







@elena@aseachange.com @aral@mastodon.ar.al I couldn't resist, so I've wasted my precious time looking at "W Identity" today. Things are not right. It is basically a repurposed https://github.com/PeterWaher/IoTGateway Just look here: https://root.widentity.eu/Settings/Master.md It has a socks4(?) open on port 1080, some xmpp stuff on 5222 and 5269, another (seemingly broken) version of the website on 8088. The following pages are accessible without auth: (found by a simple "`egrep -LR 'Privilege:|Login:' * |grep md | grep Root`" through the source) ``` /Settings/PersonalData/LocalDatabase.md /Settings/PersonalData/LocalSensorsAndDevices.md /Settings/PersonalData/EventLogs.md /Settings/PersonalData/NetworkIdentity.md /Settings/PersonalData/WebPages.md /Settings/PersonalData/Backups.md /Settings/Master.md /Copyright.md /Starting.md [http response 307] /Login.md /Entities.md /Templates/Repeat.md /AdminDropdownComponent.md /Script.md /AdminDropdown.md /AlertPopup.md /Master.md /PromptPopup.md /ConfirmPopup.md /Markdown.md /Emojis.md /Smileys.md /Index.md /MarkdownEditor.md /ScriptColors.md /Master.md ``` Others pages also exist (no 404), but are only available after login. Which brings me to the biggest problem of all. This is an **ADMIN** interface. Nobody should **ever** put an admin interface to an identity management platform on the internet. #WSocial #Widentity
Persistent, Sandboxed, Single-Site Browser (firejail and proxychains) - Michael Altfield's Tech Blog
Or how to avoid getting locked-out of another Google Account This guide will describe how to setup a persistent browser (for Evil Corp) that’s isolated in a sandbox (with firejail) and forced to use a SOCKS5 proxy to retain a static IP address (using proxychains) Have you ever been locked out of your own account, and then got an email for your service provider annoyingly letting you know that they’ve “blocked a login attempt — for your protection?“ There’s countless reports of frustrated users who have permanently lost access to their own gmail accounts because of Google’s faulty “fraud protection” systems that locked the account owner out of their own account, due to false-positives. Problem Especially the past 10 years, large corporations have been using machine learning anomaly detection systems on their login pages. Unfortunately, sometimes this is (ab)used to have priority over credential authentication challenges. Even if you enter your username, password, and 2FA credentials correctly on the very first login attempt, you may get locked out of your own account because you “look different” Even if you enter your username, password, and 2FA credentials correctly on the very first login attempt, you may get locked . . . → Read More: Persistent, Sandboxed, Single-Site Browser (firejail and proxychains)

README
This is a browser extension that provides “wormhole” navigation between different AT Protocol/Bluesky services inspired by Dame’s Shortcut. The extension transforms URLs and identifiers from one service to equivalent URLs on other services.
Elena Rossini 🌈 (@_elena@mastodon.social)
Attached: 2 images I just refreshed the #WSocial website and it's showing a MAJOR redesign... with a label at the top stating "built on the open AT-protocol." This is the first time ever they acknowledge this – I know, as I've been visiting their website for MONTHS and also never heard about this in any interviews. So the claims in my exposé stand (the Internet Archive's Wayback Machine would confirm this). Of note: they changed their URL from wsocial.eu to wsocial.news BTW thanks for all your feedback ❤️
No more “Root” features in Orbot… use Orfox & VPN instead!
People, Apps and Code You Can Trust

Weird netizens — Open Indie
It's been a year since I wrote about Weird web pages as a prospective catalyst for the reclamation of my digital identity. There's been s...
@thisismissem.social @divy.zone and I recently went through an exploration of how the browser can help you login to websites with atproto accounts. We recently presented to the FedID CG and here is a sneak peek in case you couldn't join! This is early but we'd love your input before we go too far!
It looks like W Identity, the part of @wsocial.eu that checks your papers before you go in, has a very basic XSS on its admin backend, found hours after launch. This seems almost too predictable... Cyberfriends, any thoughts on how bad? 23.social/@kantorkel/116767220594438841
kantorkel (@kantorkel@23.social)
23.social@wsocial.eu - I was one of the first to subscribe after Davos, but now I wonder what's the use of WSocial. We had to show our ID to get access, but now it seems there are many backdoors without the need for verification. Maybe I just go back to Mastodon. Nice try, but I feel a little betrayed.
🦫 alert! We published the second episode of "Teach the Web new Tricks", featuring native support for @atproto.com ! Learn more how we improve user agency and privacy at webbeef.org/atproto.html : - Native at:// protocol support. - Log in your PDS and forget OAuth ! - Authorize 3rd parties
Halfway through finishing my @astro.build @standard.site plugin to post my blog posts into #atproto and also pull my @leaflet.pub posts out and sync them! @pfrazee.com I hear you're building a full renderer!
Hey @surf.social the atproto early adopter / tech community can’t recommend you until you implement OAuth. This is a pretty big user security issue. Let us know if you need help or contract @thisismissem.social
im'bcmgs'im
surf.social looks amazing but idk about this login experience... i dont normally wanna put my password for one site into another site 🙃
I built a translator between Atproto's OAuth and OIDC, so apps like @tailscale.com can use your Bluesky identity. It includes a whitelist so you can invite people directly using their DID!
Decentralised Identity 🤝 Mesh Networking
thinking-with-portals.leaflet.pubso uhh... I needed a thing and it is here - tangled.org/sparrowtek.com/atproto-auth-p…
sparrowtek.com/atproto-auth-proxy
tangled.org