Dominic White
singe@chaos.social
<p>Hacker at Orange Cyberdefense’s SensePost Team</p>
Posts
-
Post #4441001
I haven’t settled my thoughts on the OpenAI incident but I can’t help but feel that the threat modelling & security engineering applied up-front to long-term xhigh training runs with no cyber guard-rails was seriously shoddy. Easy to say after the fact. (1/3)
-
Post #4196566
I’ve seen a few dry runs of the absolutely fire talk Reino has prepped for everyone at DEFCON this year. Want to see multiple exploit chains on a widely deployed PED device deemed so impactful the vendor asked us to wait two years to disclose, then catch “Very Pwned” https://info.defcon.org/defcon34/content/66621
-
Post #4099417
I really like this evaluation matrix from @Roeloftemmingh@infosec.exchange @bsidesjoburg@infosec.exchange keynote for judging quality in a flood of AI slop. The one that resonated with me in particular was: “Has this person ever paid a cost for being wrong”
-
Post #3956891
I put up a writeup of our @sensepost@infosec.exchange annual artwork up here https://sensepost.com/blog/2026/senseposts-2026-artwork/ Free downloads if you like it.
-
Post #2078573
I was interviewed for a local TV about the legislation &amp; enforcement of personal data protection in South Africa. It was triggered by the sentencing of the person convicted of the Experian breach. I made the point that credit bureaus remain the problematic loophole in our privacy legislation while they are allowed to collect data &amp; sell it without our consent - beyond purposes of fraud prevention. My bit was clipped but I’m happy we got Szymon’s new art project in. https://you...
-
Post #1684524
Periodic reminder - there’s no easy way to clear tracking cookies and other cruft from iOS apps. But you can do it across all of them with one easy shortcut! It won’t log you out of the app just get rid of the cruft from the in-app browser. prefs:root=SAFARI&amp;path=CLEAR_HISTORY_AND_DATA
-
Post #1560417
I’m reminded of the disconnect between typical vuln scan/pentest XSS findings and real world exploitation by this write up of Russian exploitation of webmail apps https://ctrlaltintel.com/threat%20research/FancyBear/ How do you demonstrate XSS impact beyond the classic alert dialog or cookie stealer?