Jameson Lopp

3K Followers
33 Following
292 Posts
Cypherpunk · Co-founder & Chief Security Officer of https://casa.io · creator of https://bitcoin.page, https://lightning.how, https://statoshi.info
nostrf728d9e6e7048358e70930f5ca64b097770d989ccd86854fe618eda9c8a38106

PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

Microsoft says Office bug exposed customers' confidential emails to Copilot AI | TechCrunch

Microsoft said the bug meant that its Copilot AI chatbot was reading and summarizing paying customers' confidential emails, bypassing data-protection policies.

TechCrunch

Five years ago I pointed out nearly all NFT's were going to break when the startup who minted them goes bust, causing people to get *extremely* mad at me until everyone concluded that I was correct.

Thought I'd check in on the two examples I used and well

security advice, 1996: writing your passwords down in a notebook is a very bad idea and nobody should do it

security advice, 2026: writing your passwords down in a notebook is one of the most secure storage methods for most users

(fun how threat models change over time, eh?)

If I am reading this correctly, Northern Ireland police, who just received compensation of £7,500 per officer for having their personal details published in error on the internet, were revictimized today when the Northern Ireland court system again published their personal details.
https://www.belfasttelegraph.co.uk/news/northern-ireland/it-defies-belief-names-of-psni-officers-published-on-court-website-in-new-breach/a122899735.html
‘It defies belief’: Names of PSNI officers published on court website in new breach

Some PSNI officers who had their names released in a catastrophic data breach in 2023 have now had their details published on the NI Courts website.

BelfastTelegraph.co.uk

Here's our 25-min video news-documentary version of the story of Red Bull, the whistleblower who leaked me the secrets of a crypto scam compound while trapped as a forced laborer inside it.

https://www.youtube.com/watch?v=zOcNaWmmn0A&t=1s

Hope you'll watch and consider the immense scale of this global crisis.

I Escaped Chinese Mafia Crypto Slavery | Hacklab | WIRED

YouTube
Notepad++'s update mechanism was compromised from June to December 2025. They believe it was a state actor practicing selective targeting and not a no-hosts-refused malware gang situation. https://notepad-plus-plus.org/news/hijacked-incident-info-update/
Notepad++ Hijacked by State-Sponsored Hackers | Notepad++

lol https://seclists.org/oss-sec/2026/q1/89

telnetd server invokes /usr/bin/login (normally running as root) passing the value of the USER environment variable received from the client as the last parameter.

If the client supply a carefully crafted USER environment value being the string "-f root", and passes the telnet(1) -a or --login parameter to send this USER environment to the server, the client will be automatically logged in as root bypassing normal authentication processes

In telnetd for a decade 💀

oss-sec: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd

10 years ago today: Bitcoin developer Mike Hearn declared the project a failure & sold all his BTC.

The exchange rate at the time was $430. 😬
https://blog.plan99.net/the-resolution-of-the-bitcoin-experiment-dabb30201f7

The resolution of the Bitcoin experiment

I’ve spent more than 5 years being a Bitcoin developer. The software I’ve written has been used by millions of users, hundreds of…

Medium