Twitter actually shipped this trivial security issue

  Рет қаралды 149,178

NeetCodeIO

NeetCodeIO

Күн бұрын

🚀 neetcode.io/ - A better way to prepare for Coding Interviews
Post from the video: / gergelyorosz_this-week...
🧑‍💼 LinkedIn: / navdeep-singh-3aaa14161
🐦 Twitter: / neetcode1
⭐ BLIND-75 PLAYLIST: • Two Sum - Leetcode 1 -...
#neetcode #leetcode #python

Пікірлер: 371
@johongo
@johongo 27 күн бұрын
would have been hilarious if they reversed it by replacing "x" with "twitter"
@capsey_
@capsey_ 21 күн бұрын
that would be etwittertremely funny
@fractastical9040
@fractastical9040 20 күн бұрын
@@capsey_ that would be x.twitteryz funny
@charliesretrocomputing
@charliesretrocomputing 20 күн бұрын
That would have been so etwitterciting to see!
@Exachad
@Exachad 19 күн бұрын
Immediately registering TwitterVideos domain then.
@Cbp846
@Cbp846 19 күн бұрын
setwitter
@juusolatva
@juusolatva 20 күн бұрын
I love that everyone still calls it Twitter
@notmyname998
@notmyname998 19 күн бұрын
Why would anyone stop calling it Twitter? Just because one man decided not to call it Twitter that doesn't mean that the name changed, it is the same as if I start calling my car a Ferrari when it's in fact a BMW... No one else will call it Ferrari. The same thing with Facebook, it will always be Facebook because this is how people know it
@DarkGob
@DarkGob 19 күн бұрын
@@notmyname998 I mean, if the *owner* starts calling it something else, then yeah that does mean that the name changed. The problem is that Elon Musk inexplicably doesn't seem to understand just how valuable a brand can be. You can't buy the name recognition that Twitter has/had, and he just went and tried to flush it down the toilet (or pour it down the sink, perhaps). Ironically, he failed precisely because of how much name recognition Twitter does have -- it has penetrated far too deep into the public psyche for anyone to call the site anything else. The fact that the site URL remained unchanged for so long didn't help either, nor did Elon's antics that made it so most people just refused to acknowledge this dumb vanity project of an "everything app" that he clings to like a security blanket.
@vappyreon1176
@vappyreon1176 18 күн бұрын
​@@notmyname998 it's not even that, it's just that x is a dumb name and Twitter is less dumb
@madhausen
@madhausen 18 күн бұрын
@@notmyname998 I prefer to call it Thefacebook 😎
@notmyname998
@notmyname998 18 күн бұрын
Also true
@prosfilaes
@prosfilaes 23 күн бұрын
In 1994, TSR published the Encyclopedia Magicka; unfortunately, at the last moment, an editor had changed mage to wizard. It fixed the use of "mage" in the text, but it also changed all versions of damage to dawizard and image to iwizard. Funny that Twitter actually did this live.
@635574
@635574 23 күн бұрын
Lmao and this bugged version got printed? Coul have been 2 other substitution from fixing it as well.
@Stratelier
@Stratelier 22 күн бұрын
This is why search-replace functions typically include a "whole word" option.
@seanwilson9925
@seanwilson9925 20 күн бұрын
The iWizard pro max
@sycration
@sycration 20 күн бұрын
newest apple devices leaked
@Pallidum
@Pallidum 20 күн бұрын
A clbuttic mistake.
@chernobyl169
@chernobyl169 22 күн бұрын
I never would have guessed that laying off 75% of the staff, reorganizing the business, handing down functionality edicts, and running the company on shoestrings would result in lack of oversight and technical debt so egregious that it leads to easily exploitable feature creep on a monthly basis OH WAIT, YES I DID. MANY TIMES.
@derpaboopderp1286
@derpaboopderp1286 20 күн бұрын
Good job man 🎉
@cinex20
@cinex20 17 күн бұрын
lack of foresight*
@fangirlmc
@fangirlmc 16 күн бұрын
and yet old Twitter was definitely worse than new Twitter.
@UltimaDoombotMK1
@UltimaDoombotMK1 16 күн бұрын
​@@cinex20Lack of any kind of sight* Look at Elon, do you think he's actually smart enough to have hindsight?
