Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Dominic White

@singe@chaos.social
mastodon 4.5.15
  • Open on chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

0 Followers
0 Following
15 Posts
Joined October 30, 2022
Twitter:
https://twitter.com/singe
Work Blog:
https://sensepost.com/blog
Personal Blog:
https://singe.za.net
Get in Touch:
https://hello.singe.za.net

Posts

Open post
singe
Dominic White @singe@chaos.social · Aug 07, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
Replying to @singe@chaos.social
And unlike traditional cyber insider defence they have access to the attackers thoughts! Those thoughts appear to have revealed the patterns of abuse regularly. This speaks to a scary lack of monitoring of high autonomy agents that can have vast implications beyond just cyber. (3/3)
6
1
1
0
Open post
singe
Dominic White @singe@chaos.social · Aug 07, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
Replying to @singe@chaos.social
A shared package proxy vulnerable to file writes with a simple PUT, that was exploited with hundreds (thousands?) of writes by many different agents speaks both to shoddy security, monitoring and a failure of imagination. Then to have it happen again without a major rethink! (2/3)
6
1
1
0
Open post
singe
Dominic White @singe@chaos.social · Aug 07, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
I haven’t settled my thoughts on the OpenAI incident but I can’t help but feel that the threat modelling & security engineering applied up-front to long-term xhigh training runs with no cyber guard-rails was seriously shoddy. Easy to say after the fact. (1/3)
5
3
3
0
Open post
singe
Dominic White @singe@chaos.social · Jul 29, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
I’ve seen a few dry runs of the absolutely fire talk Reino has prepped for everyone at DEFCON this year. Want to see multiple exploit chains on a widely deployed PED device deemed so impactful the vendor asked us to wait two years to disclose, then catch “Very Pwned” https://info.defcon.org/defcon34/content/66621
15
0
7
0
Open post
singe
Dominic White @singe@chaos.social · Jul 25, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
I really like this evaluation matrix from @Roeloftemmingh@infosec.exchange @bsidesjoburg@infosec.exchange keynote for judging quality in a flood of AI slop. The one that resonated with me in particular was: “Has this person ever paid a cost for being wrong”
2
0
1
0
Open post
singe
Dominic White @singe@chaos.social · Jul 20, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
I put up a writeup of our @sensepost@infosec.exchange annual artwork up here https://sensepost.com/blog/2026/senseposts-2026-artwork/ Free downloads if you like it.
0
0
0
0
Open post
singe
Dominic White @singe@chaos.social · Jun 03, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
Replying to @nuthatch@infosec.exchange
@nuthatch@infosec.exchange @adamshostack@infosec.exchange that' so useful, than you! Did it work for you Adam?
0
2
0
0
Open post
singe
Dominic White @singe@chaos.social · Apr 19, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social

I’m reminded of the disconnect between typical vuln scan/pentest XSS findings and real world exploitation by this write up of Russian exploitation of webmail apps https://ctrlaltintel.com/threat%20research/FancyBear/

How do you demonstrate XSS impact beyond the classic alert dialog or cookie stealer?

1
0
1
0
Open post
singe
Dominic White @singe@chaos.social · Apr 18, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social

Periodic reminder - there’s no easy way to clear tracking cookies and other cruft from iOS apps. But you can do it across all of them with one easy shortcut! It won’t log you out of the app just get rid of the cruft from the in-app browser.

prefs:root=SAFARI&path=CLEAR_HISTORY_AND_DATA

8
4
7
0
Open post
singe
Dominic White @singe@chaos.social · Mar 27, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
Replying to @haroonmeer@infosec.exchange
@haroonmeer@infosec.exchange I figured invoking “crumbs on the table” could have had some play with the content.
1
0
0
0
Open post
singe
Dominic White @singe@chaos.social · Mar 27, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
Replying to @haroonmeer@infosec.exchange
@haroonmeer@infosec.exchange by far the most important part of this was the title, which is why I boldly ask: did you mean “crummy”?
1
2
0
0
Open post
singe
Dominic White @singe@chaos.social · Mar 21, 2026
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
Replying to @chetwisniewski@securitycafe.ca
@chetwisniewski @tomw @campuscodi GoldDigger malware has been rampant in South Africa and Southeast Asia for the last year and a half or more. This will make a big difference.
4
0
1
0
Open post
singe
Dominic White @singe@chaos.social · Aug 20, 2023
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
Replying to @samw@hacksrus.xyz
@samw @jarkman did you find it? Work out why it didn’t return?
1
1
0
0
Open post
singe
Dominic White @singe@chaos.social · Mar 02, 2023
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social

I was interviewed for a local TV about the legislation & enforcement of personal data protection in South Africa. It was triggered by the sentencing of the person convicted of the Experian breach. I made the point that credit bureaus remain the problematic loophole in our privacy legislation while they are allowed to collect data & sell it without our consent - beyond purposes of fraud prevention.

My bit was clipped but I’m happy we got Szymon’s new art project in.

https://youtube.com/watch?v=-kmIPSJkeJs

Cybercrime in SA | 'Personal info data breaches rife in SA'
YouTube

Cybercrime in SA | 'Personal info data breaches rife in SA'

eNCA

8
0
1
0
Open post
singe
Dominic White @singe@chaos.social · Nov 13, 2022
Dominic White
@singe@chaos.social

Hacker at Orange Cyberdefense’s SensePost Team

chaos.social
Replying to @rixx@chaos.social
@rixx “ because having an instance is work, and being a troll is free” fantastic insights into how much work this is. Thank you from a recent joiner.
2
0
0
0

Remote instance

chaos.social
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:53:49 UTC