Back
Hwee-Boon Yar

Hwee-Boon Yar
PRO

@hboon

Building: stacknaut.com myog.social theblue.social Write software TypeScript (web) + Swift hboon.com/about
408
Joined February 2018

At least it's fair here. I lost a few hundred day streak at another site because they had some weird time/timezone computation.

It's 18 day. You can do it :)

thanks for the encouragement!

DId you link to the wrong post? That post that inspired you was from 2 days ago.

So the hypothesis is that the attacker reset 2fa and then reset your password? (I wasn't sure you were saying they let you, or possibly that they let the attacker reset it)

yup - they let the attacker do it. all you need is the email address and/or phone number. if this information is already public - well, you're hosed @hboon

you should see the email i got when it was time to ask for a reset - maybe you just need to be convincing. aka social engineering

But third party apps with OAuth access can't sign into X website/apps to change your password/email, right?

I should think so. But it’s possible to also socially engineer X from what I gather. I have a theory. Let’s see

You don't. But you try to do load more (again, as a habit, not via ad-hoc sheer force of will) if you reasonably can. The critical part is to keep going at it.

makes sense. just show up every day, make sure you work on effective things and not BS, and it'll grow, eventually. i like it! thanks!

Home
Search
Messages
Notifications
More