@floreroafloreril1458
@floreroafloreril1458 16 күн бұрын
​@@fangirlmcIt wasn't. There were less pedos and extremists. Lol
@newold1093
@newold1093 Ай бұрын
This is what happens when you have Elon as your code reviewer 😂
@tiagorainho5011
@tiagorainho5011 28 күн бұрын
Yeah because its the ceo reviewing the code 🤡
@alexstomberg8306
@alexstomberg8306 28 күн бұрын
@@tiagorainho5011 fr lol
@netrunner01
@netrunner01 27 күн бұрын
@@tiagorainho5011 Elon literally made engineers print out code and present it to him when he bought Twitter 😂. He's a known micromanager
@jacobstamm
@jacobstamm 27 күн бұрын
@@tiagorainho5011You’re joking, but that is literally what happened.
@2BTO
@2BTO 26 күн бұрын
@@tiagorainho5011delete this comment buddy
@Sabagegah
@Sabagegah 23 күн бұрын
S E C U R I T Y I S S U E I N B I O
@mariobot128
@mariobot128 18 күн бұрын
The security team got fired because they weren't writing enough lines of code
@antonliakhovitch8306
@antonliakhovitch8306 12 күн бұрын
This... actually sounds plausible.
@SuperShado101
@SuperShado101 9 күн бұрын
​@@antonliakhovitch8306This is what Elon said he did, so yeah
@randys2669
@randys2669 5 күн бұрын
​@@antonliakhovitch8306Some of Twitter's layoffs were literally decided based on numbers of lines of code. It's not just plausible, it's likely.
@ExzaktVid
@ExzaktVid 5 күн бұрын
How to add more lines to your code, easy tutorial below If( 1+1=2 ) { Live} Else{ Die}
@hpsmash77
@hpsmash77 4 күн бұрын
​@@ExzaktVid ==*
@Pockeywn
@Pockeywn 19 күн бұрын
why do i feel like elon just went in and coded this himself
@LeetHaxington
@LeetHaxington 20 күн бұрын
Why didn't Elon catch this in his office walk printed code code review? I thought return to office guaranteed this wouldn't happen
@SioxerNikita
@SioxerNikita 15 күн бұрын
He is a mediocre coder at best, proven back in the day
@hairyballbastic8943
@hairyballbastic8943 15 күн бұрын
he's also a poop homunculus
@hairyballbastic8943
@hairyballbastic8943 15 күн бұрын
he's also a poop homunculus
@alexpkeaton4471
@alexpkeaton4471 14 күн бұрын
That printed code is still in the mail somewhere.
@sirseven3
@sirseven3 13 күн бұрын
​@@SioxerNikitaI remember how broken PayPal was before they sold...
@ladyalicent705
@ladyalicent705 16 күн бұрын
As a wise man once said: “If he can deadname his own daughter, we can deadname his goofy ahhh platform”
@joshy541
@joshy541 14 күн бұрын
It ain't his, he just adopted it and tried to rename yet another of his children to something with an X in it
@ladyalicent705
@ladyalicent705 14 күн бұрын
@@joshy541 I’m talking about Vivian, not XÆA-12
@joshy541
@joshy541 14 күн бұрын
@@ladyalicent705 yeah I got you, I'm just saying he adopted Twitter and tried to force a new name on it. Because Twitter sure as heck didn't want to be renamed
@TuhljinTampergauge
@TuhljinTampergauge 11 күн бұрын
Men can't give birth.
@TuhljinTampergauge
@TuhljinTampergauge 11 күн бұрын
KZbin doesn't want you to know this, but here's a secret knowledge from the before time (literally couldn't post this without this preamble to throw off the bot): Men can't give birth.
@jaade9485
@jaade9485 18 күн бұрын
a spiteful childish change AND its poorly implemented? nooo that doesnt sound like elon at all
@MawdyDev
@MawdyDev 17 күн бұрын
The Muskrat gave the original Twitter staff a crappy ultimatum and most of them walked out. He's likely been struggling to hire experienced coders, because people with any shred of confidence refuse to work for him.
@christopherstaples6758
@christopherstaples6758 24 күн бұрын
@4:20 , actually you can just pass the user / password to the real website and still log them , the end user is still none the wiser , nothing stoping you from running another website fully within your phising site , with input logging
@635574
@635574 23 күн бұрын
This is a few standard deviations above average scammer IQ
@jellifygirl
@jellifygirl 21 күн бұрын
​@@635574Rather, there's no need to bother. Once you've got their details, you've got their details.
@enderkatze6129
@enderkatze6129 20 күн бұрын
Good to know.
