Was surfing the internet and found some kid who is sharing his malware proof-of-concepts online. His work is primarily recycling and recreating existing techniques for him to study or to demonstrate the ideas to others.
Is his code good? No, God no. It is littered with errors, poor naming conventions, and extremely dangerous control flow. I love it him for this, unironically.
This kid having bad code shows he isn't using AI to work. He is legit. He is putting himself out there, demonstrating what he can do (or can't do), and showing he isn't afraid to get criticized.
I love seeing people grind and put in the work. It's the pain that makes you good. Taking shortcuts doesn't achieve anything.
I don't know if it he is on social media stuff, but you're doing good stuff, "CaptMag". Keep putting in work. You'll go far. I see you, gang.
Is his code good? No, God no. It is littered with errors, poor naming conventions, and extremely dangerous control flow. I love it him for this, unironically.
This kid having bad code shows he isn't using AI to work. He is legit. He is putting himself out there, demonstrating what he can do (or can't do), and showing he isn't afraid to get criticized.
I love seeing people grind and put in the work. It's the pain that makes you good. Taking shortcuts doesn't achieve anything.
I don't know if it he is on social media stuff, but you're doing good stuff, "CaptMag". Keep putting in work. You'll go far. I see you, gang.
β€179π₯°15π12π«‘7β€βπ₯4π3π1π―1
vx-underground
Was surfing the internet and found some kid who is sharing his malware proof-of-concepts online. His work is primarily recycling and recreating existing techniques for him to study or to demonstrate the ideas to others. Is his code good? No, God no. It isβ¦
I'm sorry, CaptMag, I love you, dawg, but I audibly laughed when you initialized your unsigned integers (DWORD) to NULL.
If you want to get really technical, NULL on Windows is defined as zero, so it ... sort of ... makes sense, you are technically setting your unsigned integers to zero, but NULL is supposed to indicate an invalid pointer.
I have no idea how your IDE hasn't been screaming at you about this.
If you want to get really technical, NULL on Windows is defined as zero, so it ... sort of ... makes sense, you are technically setting your unsigned integers to zero, but NULL is supposed to indicate an invalid pointer.
I have no idea how your IDE hasn't been screaming at you about this.
β€82π€£38π±9π7π₯°5β€βπ₯3π€©1
> be nerds
> look into persona (used by discord)
> kyc (know your customer) service
> used for age verification
> search on internet (shodan)
> find weird server
> image 1
> openai-watchlistdb.withpersona
> openai-watchlistdb-testing.withpersona
> lolwtf
> look inside
> supposed to be behind cloudflare to hide ip
> openai messed up
> not behind cloudflare
> real ip shown
> using google cloud
> lookup cert history
> 2023-11-16 created
> 2024-02-28 gets cert
> 2024-03-04 prod goes live
> google stuff
> openai and persona partners
> partner around timeline of certs
> back to searching stuff
> find withpersona-gov
> look inside
> okta (image 2)
> lolwtf
> look inside
> website accidentally leaking stuff
> fedramp-private-backend-api
> look inside
> api .js accidentally exposed
> look inside
> wtf "SARInstructionsCard"
> wtf "app.onyx.withpersona-gov"
> wtf "FINTRAC"
> wtf "PrivatePartnershipProjectNameCodes"
> image 3
> wtf "AsyncSelfie"
> look inside
> openai, persona, send data to us gov
> feds map face to financial records
> map face using AI
> map face to ICE stuff
> api stores data for lots of stuff
> image 4
tl;dr persona kyc and openai are frens, using your selfie for verification and sending to ICE (or USGOV in general), using AI to tie to your financial records. see subsequent post for full write-up. its long and not mobile friendly
> look into persona (used by discord)
> kyc (know your customer) service
> used for age verification
> search on internet (shodan)
> find weird server
> image 1
> openai-watchlistdb.withpersona
> openai-watchlistdb-testing.withpersona
> lolwtf
> look inside
> supposed to be behind cloudflare to hide ip
> openai messed up
> not behind cloudflare
> real ip shown
> using google cloud
> lookup cert history
> 2023-11-16 created
> 2024-02-28 gets cert
> 2024-03-04 prod goes live
> google stuff
> openai and persona partners
> partner around timeline of certs
> back to searching stuff
> find withpersona-gov
> look inside
> okta (image 2)
> lolwtf
> look inside
> website accidentally leaking stuff
> fedramp-private-backend-api
> look inside
> api .js accidentally exposed
> look inside
> wtf "SARInstructionsCard"
> wtf "app.onyx.withpersona-gov"
> wtf "FINTRAC"
> wtf "PrivatePartnershipProjectNameCodes"
> image 3
> wtf "AsyncSelfie"
> look inside
> openai, persona, send data to us gov
> feds map face to financial records
> map face using AI
> map face to ICE stuff
> api stores data for lots of stuff
> image 4
tl;dr persona kyc and openai are frens, using your selfie for verification and sending to ICE (or USGOV in general), using AI to tie to your financial records. see subsequent post for full write-up. its long and not mobile friendly
β€76π±39π€£21π€―6π₯°5π’3π₯1
vx-underground
> be nerds > look into persona (used by discord) > kyc (know your customer) service > used for age verification > search on internet (shodan) > find weird server > image 1 > openai-watchlistdb.withpersona > openai-watchlistdb-testing.withpersona > lolwtf >β¦
full write up: https://vmfunc.re/blog/persona
vmfunc.re
the watchers: how openai, the US government, and persona built an identity surveillance machine that files reports on you to theβ¦
53MB of source code leaked from a government endpoint. 269 verification checks. biometric face databases. SAR filings to FinCEN. and the same company that verifies your ChatGPT account.
