Crystals
banner
crystals.fedi.omada.cafe.ap.brid.gy
Crystals
@crystals.fedi.omada.cafe.ap.brid.gy
I sit on a computer all day acting like I know what I'm doing and then ask questions when things break.
"You aren't a government target you are a mentally ill 15 […]

🌉 bridged from ⁂ https://fedi.omada.cafe/@Crystals, follow @ap.brid.gy to interact
Please let the ai bubble pop and it all go back to normal Please let the ai bubble pop and it all go back to normal Please let the ai bubble pop and it all go back to normal Please let the ai bubble pop and it all go back to normal
December 4, 2025 at 6:56 AM
PSA to people using immich: if your phone uploads an asset while your computer is mass uploading assets to an album, there is a chance it can be added to the album
This is problematic because public albums exist

I'll make a GitHub issue later
November 23, 2025 at 12:02 PM
Did jortage explode again
October 25, 2025 at 6:11 PM
When were you when us east 1 explod
I was eeping
"Us east 1 explod"
"No"
October 20, 2025 at 3:37 PM
Hey so how could one hijacked discord support account scrape every fucking ticket
October 3, 2025 at 11:36 PM
So disappointed with GG they're gonna be lucky if I don't post a bash script on pastebin within the next year :sob:
August 26, 2025 at 4:33 AM
Reposted by Crystals
I shoudl elaborate. I've since found that if GG finds a password field or a credit card field it does Not exfil data to their servers. But in cases like bitwarden and gmail where there is not, it will

GG is NOT exfiltrating your passwords (as you enter them) or your credit card information.
August 22, 2025 at 2:15 AM
"responsible disclosure" nuh uh
July 23, 2025 at 2:56 AM
Every time matrix starts on omada servers my garage gets a tiny bit warmer
July 17, 2025 at 12:59 AM
Exploit Code Not People (@cooperq@infosec.exchange)
So I reverse engineered the IceBlock app - https://www.404media.co/immigration-raid-tracking-app-ice-block-keeps-your-data-private-researcher-finds/ here's a thread on what I found. The TL;DR is that I didn't find anything suspicious, the app doesn't talk to any third parties, and it doesn't send your location to the developer. Neither your phone ID or iCloud account are associated with the requests the app sends to the apple cloud servers to run. The app is written in Swift and mainly uses the MapKit and CloudKit libraries. When you send a report that report contains the location of the report, this is not necessarily your location but the location at which you saw something. It also contains any free form text you choose to enter. And that's all that is contained in the report, no device ids or iCloud accounts are associated with the report. Could a judge issue a tap and trace order to Apple to get the IP addresses of people submitting reports? Possibly. But that doesn't seem to be how ICE is operating right now. And more importantly that would just give IPs which are going to be DHCP leases from a cellular network not device IDs or any other actual user identifier, so it would be harder to trace these back to real people. The developer assures me that the reports are deleted from the database after a short time so such a theoretical order would also not get any past reports, only future reports. I can't think of a way for the app to defend against this but if its your threat model maybe use a VPN. One argument I've seen against this app is that if you use it Apple will have access to your location, and yea that's probably true. But Apple always has access to your location if you have location services turned on. If that's your threat model turn off location services! My main concern was about false reports. The dev has done a decent job of preventing mass spamming, you are rate limited in how many reports you can upload and you can only make a report within 5 miles of your location. I think more likely is that people will make reports that are inaccurate because they saw an FPS vehicle or a DHS vehicle that isn't ice, or just some cops even. I'm not really sure how to solve this problem. I'm a bit concerned that this could spread fear and uncertainty. The developers take on this issue is that there may be some false reports but if a true report keeps one person from going to that location for a few hours and saves them from getting deported that's a win, I find it hard to argue against that. Anyway at the end of the day it will be up to the communities most at risk of ICE abduction to decide whether this app is useful for them. That isn't my area of expertise and I can only say what I found from a technical perspective. At the end of the day, even if this doesn't turn out to be an effective tool for people to protect themselves from ICE its still a great piece of agitprop or propaganda by the deed. It gives people a way to feel power against ICE and pisses off the administration. In conclusion: Fuck ICE!
infosec.exchange
July 16, 2025 at 7:17 AM
Hey @Tutanota you blocked my home ip I'm a paying customer mind removing 76.8.147.177 from your lists
July 10, 2025 at 5:43 PM
tuta anti spam is a joke and they do not do anything to combat mail flooding, please do not use tuta
July 7, 2025 at 4:50 PM
phone charger got murdered by a power surge 3:
July 5, 2025 at 3:10 PM
Reposted by Crystals
Update - GG replied to me 6 days after I emailed them in may, which is good. They haven't made an update on it nor is it fixed though.
This is also just about the auth bypass now, as passwords being captured was due to bitwarden not marking a password field as a password field. OTP and 2fa […]
Original post on fedi.omada.cafe
fedi.omada.cafe
June 21, 2025 at 4:02 PM
Btw , you don't want a framework ! ! Their qc is a joke and they are incredibly overpriced
June 28, 2025 at 12:25 PM
Reposted by Crystals
i wasnt paying attention and i heard this from my tv and i thought i was having a fucking fever dream
June 28, 2025 at 2:50 AM
Discord should really make webhooks their own subdomain
When a computer on my network that isn't supposed to makes a request to a discord webhook I should be able to instantly contain it and track down who just ratted my family member
June 26, 2025 at 1:00 AM
wonder how much I stick out for having orbot run a tor connection on my phone 24/7
June 1, 2025 at 5:11 PM
omada tor domains coming soon, summoning vanities using my power bill
May 28, 2025 at 7:58 AM
Pixel 8 pro try not to overheat when you turn on hotspot challenge
May 1, 2025 at 4:16 PM
[School phone policy, politics]

162.207. 1. As used in this section, "electronic personal communications device"
2 means a portable device that is used to initiate, receive, store, or view communication,
3 information, images, or data electronically.

missouri is attempting to implement a […]
Original post on fedi.omada.cafe
fedi.omada.cafe
April 29, 2025 at 2:28 AM
Does anyone remember how to get .arpa domains? I lost the post
April 23, 2025 at 6:18 AM
Muting mastosoc every time I interact with people there I want to uninstall moshidon
April 15, 2025 at 4:54 PM
If you have EVER had a password shown on your screen as plaintext html on a device with goguardian installed, it is compromised. Reset it. I'll post more later
April 8, 2025 at 8:13 PM
Oh my god fuck it we ball
March 24, 2025 at 2:18 AM