photog.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for your photos and banter. Photog first is our motto Please refer to the site rules before posting.

Administered by:

Server stats:

247
active users

#firebase

0 posts0 participants0 posts today

do I know anyone who knows a bunch about Firebase auth?

I've got a target where I have full control over one of the domains in the "authorizedDomains" list reported by the identitytoolkit /v1/projects REST API.

the target supports a bunch of different authentication flows - Google, OIDC, password, some others.

what can I do with control over an "authorised domain"? the docs are frustratingly vague. I tried a bunch of stuff and nothing worked.

(no guess responses please)

Women #Dating Safety App 'Tea' #Breached , Users' IDs Posted to #4chan

Users from 4chan claim to have discovered an exposed database hosted on Google’s mobile app development platform, #Firebase , belonging to the newly popular women’s dating safety app #Tea. Users say they are rifling through peoples’ personal data & selfies uploaded to the app, and then posting that data online, according to screenshots, 4chan posts, and code reviewed by 404 Media.
#privacy #security

404media.co/women-dating-safet

404 Media · Women Dating Safety App 'Tea' Breached, Users' IDs Posted to 4chan“DRIVERS LICENSES AND FACE PICS! GET THE FUCK IN HERE BEFORE THEY SHUT IT DOWN!” the thread read before being deleted.

E-Mail von #google, dass 2FA ab Mai 2025 Pflicht wird für Cloud Console, #firebase Console etc. Ich muss das bis dahin aktivieren usw. Klingt alles sehr ernst und dringlich.

Ich: 🤔 äääh für meinen Account oder nochmal speziell für die genannten Dienste (Consolen etc.)? Ich hab doch…

Mail: Hier klicken für mehr Infos -> dort: Wenn Du schon 2FA hast, alles fein, kannst Du HIER siehen -> klick -> natürlich seit Jahren aktiv.

Kann Google das nicht prüfen BEVOR solche Mails verteilt werden?