iwe all kinda knew Bouzy was taking pish in his press release right?
but hot-dam >> email and IP address, phone number, gender, bcrypt hashed password, 2FA secret and backup code and the code that can be immediately used to reset the password all exposed
#CoSoSec #SocialMedia #Spoutible
the vulnerable APIs was requested organically as a natural part of using the service as it was intended, Spoutible almost certainly won't be able to fully identify abuse of it
https://www.troyhunt.com/how-spoutibles-leaky-api-spurted-out-a-deluge-of-personal-data/
@ecksmc this is what happens when you build your site using a Russian Twitter clone codebase.
Bouzy's aspirations always exceed his grasp.
Spoutible’s API coughed up passwords, 2FA info, and tokens that could let attackers take over anyone’s account
https://www.theverge.com/2024/2/5/24061997/twitter-alternative-spoutible-vulnerabilty