sylvanwoods.bsky.social
@sylvanwoods.bsky.social
Reposted
We all use flawed, problematic platforms and products; it's unavoidable. But X is something else altogether. It's astoundingly evil. Almost none of the usual excuses apply any longer. Get the fuck off of it.
January 8, 2026 at 6:01 PM
Reposted
I feel like a big thing people often don't get is that computers are stupid. They are really, truly, stupid. They can only do what you tell them, exactly what you tell them, and they cannot think "well this is an obvious problem, clearly this wasn't intended" the way even a small child often can
January 8, 2026 at 8:57 AM
Reposted
And this is why I haven't completely lost faith in us as a nation. The pettiness
January 8, 2026 at 3:48 AM
Reposted
Yes people in America get only 2 weeks. People in America also can’t get abortions. People in America die at age 7 at school because of guns. America ain’t shit first of all. Second of all why isn’t Luxon back at work and why does he lie all the fucking time.
January 7, 2026 at 6:48 PM
Reposted
Rationale: API giving anything for a valid cred explains "a valid *user* password" leading to 127k users' files. Client-side access control (which is crazy) is inferred from "well they gotta put *some* access control *somewhere*... right?"
January 6, 2026 at 12:13 PM
Reposted
The website is a client-side webapp with calls to a bunch of C# backend APIs so there probably isn't too much of a difference in that they could have skippef both and queried the backend API directly.

The High Court decision from today gives a little of technical detail

bsky.app/profile/utf9...
Here's a copy of the High Court injunction decision released to me by the Wellington High Court. The attached publishers notes state that there are no restrictions on publications.

Change the URL to 2+PS.pdf for the publishers notes if you're interested

cdn.utf9k.net/documents/Ma...
cdn.utf9k.net
January 6, 2026 at 11:35 AM
Reposted
Yeah, sounds like access control was done client side, and the API (at least for that module) would give anything to any client with a valid creds. Solves your "how'd they get the file list" problem too - the API gave it up.
January 6, 2026 at 12:09 PM
Reposted
What I’m not clear on is whether it was the mobile app or the web platform or both channels that were the problem.

In any case, I’d like to know when (1) MMH last performed a pen test and (2) did they implement the recommendations?
January 6, 2026 at 7:35 AM