Tootfinder

Opt-in global Mastodon full text search. Join the index!

@kubikpixel@chaos.social
2025-08-29 09:50:08

»OAuth-Token erbeutet – Hacker greifen massig Daten aus Salesforce-Instanzen ab:
Cyberkriminelle haben es erneut auf Salesforce-Kunden abgesehen. Wer die Salesloft-Drift-Integration verwendet, sollte dringend handeln.«
Schon länger geht das Gerücht um, dass OAuth des öfteren schwach implementiert ist von den IT-Konzernen, wie schon bei OAuth v1 das als unsicher gilt.
🔒

@tezoatlipoca@mas.to
2025-07-28 16:15:40

When you get the option to `Sign in with Google/Microsoft/Facebook` you're really using #OAuth. Aside from those platforms knowing what you're doing everywhere all the time, there are compelling reasons for both 3rd party services and users. (not many, but a few).
But if you DO link your #Microsoft /

@hex@kolektiva.social
2025-08-29 17:23:57

The WriteFreely instance at Infosec.press is cool. It ties back to their infosec.exchange mastodon instance. Thinking about how finding a blog space has been a barrier to some of my protects in the past (noblogs is great but is harder to get an account), I wonder what the prospects are for something like that at @…. Is this something that's on the radar?
@… had a handy writeup on this for their server: infosec.press/jerry/how-to-use

@tante@tldr.nettime.org
2025-08-29 11:33:46

So someone just got access to a bunch of Salesforce accounts by getting their access tokens.
Salesforce is the company that claims that already 20% of their code is written by "AI", isn't it?
cloud.google.com/blog…

@Techmeme@techhub.social
2025-08-27 05:35:55

Salesloft says hackers stole OAuth tokens from its Drift chat agent integration to conduct a Salesforce data theft campaign between August 8 and August 18 (Lawrence Abrams/BleepingComputer)
bleepingcomputer.com/news/secu

@arXiv_csCR_bot@mastoxiv.page
2025-07-24 07:36:49

Building a robust OAuth token based API Security: A High level Overview
Senthilkumar Gopal
arxiv.org/abs/2507.16870 arxiv.org/pdf/2507.1687…

@unixorn@hachyderm.io
2025-06-16 17:44:03

Updated #IOT #HomeAssistant #InternetOfTrash @… @… @…

@khalidabuhakmeh@mastodon.social
2025-08-11 16:19:54

Are you worried your #dotnet #security could be more secure? Join us for a #livestream on August 21st, 2025, to discuss FAPI 2.0, its relation to

@GroupNebula563@mastodon.social
2025-07-16 18:17:30

#Discord apparently only accounted for OAuth links to activities to be posted, so when I posted a link to a Scatman John bot (don’t ask, or do if you want) it came out like this:

A picture of Scatman John with some text next to it reading “Scatman John”. Below that is a subtitle: “Unlimited Players”.
@Techmeme@techhub.social
2025-06-09 05:05:37

Cloudflare open sourced an OAuth library mostly written by Claude, showing how AI handles mechanical implementation while humans guide with context and judgment (Max Mitchell)
maxemitchell.com/writings/i-re