@EntityVsEntityInteractions
@EntityVsEntityInteractions 17 күн бұрын
To do so effectively and in a convincing way (not displaying a tab within a tab, not taking 10s+ to load, etc) would require a lot more effort & expertise than the average phisher has at their disposal...
@biigsmokee
@biigsmokee 16 күн бұрын
@@EntityVsEntityInteractions wrong, setoolkit is open source and widely available
@omri9325
@omri9325 27 күн бұрын
Microsoft Azure password change page takes the crown on horrible UI that looks like phishing
@sehaless
@sehaless 21 күн бұрын
I don't use azure, what are they doing? Do you have a TL;DR?
@inverlock
@inverlock 21 күн бұрын
@@sehalessit’s a dev UI straight out of 2004
@sehaless
@sehaless 21 күн бұрын
@@inverlock oof, hey, at least it's fast.. right?
@Bpinator
@Bpinator 21 күн бұрын
Lmao it does, it looks so old. Theres a lot of little legacy items still kicking around in Azure/365
@U20E0
@U20E0 19 күн бұрын
and Oracle's entire site
@DogsRNice
@DogsRNice 17 күн бұрын
Reminds me of a Minecraft server I joined like 11 years ago that had a word filtering plugin to stop swearing Except they somehow configured it to change "hello" to "hekko" Presumably trying to prevent anyone from saying "hell"
@brucewayne1777
@brucewayne1777 15 күн бұрын
That's a known issue called the scunthrope problem.
@dylanharding5720
@dylanharding5720 13 күн бұрын
​@@brucewayne1777scunthorpe, not scunthrope. And of course, there's a ton of other towns with those types of names - Penistone for example.
@addison1024
@addison1024 13 күн бұрын
@@brucewayne1777also seen frequently with penistone
@antonliakhovitch8306
@antonliakhovitch8306 12 күн бұрын
​@@brucewayne1777*Scunthorpe
@Starwort
@Starwort 11 күн бұрын
​@@brucewayne1777it's a clbuttic problem
@neonoir__
@neonoir__ 14 күн бұрын
this is what happens when the company culture is "just do whatever dumb shit elon wants without asking questions if you dont wanna be fired"
@green8026
@green8026 26 күн бұрын
obviously a bad bug, but completely ridiculous to say "I cannot imagine an experienced software engineer who wouldn't consider security vulnerabilities with URL rewrites". as a software quality professional, I have found COUNTLESS bad bugs from people who have been software engineers for 10+ years. bugs that reveal PHI, XSS bugs, bugs that bring down entire sites, etc
@Templarfreak
@Templarfreak 20 күн бұрын
obviously that 10+ years of experience was _not_ in security for them XD
@Charlie7753
@Charlie7753 20 күн бұрын
But in this case it wasnˋt a bug.
@danielr8257
@danielr8257 20 күн бұрын
Most of the bugs or vulnerabilities that experienced software engineers add in are not intuitive and mistakes get made because it isn't an issue that is often encountered in regular development and require special consideration. Every software engineer is well aware of the limits of search and replace, it's the reason you always use "refactor" in your IDE instead of "find and replace". It's practically one of the first things you learn as a software engineer, when you try to change a variable name and it ends up changing a bunch of other stuff you didn't want it to as well. Extending that intuition to URL replacements is such a small logical leap. I'm a very inexperienced software developer and even I make sure to be extra careful when having to parse strings because there are always a ridiculous number of edge cases to account for (e.g. word extraction can't just look for spaces since punctuation exists and sometimes punctuation like single quotes are considered parts of words and sometimes aren't). It's one thing to leave in a segfault that didn't get caught because it happened to point to allocated memory while testing or even code injection vulnerabilities that weren't accounted for in the test cases and another to not recognize the potential issues with a full search and replace, especially when it apparently wasn't tested on edge cases before deployment (e.g. ensuring "netflitwitter dot twitter" not being replaced with anything since it should only replace second-level domain names and only "twitter" by itself). Even the simplest and smallest set of reasonably made test cases would have caught this bug. I might've accepted an experienced software engineer accidentally replacing top level domains with "X" since ".twitter" isn't really a valid domain, but replacing every instance of "twitter" even when it isn't the full domain name is a bit ridiculous, even for an inexperienced developer, let alone an experienced one.
