David Longenecker

281 Followers
262 Following
61 Posts
Christ-follower | CSIRT | SOC | Threat Intel |Insider Threat | #DFIR | dad | #aviation geek | proud Texan | 90% blue / 10% red team #infosec
Yikes... That's a serious swing in the #weather #forecast. 54° differential from afternoon high to overnight low on Thursday 🌬️🥶 #txwx

I planted a flag over here because while I didn't expect Twitter to fully crash and burn, I wasn't sure Twitter as I knew it would still be around in 6 months.

Turns out I was off by about 5 months.

Random question: why is it that even with app-based #MFA enabled and #SMS MFA disabled, accessing account management features in Twitter prompts for an otp code delivered by SMS or email and not the auth app? Kinda defeats the purpose...

Oh fun. Fake payment confirmation scams are back (or more likely have been there all along and simply managed to slip one by my spam filters).

I hadn't really thought out it in these terms before, but this is a fine argument for enabling real-time transaction alerts with one's bank or payment card processor. Not only do those alerts give an immediate heads-up to an unauthorized transaction, but it's pretty obvious that an emailed "confirmation" is fake, when there is no corresponding transaction alert from my bank.