Mikail Tunç (@emtunc) 's Twitter Profile
Mikail Tunç

@emtunc

I do security things

ID: 821012994486337536

linkhttps://emtunc.org calendar_today16-01-2017 15:15:26

1,1K Tweet

249 Followers

1,1K Following

Mikail Tunç (@emtunc) 's Twitter Profile Photo

Not ideal. Legitimate email and link from the NHS. Warning probably triggered because URI contains the word COVID in it.

Not ideal. Legitimate email and link from the NHS. Warning probably triggered because URI contains the word COVID in it.
Mikail Tunç (@emtunc) 's Twitter Profile Photo

Slack does a crappy job of session management on their desktop and mobile apps. Connection failure due to degraded service? No problem, let's sign you out of the 15 Workspaces you were in.

Maya Kaczorowski (@mayakaczorowski) 's Twitter Profile Photo

Some observations on the SolarWinds supply chain attack, now that I'm all caught up! Just a rundown of what I learned - citations included, all opinions my own 😄 /1

Mikail Tunç (@emtunc) 's Twitter Profile Photo

yo British Gas, what's up? you could have gone with something more neutral like "we're sorry but our legacy systems don't support special characters" instead of the patronising wording used here :)

yo <a href="/BritishGas/">British Gas</a>, what's up? you could have gone with something more neutral like "we're sorry but our legacy systems don't support special characters" instead of the patronising wording used here :)
Mikail Tunç (@emtunc) 's Twitter Profile Photo

Just blogged about responsible disclosure pages and how easy it can be to add one to your website - maybe this will help influence some small, meaningful change somewhere 😅 emtunc.org/blog/01/2022/w…

Mikail Tunç (@emtunc) 's Twitter Profile Photo

GitHub Security 2022: Branch Protection Edition. Have a read, you might find something useful! 😄 emtunc.org/blog/01/2022/g…

Mikail Tunç (@emtunc) 's Twitter Profile Photo

I uncovered a disturbing lack of security & privacy practices in the mobile apps of some well known orgs, including a couple of UK FinTechs. In this particular example, Identity documents and Biometric data were open to abuse. Collab with Cybernews cybernews.com/security/popul…

Mikail Tunç (@emtunc) 's Twitter Profile Photo

There's a lot of talk on passkeys and how they impact security. As with almost everything in life; there are pros and cons... so I did what any other sane person would do and blogged about it 😅 emtunc.org/blog/09/2022/p…

Mikail Tunç (@emtunc) 's Twitter Profile Photo

Hey Merton Council do better please. You're allowing PII (name, address, email, phone number, DOB) to be easily accessible by setting this ridiculous password as the default... what makes things worse is users aren't prompted to update from this weak password on log-in!

Hey <a href="/Merton_Council/">Merton Council</a> do better please. You're allowing PII (name, address, email, phone number, DOB) to be easily accessible by setting this ridiculous password as the default... what makes things worse is users aren't prompted to update from this weak password on log-in!
Clint Gibler (@clintgibler) 's Twitter Profile Photo

🔬 Open Sourcing Chronicle Detection Rules A collection of detection rules for Google’s cloud-native SIEM, Chronicle ➡️GitHub, Okta, Google Workspace, Slack AWS, Kubernetes, others coming soon Code: github.com/Algbra-Labs-OS… By Mikail Tunç labs.algbra.com/open-sourcing-…