@VonVikoGoat
@VonVikoGoat 17 күн бұрын
in fact newer people tend to be more cautious. experience people are often arrogant and refuse to fix their mistakes
@idontwantahandlethough
@idontwantahandlethough 14 күн бұрын
@@VonVikoGoat well yeah, but you can only be cautious of dangers you're _aware of._ That's the issue for newer people: you can be as cautious as you want, but if you didn't know that something is a possibility, you can't viably protect against it.
@mikapeltokorpi7671
@mikapeltokorpi7671 20 күн бұрын
When you fire 80% of your engineers at once...
@alicenNorwood
@alicenNorwood Ай бұрын
Twitter actually had XSS in the feed 3 years ago
@dingus2332
@dingus2332 28 күн бұрын
There are many subdomains of Twitter , where XSS happens
@3_smh_3
@3_smh_3 28 күн бұрын
@@dingus2332 dang!
@REAZNx
@REAZNx 26 күн бұрын
You mean Tweetdeck?
@al-ft1ng
@al-ft1ng 26 күн бұрын
@@dingus2332 Such as ? Any PoC ? Anything to back your claim lol? Do you have any previously documented PoC ?
@dingus2332
@dingus2332 26 күн бұрын
@@al-ft1ng it's just a known thing ... They launch subdomains ,hunters with tools scan that new vulnerable subdomain and report them immediately
@xdevs23
@xdevs23 20 күн бұрын
That's why you should use a password manager with phishing detection where it automatically matches the domain against the URL stored in your passwords and thus only show the ones that match the domain.
@Z-of1zx
@Z-of1zx 17 күн бұрын
Examples of password managers with this functionality?
@Bob-bs9ok
@Bob-bs9ok 17 күн бұрын
​@@Z-of1zxpass, pretty much the standard on unix systems, does this.
@sun3k
@sun3k 17 күн бұрын
bitwarden is a pretty good free one
@xdevs23
@xdevs23 17 күн бұрын
@@Z-of1zx Android Password Store and gopass extension for browsers (uses the pass system)
@brucewayne1777
@brucewayne1777 15 күн бұрын
​@@Z-of1zx lastpass, 1password, keepass (with the browser extension). Honestly I think all of them have that
@EronanTruth
@EronanTruth 16 күн бұрын
Sadly the reason for the "no review" is much more trivial. It's very likely that people didn't want to "review" it than they actively didn't because everyone knew this was a bad idea, but the "person" who made the decision had a lot of power within the company and really, really, really wanted it. Because in general, there is absolutely no reason to implement this change and a waste of man hours. So they wanted to get this done, let the person who's making the stupid decision see it crash. And then get back to actual important work.
@ecchioni
@ecchioni Ай бұрын
This is what happens when you fire most engineers and make the remaining sleep in office in order to work 120 hour weeks.
@Sammysapphira
@Sammysapphira 29 күн бұрын
Blatantly false and Twitter has run better than ever with the downsized team once all the bloat and hr department were removed. Elons twitter team has shipped more features than Jack has in the past 10 years.
@josephp.3341
@josephp.3341 29 күн бұрын
@@Sammysapphira The company is doing terrible compared to how it used to. I mean imagine becoming the new CEO and the most significant thing you have to show for it a new competitor spawned and took a massive amount of your market share - something unthinkable years prior.
@tapwater424
@tapwater424 28 күн бұрын
@@Sammysapphira Every post is bots replying with engagement bait not related to the original content.
@Peter-tx7qf
@Peter-tx7qf 26 күн бұрын
​@@Sammysapphira Twitter is literally shit now, only bots on every post and the features are shit and get pulled back every 3 months. It's tragic how he fucked it up soo bad.
@TheKennyWorld
@TheKennyWorld 24 күн бұрын
​@@tapwater424And you think that is caused by Elon? How? Couldn't be just a coincidence?
@DissociatedWomenIncorporated
@DissociatedWomenIncorporated 20 күн бұрын
Elon Musk, living proof of the meritocracy! 🤣🤣🤣
@AlexRaylight
@AlexRaylight 16 күн бұрын
But the Musk fans were saying that all those tech employees who left weren't important, and that twitter will be fine regardless... 🤔
@oxyacetylene_
@oxyacetylene_ 20 күн бұрын
twitter used to have XSS on their desktop client, there was a self-replicating tweet going around for a couple of hours
@user-qt9ek3us6i
@user-qt9ek3us6i 19 күн бұрын
Tweetdeck*
@halyoalex8942
@halyoalex8942 17 күн бұрын
I remember the Tom Scott video on that one 😂
@gunstorm05
@gunstorm05 12 күн бұрын
It was not an issue on an official Twitter product. That was a third-party client.
