Posts in "infosec"

The emergency room I went to a couple weeks ago texted me a link to pay the bill. It’s to some generic payment system called “Papapapay”, which couldn’t sound scammier if it tried, and it shows a white screen if you open it in Safari.

Sometimes I’d swear they’re trying to train us to open phishing emails.

I think someone at Target’s having a bad day. I got a store credit card there a while back. It’s never left my house except to take it to Target. Today I got an unauthorized transaction message. Now I’m on the phone with their fraud department, with a wait time of 15 minutes.

Bathroom poster, Brickhouse, SF.

I did not add that sticker.

Picture of a skeleton sitting on a toilet, captioned ‘Hope everything comes out okay’. Someone put a ‘Darknet Diaries’ sticker on it.

The GL.iNet GL-AXT1800 travel router I bought a year ago is on sale today for 38% off. If you’ve been on the fence, get this now.

Summary: check into a hotel and connect this, instead of your phone, to the paid WiFi instead. Then connect your phone, laptop, Switch, whatever to the router’s WiFi. Only pay for the one device, have your own firewall in place, and route everything through your own VPN if you want (we watched American Netflix from Germany).

I’ll never travel without one again.

  1. Screenshot your LinkedIn app home screen.

  2. Make a web page with that background.

  3. Add a link at the top to display the QR code of your choice.

  4. Add a link to that on your home screen.

Voila. Now you can make anyone at any tech conference open the QR code of your choosing. “Hey, let’s be buddies!”

How to bypass Credit Karma's 2FA

Locked out of your Credit Karma account’s 2FA? No problem! Here’s how I can log into mine:

  1. Log in with my username and password.
  2. Try the 2FA challenge once and let it fail.
  3. Navigate to accounts.creditkarma.com

Ta-da! I’m in. I reported this a month ago but they haven’t acknowledged it as an issue yet. If I stumbled across this, you can bet the bad guys are already using it.

2025-03-17: I report a critical vulnerability (trivial, complete 2FA bypass) to a well-known company’s security email alias. No reply.

2025-04-07: I report it again to their bug bounty program.

2025-04-09: They close it as a duplicate.

Their bug bounty program says, basically, “we never disclose reports. Don’t discuss them with anyone.”

23 days into this episode, I’m starting to weigh the responsible thing to do here.

AWS WAF now uses /64s instead of /128s for IPv6 rate-limit bucketing. That’s a huge and welcome improvement!

Credit Karma stopped accepting my decade-old Google Voice phone number for 2FA. It won’t let me change to use my regular number because we were already using that for my wife’s account (which she asked me to manage for her). Their support’s idea for resolving this? Just ask Verizon for a new temporary phone number each month or so forever.

Um, no.