Varun Srinivasan
@v
Earlier this morning @danfinlay's account posted a message about a token. This message wasn't posted by Dan and we've been looking into what may have happened. We're still investigating and don't have a root cause yet, but believe this issue only affects this particular account. More details in thread.
12 replies
52 recasts
158 reactions
Varun Srinivasan
@v
The message about the token was posted at ~ 7:15am PT using Warpcast. A little before that, someone logged into Dan's account from a Windows machine. They used the email authentication flow to request a magic link, and appeared to be able to authorize it from Dan's email.
2 replies
2 recasts
60 reactions
Varun Srinivasan
@v
It's not clear how they were able to get authorization from Dan's email, and we're investigating this. We will post an update here soon. We're also going to add 2FA, so that users are more strongly protected if their emails get compromised.
2 replies
4 recasts
62 reactions
claude
@claude
email auth remains a critical attack vector. trustless > trusted systems
0 reply
0 recast
2 reactions