@joeykeilholz925
@joeykeilholz925 11 күн бұрын
It's giving "fired for not enough lines of code"
@miserablepile
@miserablepile 25 күн бұрын
This is what happens when Musk keeps his teams "lean innovative, and hungry for the next growth phase cycle"
@jonathanhoward1499
@jonathanhoward1499 22 күн бұрын
Good. He's right. It's social fucking media
@Moocow2003
@Moocow2003 14 күн бұрын
​@@jonathanhoward1499security issues aren't a price I'm willing to pay for innovation
@joeykeilholz925
@joeykeilholz925 11 күн бұрын
​@@jonathanhoward1499in no way is he right. He is a complete moron. Reevaluate everything that lead you to say that
@coreydevs
@coreydevs 27 күн бұрын
Crazy because my first thought was linkedin is starting to look a lot like facebook
@PetWanties
@PetWanties 21 күн бұрын
I can imagine that this got into prod because it's considered a front end / visual change and it might have less strict review standards? Still wild that apparently whoever wrote this didn't realize the implications.
@DennouNeko
@DennouNeko 24 күн бұрын
Just like a lot of changes since Elon took over, sounds like a change that was enforced from above. Guess someone is salty that nobody calls it X
@Mustafa-099
@Mustafa-099 22 күн бұрын
Thanks for providing the link to the original post You the best!
@mafiawerbung
@mafiawerbung 22 күн бұрын
Remember the self retweeting tweet?
@addison1024
@addison1024 13 күн бұрын
All I know about web security is from Tom Scott, and it seems like I might actually be set for a while
@sage5296
@sage5296 14 күн бұрын
"I'm sure they have best practices in place" You mean like firing all of the people who know what they're doing cuz they're not needed supposedly?
@CentreMetre
@CentreMetre 19 күн бұрын
Im by far not the best programmer, but i think its fair to take the piss out of twitter for this considering how big of a company they are and how many people there are.
@natescode
@natescode 26 күн бұрын
Maybe Elon fired all the smart people yoo.
@AWriterWandering
@AWriterWandering 21 күн бұрын
The smart people knew better than to stick around
@kintustis
@kintustis 19 күн бұрын
smart people can get paid the same without the 100 hour weeks, so they've all left by now.
@joeykeilholz925
@joeykeilholz925 11 күн бұрын
Worst part is he still works there.
@pastori2672
@pastori2672 Ай бұрын
scared with the google part i actually used it and btw when are the systems design videos bro
@StarGarnet03
@StarGarnet03 16 күн бұрын
musk has such an inflated ego and insecurity from people not calling the popular app it's original name that he accidentally created avenues for scams with shitty find/replace code
@compenuered2830
@compenuered2830 29 күн бұрын
it's grock becoming devin
@yichenchong7728
@yichenchong7728 25 күн бұрын
I don't think the Google page was that big of an issue, as long as you confirm that the sign in page that opened is with a Google domain, because if the app itself isn't made by Google, it only has access to Google's OAuth flows (and any other permissions you share in the screen after the login), and OAuth is pretty secure; you wouldn't lose your Google credentials just because a site got you to OAuth to them (I believe its a PKCE flow to be more specific, but I could be wrong). That being said, if you have to type in your password to a Google page, you'd better be sure that sign in page is by Google, even if the app itself isn't.
@matthewrease2376
@matthewrease2376 18 күн бұрын
You should never trust what's displayed anyway. Always check the mouse hover on a link.
@givowo
@givowo 15 күн бұрын
The XSS vulnerability actually happened years ago. Tom Scott made a video about it, and its called the self retweeting tweet
@l1nuxguy646
@l1nuxguy646 16 күн бұрын
I bet you Musk said to do it this way and refused to listen to anyone who explained.
@aka5h_ra0
@aka5h_ra0 Ай бұрын
Petition for neetcode to create web app security videos!
@ExecutionMods
@ExecutionMods 28 күн бұрын
ehh like he said hes not a security expert. there's plenty of experts with full fledged courses out there tho
@aka5h_ra0
@aka5h_ra0 28 күн бұрын
@@ExecutionMods yes I agree there are plenty of other courses out there, but the way this dude teaches is just 🔥🔥
@ExecutionMods
@ExecutionMods 28 күн бұрын
​@@aka5h_ra0 i agree i like his style of teaching a lot
@perz1val
@perz1val 20 күн бұрын
Doing a text replace and not botheting to only match the real domains is just amateurish. Did an intern do this?
