iwe all kinda knew Bouzy was taking pish in his press release right?
but hot-dam >> email and IP address, phone number, gender, bcrypt hashed password, 2FA secret and backup code and the code that can be immediately used to reset the password all exposed
#CoSoSec #SocialMedia #Spoutible
the vulnerable APIs was requested organically as a natural part of using the service as it was intended, Spoutible almost certainly won't be able to fully identify abuse of it
https://www.troyhunt.com/how-spoutibles-leaky-api-spurted-out-a-deluge-of-personal-data/
bouzy will more than likely use this line
"this isn’t entirely uncommon, as seen in similar data-scraping incidents on platforms like Facebook and Trello"
when he tries to spin the whole thing to his followers being the spn-doctor master manipulator he is