Karan Saini

728 posts

Karan Saini banner
Karan Saini

Karan Saini

@squeal

hacker, security researcher; alum @cis_india, @hasgeek; blog at https://t.co/pXy5yRt8Jw

New Delhi, India Katılım Haziran 2008
987 Takip Edilen4.3K Takipçiler
Karan Saini
Karan Saini@squeal·
@pranesh Totally fine for two parties to arrive at the same conclusion across incidents, but it’s literally the same incident? The insights are similar (albeit less nuanced, some misplaced), and the references are almost identical.
English
0
1
3
255
Pranesh Prakash
Pranesh Prakash@pranesh·
@squeal I'm not sure I'd agree it's plagiarism. Their piece seems to have different references. And the conclusion is one that many (incl. I, since at least 2012, in a write-up on Huawei) have repeatedly made: that security safeguards should rely on processes and not national origin.
English
1
0
3
313
Karan Saini retweetledi
Shashank Mattoo
Shashank Mattoo@MattooShashank·
1.5 million views on this tweet by ex-Japan minister blaming India for delays in Indo-Japanese Shinkansen project “Sheer recklessness of the Indian side..” “They just don’t keep promises..” “The minister in charge was awful..”
Shashank Mattoo tweet media
English
489
2.5K
10K
1.4M
Karan Saini
Karan Saini@squeal·
@akhmxt @Uber_India For T1, I walk out past the Flight Crew parking to the metro station entrance and just take an auto. Usually also cheaper!
English
1
0
0
201
kalim
kalim@akhmxt·
T1 @Uber_India pick up zone in IGI Airport Delhi is extremely chaotic. If your drop location is within Delhi, the waiting time can be anywhere between 30-50 mins. People are furious and a fight might breakout at any moment.
English
4
1
33
2.4K
Karan Saini retweetledi
Rithwik Jayasimha
NIXI decided to yank our original domain we picked and now apparently has rules disallowing @ProtonMail emails. There was no warning, no notice and it took them an entire day to get back. Guess that's the last time I ever buy a .in domain for a project.
Rithwik Jayasimha tweet mediaRithwik Jayasimha tweet media
Saumya Mehta@NotNotSaumya

The ECI started a country wide cleanup of the electoral rolls (SIR) to rebuild voter lists. But the data is full of typos, OCR issues & often written in native languages. I built a search w @thel3l on the ECI's data to handle this Find your record at oldvoterlist.com!

English
4
11
41
4.8K
Karan Saini retweetledi
Rithwik Jayasimha
The ECI is doing a nationwide cleanup of the rolls but the raw data has TONS of issues, from bad translation to typos. @NotNotSaumya and I built a search to fix this. Provide as much detail as you can and we filter through thousands to find you! Examples from folks using it:
Saumya Mehta@NotNotSaumya

The ECI started a country wide cleanup of the electoral rolls (SIR) to rebuild voter lists. But the data is full of typos, OCR issues & often written in native languages. I built a search w @thel3l on the ECI's data to handle this Find your record at oldvoterlist.com!