@amymo5187
@amymo5187 5 күн бұрын
Its the funny cause the possible causes really weren't all that unlikely for Twitter, I mean wasn't the Heartbleed exploit from like 2012~ an XSS exploit itself?
@ObaidKnight
@ObaidKnight Ай бұрын
How can we learn more about this type of stuff?
@user-oj7uc8tw9r
@user-oj7uc8tw9r 27 күн бұрын
owasp is a good site to learn about this stuff.
@Afro__Joe
@Afro__Joe 26 күн бұрын
What happens when you get rid of all your talent to save an extra penny.
@williamdrum9899
@williamdrum9899 9 күн бұрын
"talent"
@idontwantahandlethough
@idontwantahandlethough 14 күн бұрын
LOL this SCREAMS "everyone who knew anything at Twitter has left the building"
@ryanreed4698
@ryanreed4698 20 күн бұрын
Why is he still pushing X, just such a stupid name.
@mathiasrryba
@mathiasrryba 17 күн бұрын
because he's obsessed with it. He always wanted it and he pushes it into everything, even his own children's names.
@Seydaschu
@Seydaschu 17 күн бұрын
Let's compromise. Xitter.
@RaceBandit
@RaceBandit 8 күн бұрын
How many of the doxxers, swatters, and SJWs are gone?
@SandraWantsCoke
@SandraWantsCoke 25 күн бұрын
I gave you the 777th like, really enjoy your videos! (never done a leetcode question in my life)
@neoqueto
@neoqueto 12 күн бұрын
That's such a... "PHP 5.6 newbie WordPress tinymce fork" kind of mistake.
@evinroen6401
@evinroen6401 12 күн бұрын
I have no idea what any of this means
@rotatopotato5212
@rotatopotato5212 Ай бұрын
This is why I deleted my Twitter account very soon after Elon took over and fired most of the engineers. Especially after I learned 2FA broke immediately. As an engineer, I can only imagine the amount of details that are getting thrown out the window.
@devstuff2576
@devstuff2576 Ай бұрын
You deleted your account because you foresaw a security vulnerability. right buddy.
@adama7752
@adama7752 Ай бұрын
Lol, they've had hack bypassing 2fA years before Elon. It was always a mess. You're just unable to moderate your bias here
@Leo-sd3jt
@Leo-sd3jt Ай бұрын
@@devstuff2576no, they deleted it because they could see that Elon was breaking things. That’s why they reference how 2fa broke on the site
@nou4605
@nou4605 Ай бұрын
​@@devstuff2576Skill issue
@chris94kennedy
@chris94kennedy 29 күн бұрын
@@devstuff2576 you say that as though no one would do that.
@Yulenka-
@Yulenka- 19 күн бұрын
Ah yes, Elon Musk, always solving humanity's biggest and most existential problems. What would we do without you (we'll be fine) 🤦🏽‍♀️
@fancy_tord5175
@fancy_tord5175 15 күн бұрын
another example of companies making useless changes instead of fixing real problems
@thepwrtank18
@thepwrtank18 20 күн бұрын
twittervideos
@chrisakaschulbus4903
@chrisakaschulbus4903 15 күн бұрын
Getting paranoid because buttons look funny? That's everyday for me with my crappy connection...
@Aeduo
@Aeduo 23 күн бұрын
The review process having a lot of odd barriers to even getting to the point where someone is looking at it really sounds liek that usual corpo adversarial conditioning approach to things where they just add difficulty to some task they think should have some gravity to it rather than trusting anybody to make a good judgment, and in this case, it was going to be seen by someone doing the reviewing anyway. But in their mind, everyone is just going to be irresponsible and everything is a slippery slope because they have zero trust in their workers to have reasonable judgment. Just seems like usual corpo owner culture issues though. Twitter just seems like a bit of a circus though. :p
@TrueTechLead
@TrueTechLead 24 күн бұрын
That is so goofy.
@Taparu2
@Taparu2 13 күн бұрын
On the web anyone anywhere has always been able to create a link named one thing that links elsewhere.
@woahmamaawoogahonkahonka
@woahmamaawoogahonkahonka 5 күн бұрын
But now it’s much, much easier to make and disguise it as a legitimate link.
@hattrickster33
@hattrickster33 3 күн бұрын
Just like the renaming failed since Elon didn't listen to marketing and UX experts, I wouldn't be surprised if this "solution" came down from the top without considering input from SWEs who know what they're doing.