β€42π₯14π₯°3π€1
vx-underground
> be nerds > look into persona (used by discord) > kyc (know your customer) service > used for age verification > search on internet (shodan) > find weird server > image 1 > openai-watchlistdb.withpersona > openai-watchlistdb-testing.withpersona > lolwtf >β¦
1. i didnt discover this, vmfunc and friends did. im regurgitating their stuff
2. ive been informed discord stopped using persona. they use something else now. persona is still used in lots of places (like apparently roblox)
3. vmfunc and friends are still doing a write up about it and trying to talk to persona about it.
https://x.com/vmfunc/status/2024100827510517891
2. ive been informed discord stopped using persona. they use something else now. persona is still used in lots of places (like apparently roblox)
3. vmfunc and friends are still doing a write up about it and trying to talk to persona about it.
https://x.com/vmfunc/status/2024100827510517891
X (formerly Twitter)
celeste (@vmfunc) on X
update on "the watchers"
we are in direct written correspondence with persona's CEO. he's been responsive. he's been engaged. all exchanges will be published in full in part 2. a part 3 might be coming too.
now. about the names.
the personnel section wasβ¦
we are in direct written correspondence with persona's CEO. he's been responsive. he's been engaged. all exchanges will be published in full in part 2. a part 3 might be coming too.
now. about the names.
the personnel section wasβ¦
π€£45β€βπ₯12β€4π₯°4π’1
Earlier today X employees bragged X only has 30 employees. Guess which website is down again?
π€£167β€9π―7π₯4π₯°3
Meanwhile at Microsoft: Microsoft deployed botched security rules and Exchange Online accidentally flagged legitimate emails as malicious.
From February 5th to February 12th, "thousands" of safe emails were flagged as phishing emails
https://www.bleepingcomputer.com/news/microsoft/microsoft-anti-phishing-rules-mistakenly-blocked-emails-teams-messages/
From February 5th to February 12th, "thousands" of safe emails were flagged as phishing emails
https://www.bleepingcomputer.com/news/microsoft/microsoft-anti-phishing-rules-mistakenly-blocked-emails-teams-messages/
BleepingComputer
Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages
Microsoft says an Exchange Online issue that mistakenly quarantined legitimate emails last week was triggered by faulty heuristic detection rules designed to block credential phishing campaigns.
π₯°35π7π4β€3
vx-underground
Meanwhile at Microsoft: Microsoft deployed botched security rules and Exchange Online accidentally flagged legitimate emails as malicious. From February 5th to February 12th, "thousands" of safe emails were flagged as phishing emails https://www.bleepiβ¦
tldr if you're missing an email, or forgot to read an email, just blame it on Microsoft. Ez GG
π₯°46π11β€4
> be me
> working
> wife and baby sleeping
> hear blood-curdling scream
> "HELP"
> run fast af
> blast through door
> 11 month old climbed over baby barricade
> wife holding him by foot
> dangling off bed
> wife terrified
> grab baby
> he looks at me
> smiles
> starts laughing
> wife crying from pure terror
> baby sees her crying
> laughs
mfw baby almost killed himself, thinks its hilarious
> working
> wife and baby sleeping
> hear blood-curdling scream
> "HELP"
> run fast af
> blast through door
> 11 month old climbed over baby barricade
> wife holding him by foot
> dangling off bed
> wife terrified
> grab baby
> he looks at me
> smiles
> starts laughing
> wife crying from pure terror
> baby sees her crying
> laughs
mfw baby almost killed himself, thinks its hilarious
π±90π€£66π15β€6π’6π₯°5
vx-underground
> be me > working > wife and baby sleeping > hear blood-curdling scream > "HELP" > run fast af > blast through door > 11 month old climbed over baby barricade > wife holding him by foot > dangling off bed > wife terrified > grab baby > he looks at me > smilesβ¦
Babies have no concept of danger. All they know right now is "I can go places" and "I want to go places". He probably think it's funny Mommy and Daddy gave him a bunch of attention and thought falling was like a fun little ride.
tl;dr on constant suicide watch
tl;dr on constant suicide watch
π₯71π₯°22π«‘11β€7π6π€£5π2
I guess Persona saw my post, or other adjacent posts on social media, because Persona sent out an email addressing the findings to their customers.
They wrote the following (although I'm paraphrasing):
1. Persona does not share your customers data outside of scope. They said all contracts are solidified and compliance is important
2. Persona does not work with the Department of Homeland Security, or the United States government in general, however they assert they admit they are seeking potential contracts
3. Persona is not involved with Peter Thiel, although he is an investor. Persona asserts they have no relationship with Palantir
4. Company employees, including investors, do not have access to customer data.
5. They don't plan on saying anything else about this posts on social media because it amplifies stuff. They politely and gently call social media people schizo conspiracy theorists and state they are privately engaging with accredited journalists behind the scenes.
They wrote the following (although I'm paraphrasing):
1. Persona does not share your customers data outside of scope. They said all contracts are solidified and compliance is important
2. Persona does not work with the Department of Homeland Security, or the United States government in general, however they assert they admit they are seeking potential contracts
3. Persona is not involved with Peter Thiel, although he is an investor. Persona asserts they have no relationship with Palantir
4. Company employees, including investors, do not have access to customer data.
5. They don't plan on saying anything else about this posts on social media because it amplifies stuff. They politely and gently call social media people schizo conspiracy theorists and state they are privately engaging with accredited journalists behind the scenes.
π€£83π₯°5π€5π―2β€1