blog, to Cybersecurity
@blog@shkspr.mobi avatar

O2 UK's Weird MSISDN Lookup API
https://shkspr.mobi/blog/2024/03/o2-uks-weird-msisdn-lookup-api/

It's always fun keeping your network inspector tab open. While looking around the O2 UK website, I found this page all about eSIMs. For some reason, it wants to know the user's phone number.

I put in a random number, and it refused to let me in.

Sorry, we don’t recognise this number. Please try again.

Putting in a genuine O2 number let me through. So what is it doing to validate numbers?

It is making an API call to this URl:

https://www.o2.co.uk/o/customer/mods/lookup/447700900123

After a bit of testing, this is how I think it works.

If you give it an O2 phone number, it replies with:

{"type":"ONE"}

If you give it a number which isn't on O2, it gives:

{"type":"ZERO"}

A number it doesn't recognise gives:

{"message":"Unable to find the requested resource."}

A malformed or incomplete phone number gives:

{"message":"Something's wrong. Please try again later."}

Responsible Disclosure?

As far as I can tell, O2 no longer have a Bug Bounty or Responsible Disclosure offering. So I'm publishing it here to let people know.

It is possible that someone could use this API to disclose a (minor) piece of personal information about you - namely whether your phone number is on O2 or not. I don't think that's particularly sensitive, but it is probably worth knowing.

https://shkspr.mobi/blog/2024/03/o2-uks-weird-msisdn-lookup-api/

eff, to random
@eff@mastodon.social avatar

EFF’s “How to Fix the Internet” podcast is an Anthem Awards winner! Heartfelt thanks to the Sloan Foundation and Pacific Content for supporting our exploration of a better tech future that benefits all of us. Season 5 is on the way!
https://www.anthemawards.com/winners/list/entry/#responsible-technology/awareness-media-categories/electronic-frontier-foundations-how-to-fix-the-internet-podcast/458892

Codeberg, to random
@Codeberg@social.anoxinon.de avatar

Sorry for decreasing average uptime from 99.97% to 99.64%.

We are still investigating the root cause for the downtime. It looks like it started within our file system.

Codeberg,
@Codeberg@social.anoxinon.de avatar

@ekis @the_moep

Just for the record: We recommend that no one uses Gogs for anything serious. It has numerous critcal security issues. The latest one allows users to perform destructive actions in other users' repositories or access content from private repositories. And there are even more critical security issues that allow for similarly dangerous things.

https://forgejo.org/2023-11-release-v1-20-5-1/#responsible-disclosure-to-gogs

rfc2549, to random
@rfc2549@fosstodon.org avatar

Friends of Mastodon, or ?
Why ?

I am aware of the difference between the two and why Forgejo exists but I'm interested in your opinion.

Thanks !

rodolphe,

@rfc2549 At first I moved from Gitea to Forgejo because I wanted to be ready for forge federation and also because I don't want to promote Gitea's corp.

Yesterday, with Forgejo's critical security fix, I saw a new reason to use Forgejo: Gitea's security team stopped cooperating with Forgejo and gave no explanation for that. This behavior from Gitea is unprofessional and I am not confident on their ability to handle security issues.

https://forgejo.org/2023-11-release-v1-20-5-1/#responsible-disclosure-to-gitea

PS: I started with Gogs and later moved to Gitea, so I really tested all the 3 of them.

msquebanh, to Medicine

More than 1,100 have joined the Committee for in the Nutrients until it stops publishing egregious that could have been conducted in .

The , which also applies to Nutrients’ publisher, , comes after repeated requests to the journal’s editors asking them to institute sound editorial practices.

https://www.pcrm.org/news/news-releases/more-1100-physicians-health-care-professionals-and-scientists-boycott-medical

sarahdrochat, to ArtificialIntelligence French

Hello!

I am the head of the research field "Humane Digital Transformation" at the Bern University of Applied Sciences .

Our goal is to promote a implementation of new technologies that focuses on the human needs.

My personal research focuses on human- interactions and the impact of on conditions and requirements.

I am looking forward to interesting interactions on all topics around responsible digital transformation!

msquebanh, to random
@msquebanh@mastodon.sdf.org avatar

You will find that many folks like me, war survivors, won't take any political sides & can see bigger picture of evil ego filled puppeteers & power hungry violent leaders as who they are - evil & heartless towards innocent citizens.

I'm upset over seeing mostly one sided support by colonial nations - including Canada. You know most of us called it the US war in Vietnam while Western media/ppl called it Vietnam War? US & colonial states fund/interfere/kill innocent ppl in war games. FUCK WAR.

msquebanh, (edited )
@msquebanh@mastodon.sdf.org avatar

is for many & when are they going to be charged in for all their ?

Same with multiple states - when are they going to be tried for multiple war crimes?

The use of human shields in modern day warfare was first used by in 1930s.

Please learn actual history.