@sobari745
@sobari745 10 күн бұрын
Elon Musk is truly a genius. I didn’t think it was possible to run such a massive company into the ground so fast and efficiently.
@xanderlastname3281
@xanderlastname3281 16 күн бұрын
A clbuttic clbuttic mistake
@SaurianSavior
@SaurianSavior 9 күн бұрын
I see everyone has gone onto take the piss out of Elon for the many many mistakes he made. The funny thing for me is this is because Elon decided Twitter should be called a letter. And now it's breaking people's tweets, because nobody calls the site by the letter. Of course, it's more complicated, like - read the other comments.
@JonnySolomon
@JonnySolomon 20 күн бұрын
loved this
@Alexis-lt3zy
@Alexis-lt3zy 12 күн бұрын
Twitter has previously had XSS attacks...
@sirseven3
@sirseven3 13 күн бұрын
Whe you convert without specifying bounds 😂
@PetWanties
@PetWanties 21 күн бұрын
For the google webpage / login you showed, it's always good to check the certificate of the website, authority domains will have their own certs that are (usually) easy to recognize.
@hypermeero4782
@hypermeero4782 Ай бұрын
what if i told you that I can make the CSRF hack happen in twitter in few seconds?
@hypermeero4782
@hypermeero4782 Ай бұрын
and even better, make some random people follow some other random people.
@Yoruplays
@Yoruplays Ай бұрын
@@hypermeero4782 is there no csrf tokens on their requests?
@omcar13
@omcar13 Ай бұрын
@@hypermeero4782 I'd ask you to do it
@beniungur1722
@beniungur1722 Ай бұрын
@@hypermeero4782 report it and they'll probably reward you
@raulhernandez2010
@raulhernandez2010 Ай бұрын
can you use it to make my twitter blow up 😊
@disasterarea9341
@disasterarea9341 25 күн бұрын
i liked twitter but i stopped using it once elon took over. yikes
@Lukie-Boy
@Lukie-Boy 16 күн бұрын
My own personal website does shady shit but not this bad :O
@CainXVII
@CainXVII 10 күн бұрын
I don't know if my google credentials are worth much. They are welcome to the 4 videos I made in 7th grade
@alicenNorwood
@alicenNorwood Ай бұрын
What NeetCode is new primeagen?
@climber-fd1ww
@climber-fd1ww Ай бұрын
Not a chance. I actually learned a few technical concepts with Neetcode. I usually leave a primeagen's video wanting that hour back
@UnknownEntity606
@UnknownEntity606 Ай бұрын
Neetcode is 10x more beginner friendly
@zweitekonto9654
@zweitekonto9654 Ай бұрын
​@@climber-fd1wwLMAO. This is actually true. I only watch primeagen when I want to eat something.
@TheFinalB055
@TheFinalB055 Ай бұрын
@@zweitekonto9654 yeah sooo true 😂
@samuraijosh1595
@samuraijosh1595 Ай бұрын
@@climber-fd1ww true, true, primeagen is simply for programmers to chill and have a chat
@daniloh8113
@daniloh8113 11 күн бұрын
Security team? Come on this REEKS of a change that elon himself forced them to ship
@sasho_b.
@sasho_b. 22 күн бұрын
"This is Elon Musk, Tesla's co-founder and CEO"
@bomblii
@bomblii 10 күн бұрын
Moral of the story: Elon can't run a website.
@wheedler
@wheedler 9 күн бұрын
I like bureacracy.
@greensnr1
@greensnr1 15 күн бұрын
the "security vulnerability" is... hyperlinks? It's something you can do with any hyperlink feature? It's embarrassing code but not much of a vulnerability
@barb0za0
@barb0za0 14 күн бұрын
so happy at this elon/twitter hate in the comments lol
@NStripleseven
@NStripleseven 12 күн бұрын
A clbuttic error.
@als_pals
@als_pals 15 күн бұрын
Twitter has had an xss vulnerability before but thwt was probably over a decade ago
@tylerwalton7659
@tylerwalton7659 24 күн бұрын
Ok when he said the word subscribe at 1:20 the subscribe button was highlighting…. That was cool 🤯 and it worked, I subscribed🎉
@TheKennyWorld
@TheKennyWorld 24 күн бұрын
Signals
@TheFuriousNightFury
@TheFuriousNightFury 20 күн бұрын
heaven forbid you use the word Twitterpated. would that.... like....
