the attacker is opening github issues 😂
> I noticed in your blog post that you were talking about doing a postmortem and steps you need to take. As someone who is intimately familiar with your entire infrastructure, I thought I could help you out.
[then about ssh agent forwarding, and principle of least privilege]
@saphire for the first hour i thought that was a killjoy comment but now i stopped laughing yeah absolutely fair point
Taking over the production web servers, dns, etc, publicly disclosing everything /before/ going to devs and then calling themselves a "whitehat" after all that? Meh. That's not even funny.
The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!