English
6
18
55
9.6K
Karan Saini retweetledi
Saumya Mehta
Saumya Mehta@NotNotSaumya·
The ECI started a country wide cleanup of the electoral rolls (SIR) to rebuild voter lists. But the data is full of typos, OCR issues & often written in native languages. I built a search w @thel3l on the ECI's data to handle this Find your record at oldvoterlist.com!
Saumya Mehta tweet media
English
8
9
62
13.2K
Karan Saini retweetledi
Seema Chishti
Seema Chishti@seemay·
In 2026, four Asian nations achieved upper-middle-income status, including Vietnam and the Philippines, while India didn’t, by a wide margin. @livemint
Seema Chishti tweet media
English
61
254
464
84.5K
Karan Saini retweetledi
Rick de Jager
Rick de Jager@rdjgr·
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663. Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution.
English
44
250
2.4K
230.1K
Karan Saini retweetledi
Aditya Kalra
Aditya Kalra@adityakalra·
⚡ 🚨 BREAKING: Files tied to India's largest nuclear power plant Kudankulam have surfaced on the dark web -- including purported blueprints of its ventilation systems and a control room floor layout.... What's in the data leak? Nearly 19,000 files tied to Kudankulam are part of a larger 858,000-file cache ransomware group World Leaks says it stole from Anil Ambani's Reliance Group. The files include vendor proposals and records of a joint inspection between the plant's operator and Reliance, with photos of equipment. Why did Reliance have these docs? Reliance Infrastructure won a contract in 2018 to build support infrastructure for the plant's Unit 3 and Unit 4. Reliance says there was a "partial breach" of its data on a server hosted by Yotta Data Services Private Limited. Yotta says it caught suspicious activity on that server on May 29 and Reliance flagged the leak claims to Yotta in late June. Significance? "The exposure of such data could show an adversary not just who has access to the project but which systems that access reaches," Nickolas Roth of the Nuclear Threat Initiative told us. World Leaks context? In June, World Leaks told Reuters it had sought $1.5 million in ransom for Tata Group files that contained confidential component designs of clients Apple and Tesla, adding that it posted the data after Tata "ignored" its demand. Nuclear Power Corporation has been communicating with Reliance about the breach and India's main cybersecurity agency CERT-In is looking into the incident, a source said. Story with @MunsifV. Read here reuters.com/world/india/fi…
English
56
799
1.3K
196.8K
Karan Saini retweetledi
Rithwik Jayasimha
In February, @rithvikvibhut and I started hacking fiber optic networks and a curious protocol called GPON. We ended up with a way to see mobile traffic bc of 4G/5G backhaul, wiretap phone calls and build a massive botnet. We're presenting at @defcon and @BlackHatEvents in Aug!
Rithwik Jayasimha tweet mediaRithwik Jayasimha tweet media
English
17
12
115
7.1K
Karan Saini retweetledi
Joshua Khane
Joshua Khane@JoshuaKhane·
Microsoft DELETED my account AND OneDrive!!?? After ACKNOWLEDGING that I’m the owner of the account and that it was compromised??? 25 fucking years of data, thousands of euros spended on games?? My son’s baby pictures? GONE! All because MICROSOFT couldn’t bring back a compromised account?? One of the biggest companies ever coulnd’t do that so they just deleted that shit like it was nothing?? Fucking shame on you!! @microsoftnl @MicrosoftHelps @MicrosoftHelpt @Microsoft #microsoft #hacked
Joshua Khane tweet media
English
4.7K
9.9K
82.2K
5.8M
Karan Saini retweetledi
Aroon Deep
Aroon Deep@AroonDeep·
Exclusive: The UMANG portal, used crores of times over the last couple months for hundreds of government services, has vulnerabilities that expose any user's details as long as they are logged in to a valid session, two researchers told The Hindu. Details: thehindu.com/sci-tech/techn…
English
1
32
38
3.7K
Karan Saini
Karan Saini@squeal·
why does @Google treat ipv6 addresses so terribly? getting a captcha on literally every search
English
38
9
796
90.4K
Karan Saini retweetledi
Srinivas Kodali
Srinivas Kodali@digitaldutta·
Where @squeal argues for supply chain regulations. A classic attack vector.
Srinivas Kodali tweet media
English
0
10
36
1.6K
Karan Saini retweetledi
hugeh0ge
hugeh0ge@hugeh0ge·
I found a Linux 0day vuln with @rqda_A, and $80,000+ rewarded for it by Google kernelCTF! The vuln has been surprisingly hidden for about 19 years. We've published an English version of the blog post! gmo-cybersecurity.com/blog/19-years-…
rona@rqda_A

Linux kernelで19年以上見過ごされていた0-day脆弱性を報告しました 悪用されると一般ユーザーからの権限昇格が可能になる脆弱性です 詳しくはこちら gmo-cybersecurity.com/blog/19-year-o…

English
8
112
663
55.3K
Karan Saini retweetledi
Pranesh Prakash
Pranesh Prakash@pranesh·
#security #censorship #FoE #India #AppBlock Banning BMS apps isn't a solution when the underlying software flaws continue to exist, and in fact makes things worse. It's shocking that this even needs to be said. MEIT needs a change in leadership! thehindu.com/sci-tech/techn…
Pranesh Prakash tweet media
Karan Saini@squeal

My piece for The Hindu today, where I explain the recently popular BMS vulnerabilities, suggest supply chain regulation, and argue against app bans. Originally titled “Information controls are not security.”

English
1
6
16
905