BobDaHacker 🏳️⚧️
Can we hack it?? Yes we can!!! 😎😎😎
Hey Im BobDaHacker an ethical hacker 🤓
Thx 4 coming to my ted talk
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
Anyone based in Tokyo want to make some friends? :3
im 20TF, been here since last summer. im very geeky and i love everything tech, cybersecurity, and programming. i also love animals, nature, geocaching, theme parks, musicals, cocktail mixing, baking, hiking, travelling, gaming, playing clarinet, listening to music (Tally Hall, Will Wood, classic rock, metal etc), tv shows, movies, and crime documentaries. i also turned my apartment into a whole hangout spot with a dart machine, karaoke, and a room full of 400 Blåhajs, (I call the Blåhaj pit) lol
always free and always down to grab a drink or explore the city.
#tokyo #japan #friends #t4t #cybersecurity #infosec #techie #gaming #hiking #karaoke
Found critical vulns in Lovense (the biggest sex toy company) affecting 11M+ users. They ignored researchers for 2+ years, then fixed in 2 days after public exposure. 🤦
What I found:
- Email disclosure via XMPP (username→email)
- Auth bypass (email→account takeover, no password)
History of ignoring researchers:
- 2017: First recorded case of someone reporting XMPP email leak.
- 2022: Someone else reports XMPP email leak, ignored
- Sept 2023: Krissy reports account takeover + different email leak via HTTP API, paid only $350
- 2024: Another person reports XMPP email leak AND Account Takeover vuln, offered 2 free sex toys (accepted for the meme)
- March 2025: I report account takeover + XMPP email leak, paid $3000 (after pushing for critical)
- Told me fix for email vuln needs 14 months because "legacy support" > user security (had 1-month fix ready)
- July 28: I go public
- July 30: Both fixed in 48 hours
Same bugs, different treatment. They lied to journalists saying it was fixed in June, tried to get me banned from HackerOne after giving permission to disclose.
News covered it but my blog has the full technical details: https://bobdahacker.com/blog/lovense-still-leaking-user-emails/
#InfoSec #BugBounty #ResponsibleDisclosure #Security #Vulnerability #IoT #cybersecurity
I'm at 39C3 you can call me at 24630
Ok
#39C3 #ccc #gay #cybersecurity #germany #hamburg #likeandshare #penis
@AlexQR@mastodon.social blud, what are you on about



