Adam Katz

@adamhotep@infosec.exchange
400 Followers
782 Following
2.2K Posts

#Cybersecurity #antispam research leader at @TalosSecurity, FOSS advocate, zsh/bash #Linux geek, bastion of obscure knowledge.

Support freedom for ✊🏿🇺🇦🇵🇸🏳️‍🌈🏳️‍⚧️♀️
he/they.

Currently living in NYC.

Not representing any entity but myself (and occasionally your mom).

#fedi22 searchable

I run:opensource:​:debian:​:linux:​:bash:​:firefox:​:vim:​:signal:​:donor:
Githubhttps://github.com/adamhotep
Infosec Stack Exchangehttps://security.stackexchange.com/users/42391/adam-katz
Stack Overflowhttps://stackoverflow.com/users/519360/adam-katz
PGP FingerprintF8EC 5C50 92BA 06CA 8DCA 8BA1 8EBA 15BA F4AD 9292

RE: https://mstdn.ca/@paulisci/115769718574645378

This thread is a great way to end the year. It's not political and not bad news, just wholesome lunacy of the best kind.

Internet Sleuths Reveal Hack to Undo Epstein File Redactions

Trump’s DOJ has botched the Epstein files release even more than previously thought.

The Daily Beast

Canadians are the BEST neighbors! Here they've gone ahead and leaked the #CBS #60Minutes CECOT segment that Bari Weiss pulled for Trump. Enjoy!!!
#uspol #uspolitics #TangerineTyrant #FreeSpeech #journalism

https://archive.org/details/60-minutes-inside-cecot

60 Minutes Inside CECOT : Free Download, Borrow, and Streaming : Internet Archive

Full video of the 60 Minutes Inside CECOT episode that CBS pulled.

Internet Archive

This Gmail hack is unsettling not because it’s flashy, but because it’s bureaucratic. Attackers aren’t breaking encryption or outsmarting algorithms. They’re filling out forms. By changing an account’s age and abusing Google’s Family Link feature, they can quietly reclassify an adult user as a “child” and assume parental control. At that point, the rightful owner isn’t hacked so much as administratively erased.

The clever part is that everything happens inside legitimate features. Passwords are changed. Two-factor settings are altered. Recovery options are overwritten. And when the user tries to get back in, Google’s automated systems see a supervised child account and do exactly what they were designed to do: say no.

Google says it’s looking into the issue, which suggests this wasn’t how the system was supposed to work. But it’s a reminder of an old lesson. Security failures often happen when protective mechanisms are combined in ways no one quite imagined. The tools aren’t broken. The assumptions are.

There’s no dramatic fix here, only mildly annoying advice that suddenly feels urgent. Review recovery settings. Lock down account changes. Use passkeys. Because once an attacker controls the recovery layer, proving you’re you can become surprisingly difficult.

TL;DR
🧠 Family safety tools are being weaponized
⚡ Account recovery can be shut down entirely
🎓 Legitimate features enable the lockout
🔍 Prevention matters more than appeals

https://www.forbes.com/sites/daveywinder/2025/12/07/google-looking-into-gmail-hack-locking-users-out-with-no-recovery

#Cybersecurity #Gmail #IdentitySecurity #AccountRecovery #DigitalRisk #security #privacy #cloud #infosec

This took way too long to find. Blocking the "Sign in with google" on sites via #uBlock custom filter. Add accounts.google.com/gsi/* to the filter and adios stupid Sign in with google popups.

Edit: I tested this with logging into gmail (yeah i know, irony), and it still works fine.

Update: Thanks to @bill , this might be the more 'proper one'.

accounts.google.com/gsi/*$xhr,script,3p

#google #ublockorigin

The back page of last month's edition of The Onion.

I don't think I'll stop using Firefox anytime soon.
Yes, their management are fucking idiots and it's annoying that I'll have to disable new AI features whenever they release them..

But the alternative is to use something Chromium-based, which would make Google's domination of web technology absolute - and Google is 100x more evil than Mozilla ever could be.

I hope this fucking bubble pops before Mozilla fucks up Firefox so badly that it becomes completely unusable

This guy made the best counterfeit US cash the Secret Service had seen in 25 years. The article has a nice short documentary interviewing him. Yes, he shares some of his methods.
https://www.yahoo.com/news/counterfeit-money-actually-works-according-204204316.html
How counterfeit money actually works, according to a former forger

Jeff Turner counterfeited over $1 million in US currency. He forged the 1996-series $100 bill and later the 2013 "blue note." He was indicted on federal...

Yahoo News

Pete Buttigieg and Robert Reich have highlighted our plan to
✅ defeat Citizens United:

“Interesting things are happening across the country…
Montana is trying to address this through attention to what a corporation can and can’t do,
because that’s actually decided at the state level.

So instead of working it at the ‘speech’ side of the equation,
💥they’re working at the
‘what is a corporation’ side of the equation.” --Secretary #Buttigieg

And Former Labor Secretary Robert #Reich highlighted our plan as the path to beating Citizens United,
and a bipartisan coalition of state party leaders here are lending their efforts to the cause,
including Former Senator Jon #Tester and Former Governor Marc #Racicot.

⭐️. But the most important part is that 74% of surveyed voters
— regardless of party affiliation
— support our plan to get corporate money out of our elections.

👉 We’ve launched a ballot initiative to get undue corporate influence out of our politics and end dark money loopholes for good.

👉 Once we win here in Montana, we will have a legal precedent for all 49 other states. -- Yours could be next!

🔥We’re taking our elections back from the oligarchs, once and for all.

Thank you for supporting The Montana Plan today!
https://secure.actblue.com/donate/tei-roi-quotes