Alesandro Ortiz 🇵🇷🏳️‍🌈

759 Followers
430 Following
2K Posts

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ 🏳️‍🌈. He/him.

Focused on browser research. Glad to collaborate.

Website: https://AlesandroOrtiz.com
(Header 📷: roriv3ra on IG)

Websitehttps://AlesandroOrtiz.com
LocationQueens, NY / Puerto Rico
Infrequent Newsletterhttps://AlesandroOrtiz.com/subscribe
Twitter (unused)https://twitter.com/AlesandroOrtizR
@ecr80 TIL about Nine Inch Noize. :O Two groups I didn't expect to collab.

@SecureOwl Makes me think of Plex, the software.

Considered NotDeleted? VoidExfil? VoidInTheMiddle? VoidExfil? BlackHolExfil?

Anything that invokes void/null routing?

@wdormann Now I'm wondering how Windows behaves here too. Can't test now but IIRC it does store notifs for at least a few days.

@wdormann @Mer__edith FWIW, at least some Android flavors have Notification History feature too. e.g. my Samsung phones have had it for years.

In UI it only shows 24 hours of history and doesn't show uninstalled apps, but not sure if older or uninstalled app notifications are actually deleted behind the scenes.

I agree Signal should have No Content by default. Also needs clear warning about risks when relaxing settings.

@bagder Do reporters share the tools used, or are there strong tool indicators in the reports?

Curious about which tool(s) are most successful, at least for cURL research.

I imagine in most cases reporters don't mention the tools used (especially if custom), which is unfortunate.

@kf It has entered The Void™

@xssfox Someone recently emailed me:
"There is no option to disable [main feature]. How can a company of this size fail to implement something as simple as an on/off switch? Hire people who, in addition to having a degree, can actually think beyond it."

Keep in mind:
1. The company is just me, myself, and I.
2. There is an always-visible on/off switch in the main UI. In fact, it's been there since the very first release. I did think about it.
3. I don't have a degree. 🤷‍♂️

protip: ALWAYS use regular expression literals in JavaScript and TypeScript and any other language that supports it, instead of writing your regex out in a string. I cannot count how many critical security bugs I have found over the years from someone writing a regex like "^en\.wikipedia\.org$", which is incorrect because the \. is treated as *string* escape sequence (an invalid one that just produces .) which then results in the regex being "^en.wikipedia.org$" which matches "enowikipedia.org".
Iran War Live Updates: Trump Announces Two-Week Cease-Fire, Subject to Strait of Hormuz Reopening

The deal came shortly before President Trump’s deadline for Iran to reopen the Strait of Hormuz or face devastation. Israel said the cease-fire did not include Lebanon.

The New York Times
@chasnah @shodansafari 😂 I missed that before reading your post.