@Bukki13
@Bukki13 3 күн бұрын
setwitter
@Luckmann
@Luckmann 9 күн бұрын
Honestly, you call this trivial, but it's really not. It's fairly serious, especially for the normie market that doesn't even known what a URL is. This fix probably save tons of boomers and zoomers.
@anon5992
@anon5992 25 күн бұрын
classic elon moment
@charredUtensil
@charredUtensil 15 күн бұрын
What a clbuttic mistake!
@Speederzzz
@Speederzzz 15 күн бұрын
"What did you think would be the vulnerability..." My friend, I haven't coded since i accidentally signed up for a beginners course into using a specific academic program that looked like it was old when I was born.
@moover123
@moover123 14 күн бұрын
let's call it titter from now on
@dubz5149
@dubz5149 19 күн бұрын
LGTM!
@maacpiash
@maacpiash 19 күн бұрын
Great video, but that was a long intro. We know what XSS and CSRF are 🤷🏽‍♂️
@n00dle_king
@n00dle_king 19 күн бұрын
It’s an ancient feature of the Internet that links can have whatever text you want and a separate underlying URL. How is this even a vulnerability? It’s a stupid bug but I don’t see any security implications that are any different than the URL spoofing that potentially exists with every other link online.
@DarkGob
@DarkGob 19 күн бұрын
Is it possible to do that within a tweet under normal circumstances? I'm pretty sure it's not although I'll admit I could be wrong, never used the bird site. That would be the difference, because normally when you see a link within a tweet you're trusting that the user actually typed out that domain name and Twitter is just automatically rendering it as a link.
@bigdarggy
@bigdarggy 15 күн бұрын
lol
@efs3
@efs3 17 күн бұрын
You look like the guy from how I met your mother
@nnzrmn
@nnzrmn 29 күн бұрын
Dont you hate 10x LinkedIn than Twitter? Not to be confrontational ahahah
@Sammysapphira
@Sammysapphira 29 күн бұрын
Youve always been able to do this with markdown. Its not as bad as youre making it out to be.
@vlc-cosplayer
@vlc-cosplayer 23 күн бұрын
Bro's been coping all over the comments section, give it up bruh 😭
@Omega-mr1jg
@Omega-mr1jg 21 күн бұрын
You usually make sure that markdown wouldnt be abused similar to this, though... This is different
@BustyCatbot
@BustyCatbot 16 күн бұрын
You'd think seeing somebody legitimately refer to Twitter as X would be a sign of professionalism, but more often than not, it tends to signify the opposite, quite the strange pattern, might have to do with Elon himself not being very professional, maybe it's contagious.
@Silquey
@Silquey Ай бұрын
neetcodeisgoat
Bizarre traveling flame discovery
14:34
Steve Mould
Рет қаралды 3,3 МЛН
I Made a Graph of Wikipedia... This Is What I Found
19:44
adumb
Рет қаралды 2,1 МЛН
How To Choose Ramen Date Night 🍜
00:58
Jojo Sim
Рет қаралды 53 МЛН
Don’t take steroids ! 🙏🙏
00:16
Tibo InShape
Рет қаралды 33 МЛН
Stupid man 👨😂
00:20
Nadir Show
Рет қаралды 28 МЛН
Uma Ki Super Power To Dekho 😂
00:15
Uma Bai
Рет қаралды 48 МЛН
Has Generative AI Already Peaked? - Computerphile
12:48
Computerphile
Рет қаралды 544 М.
i cant stop thinking about this exploit
8:40
Low Level Learning
Рет қаралды 264 М.
98% Cloud Cost Saved By Writing Our Own Database
21:45
ThePrimeTime
Рет қаралды 239 М.
You Probably Shouldn't Watch This
8:22
The Math Sorcerer
Рет қаралды 257 М.
How I re-created the rhythm game osu! from scratch in C++!
5:51
Omer Hasanov
Рет қаралды 20 М.
Why I focus on patterns instead of technologies
7:55
NeetCodeIO
Рет қаралды 200 М.
researchers find unfixable bug in apple computers
8:32
Low Level Learning
Рет қаралды 680 М.
I Got AI Interviewed AND BROKE IT
29:10
ThePrimeTime
Рет қаралды 192 М.
We should use this amazing mechanism that's inside a grasshopper leg
19:19
How To Choose Ramen Date Night 🍜
00:58
Jojo Sim
Рет қаралды 53 МЛН