Nonilex, to Law
@Nonilex@masto.ai avatar

#Trump #fraud #trial #Day3 🧵:

Trump gripes trial is 'unfair' after judge's #GagOrder
(it was just in regards to the judge’s staff.)

After the trial wrapped up yesterday, Trump aired his #grievances in a post on his social media platform, saying the trial is “unfair” & again suggesting it was an attempt to interfere w/his presidential campaign.

#law #legal #FediLaw #TrumpTrial #TrumpOrganization

Nonilex,
@Nonilex@masto.ai avatar

, argued the are for their

& , who signed the representation letr. & the engagement letr. for the 2021 compilation of ’s statements of condition, were a focus of the PM court session.

When was engaged, , fmr CFO, played that role, but by 2021, the responsibility for retaining & managing the relationship seems to have shifted to the .

Nonilex, to Law
@Nonilex@masto.ai avatar

thread;

continued his attacks against hours before he returned to court for the 2nd day of arguments in the that the AG brought against him & his company.

In 2 posts on his social platform this morning, Trump used derogatory terms to James while denying any wrongdoing against allegations that he his .

Nonilex,
@Nonilex@masto.ai avatar

That included entering into a letter that , then the 's CFO, sent , which read, "We are for the preparation & fair presentation of the statement on financial condition in accordance with accounting principles generally accepted in the United States."

cdarwin, to geopolitics
@cdarwin@c.im avatar

Does anyone know what has happened in this lawsuit?

👉 Puerto Rican towns sue Big Oil under RICO alleging collusion on climate denial

Puerto Rican municipalities have filed a lawsuit in federal court saying Corp, Plc, Corp and others colluded to publicly downplay the risks of their fossil-fuel products on climate change and are for damages from the devastating 2017 hurricane season, which was made worse by .

The group of 16 municipalities filed what they called a first-of-its-kind lawsuit last week against about a dozen fossil fuel companies and others.

The towns say the companies coordinated a multibillion-dollar " marketing scheme" to convince consumers that fossil fuel products do not alter the climate.

That campaign ran contrary to the companies' own studies showing their products accelerate climate change, resulting in more deadly storms, the lawsuit said.

https://www.reuters.com/legal/litigation/puerto-rican-towns-sue-big-oil-under-rico-alleging-collusion-climate-denial-2022-11-29/

PhilosophicalPsychology, to random
@PhilosophicalPsychology@fediscience.org avatar

New paper in the special issue on Collective Irrationalities by Anne Meylan & Sebastian Schmidt: "many vaccine-refusers are for the belief that they should not be vaccinated and epistemically in holding it." https://doi.org/10.1080/09515089.2023.2181151 @philosophy @ethics

fulelo, (edited ) to Podcast
@fulelo@journa.host avatar

@Bellingcat : , Episode 1 Guide: The People Who Fell From the Sky

https://www.bellingcat.com/resources/podcasts/2019/07/17/mh17-episode-guide-1/

Looks like an excellent podcast recommendation v @ChristopherJM and a reminder from him why is it important:"9 years ago today, forces shot down MH17, killing all 298 people aboard. Dutch court found , convicting 3 Russians, 1 Ukrainian in absentia for roles. has repeatedly lied about the attack. But overwhelming evidence points finger straight at "

cazabon, to Canada

A followup to this thread on a huge medical-privacy in ...
https://mindly.social/@cazabon/110557881736874267

The in question, which is happy to give both your (and presumably ) to pretty much anyone who wants them, in addition to letting them see when your prescriptions are eligible for refill, order those refills, and turn on OR OFF automatic fills for your prescripts is ...

Shoppers' Drug Mart.

[...]

cazabon,

Following links on the Shoppers' site, privacy issues are directed to the Chief Privacy Officer at Loblaws, their parent corporation. bought some years ago in a megamerger.

Shoppers is, I believe, the single largest source of ' . So this affects a lot of Canadians.

I tried to engage in . I emailed the person in question, twice. I have the logs from my email server showing the messages getting to them.

[...]

ManyRoads, to business
ManyRoads avatar

This certainly seems like a good idea and certification. I wonder how I managed to miss it...

"Make Business a Force For Good: B Lab is the nonprofit network transforming the global economy to benefit all people, communities, and the planet."

https://www.bcorporation.net/en-us/

cazabon, to security

1/13 So, this week I discovered my first in a public system.

In the past I've found in , problems with , with bureaucratic processes, some of which were significant, but they all pale in comparison to this one.

It starts with a of .

cazabon,

3/13 I have reported the issue to the company; I have asked them to acknowledge and take short-term steps to close the hole. I reported it after hours, so I have not yet received a response, although maybe they should be monitoring this address out of office hours due to the nature of the system.

I will not identify the company in the meantime, providing they address this in a amount of time.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • ngwrru68w68
  • JUstTest
  • cubers
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • lostlight
  • All magazines