweet its translating)
English
0
0
0
2
Lord Bebo
Lord Bebo@MyLordBebo·
🇮🇱 Grok wildly translates a question about Israel. Bro wrote in German: “What’s your position on Israel’s right of existence?” Grok answered instead of translating. Wild. Probably some hard-coded rules on Israel worked too strongly and overrode the command to translate. 1/
English
69
370
5.1K
222.9K
Roman Weisman
Roman Weisman@RWeisman15348·
@mullvadnet Thanks for sharing - so the current design assigns an exit address based on a key which is generated on login to the Mullvad app. While logged in, switching to another VPN, doesn’t re-generate the key, which leads to similar exit address? How the browser knows it’s the same user?
English
1
0
8
6.5K
Mullvad.net
Mullvad.net@mullvadnet·
On Friday the 15th of May, we became aware of a fingerprinting issue affecting Mullvad users. We have a method which changes this behaviour currently being tested, with plans to begin rolling it out to our VPN servers in the coming weeks. Read more here: mullvad.net/blog/exit-ip-f…
English
26
199
2.2K
125.8K
lefty155🌻
lefty155🌻@lefty155·
@KrondstadtBaker @ElliotMalin Correct, the genocide was carried out by the Committee of Union and Progress, which was the most powerful organisation within the Young Turks movement You may wanna check out google.com, I find it answers my questions much faster than if I asked them on Twitter
English
0
0
0
26
Raskolnikov
Raskolnikov@KrondstadtBaker·
@ElliotMalin 'the group' So a 'group' called 'The Young Turks' did it?
English
1
0
0
254
Pinky
Pinky@cubfan13·
@rowanfornow They were naming movie titles, not black people. You twit.
English
1
0
1
5.2K
lefty155🌻
lefty155🌻@lefty155·
@stupidtechtakes @mxdabz I think your IPv6 IP address does (although websites that know what they're doing will implement IPv6 blocks based on /64 subnets)
English
0
0
1
144
lefty155🌻
lefty155🌻@lefty155·
@DTealy1 @hpglassford @aaronsmith It’s literally what’s happening here. I’m sure the Taliban would allow Fatima Payman to renounce her citizenship if she supported them. The fact the Taliban won’t shows she doesn’t have an allegiance to them. Why do you want other nations to be able to influence our elections?
English
0
0
1
17
lefty155🌻
lefty155🌻@lefty155·
@DTealy1 @hpglassford @aaronsmith If China don't like Australia's prime minister, should they be able to declare them a citizen so that they have to resign? You really haven't thought this through, have you?
English
2
0
3
20
D.Tealy
D.Tealy@DTealy1·
@hpglassford @aaronsmith Not good enough Black and white, dual citizen or not, no loopholes Australia owes nothing to the rest of the world and should stop compromising its own citizens for global virtue signalling
English
2
0
1
242
Brendan Rhodes
Brendan Rhodes@JontyTheCaller·
Politicians aren't ethical, that's my point! But independent means independent of all parties, so no she shouldn't be allowed to join a party because that proves she isn't the independent she was re-elected as. If she has had two terms and changed teams in both it makes it even harder to trust her!
English
1
0
0
20
Maggie Perry
Maggie Perry@Maggie_Perry6·
With this surprise defection, the Labor-Greens majority in the senate will expand from 39 seats (1 seat majority) to 40 seats. Also worth noting that if she ran again, she was very likely to lose her seat to One Nation candidate Lee Hanson.
6 News Australia@6NewsAU

#BREAKING 🚨 Tasmanian senator Tammy Tyrrell, who was elected in 2022 as a member of the Jacqui Lambie Network before leaving and forming 'Tammy Tyrrell for Tasmania', has joined the Labor Party It brings Labor to 30 senators in the 76-member upper house

English
10
14
253
30.7K
lefty155🌻
lefty155🌻@lefty155·
@JontyTheCaller @Polls0Politics @Maggie_Perry6 Not saying it’s ethical in the slightest, but you can’t make a rule forcing her to remain an independent because parties are allowed to merge or form alliances and the same goes for independents
English
0
0
0
9
lefty155🌻
lefty155🌻@lefty155·
@JontyTheCaller @Polls0Politics @Maggie_Perry6 She was re-elected in 2025 as an independent. Whether it was ethical for her to leave the Jacqui Lambie Network before the end of her 2022-2025 term is another question, but now that she’s been elected as an independent I think she should be free to join whatever party she wants
English
2
0
0
28