Joined March 2007
281 Photos and videos
Pinned Tweet
21 Aug 2023
Costco code of ethics: 1. Obey the law. 2. Take care of our members. 3. Take care of our employees. 4. Respect our suppliers. Ponder for a moment why Musk, Bezos, Ellison and Zuck run companies share none of these values. podcasts.apple.com/us/podcas…
1
3
1,786
I encountered this same thing last June. X doesn’t moderate the names/website/icon of developer apps which makes account takeover phishing trivially easy. X took weeks to pull the app running and my HackerOne submission was rejected. x.com/notpeter/status/193724…

Mar 9
PSA: I just survived the best phishing attempt I've ever seen. A "reporter" at TechCrunch with a 10-year-old account and 9k followers DMed me asking if I'd be interested in giving input to an article that sounded relevant. When I said yes, they sent me to a real cal.com link to book with the name of an actual TC reporter. After booking, I got redirected to another page saying I had to verify myself to complete the booking. The auth request looks somewhat legit, except for a small red note that it's not approved. My spidey sense had been tripped and I realized the domain was sketchy, but if I wasn't on autopilot (or if I was an OpenClaw) I might have easily given them full access to my account. Stay safe out there.
113
Summer camp exists.
Replying to @joeybeastmarket
Zoomers will never know what it was like to be with 300 other good-looking non-seed oil afflicted non-septum pierced teenagers next to a lake around a bonfire with zero cell phone cameras and everybody living purely in the moment. Just literally impossible now.
110
I did a mini version of this on a BOS->SF flight a few years ago and New Years rollovers in 3 timezones. We took off at ~10pm and at Eastern/Central/Mountain time midnights I popped a mini bottles of bubbly and celebrated each with a meek outloud “Woo!” while everyone else slept.
Time travel is real! Flight CX880 departs Hong Kong in 2026 and lands in Los Angeles back in 2025 😲✈️ Welcome to the time zone glitch. #BackToTheFuture
113
So many one-off scrapers.
Trying to revisit every idea we’ve said “no” to in the past in case it makes sense to say “yes” now with the help of AI… Is there anything you’ve built that’s been game changing for your business that was just impossible to justify pre-AI?
86
Six months later and the security issue remains. Using links that redirect in a tweet/DM will: (1) hide the url of your link (2) only show 't. co' on hover (3) show domain & preview card of redirect target (4) clicks go to the original (hidden) link/domain Quote tweets too:
23 Jun 2025
Replying to @notpeter
P.P.S They hide links from tweets too 🫠 That tweet contains a link to 'nimble.li/jmo57pvd' not jetbrains.com and hovering shows 't.co / AzNOkFoo4F' with no hint of the original link whatsoever. Sigh🙃 x.com/notpeter/status/193724…
87
24 Nov 2025
Would love to see this in the @zeddotdev agent panel (nudge @danilobleal).
23 Nov 2025
Normal accordion vs. upward accordion I was scrolling on social media and noticed that when you collapse replies on a comment, the collapse button stays in the exact same spot. Really nice UX, so I tried building it myself. (flex-col-reverse did not work LOL)
5
245
12 Nov 2025
“He sent a message to jerks all over the country, their hour had arrived. Enough of this idealism. Enough of the Kennedy uplift. We’re going to have our day. The day of the jerk. The silent majority, which is the apotheosis of jerkhood.” m.youtube.com/watch?v=cGJcQ_…
92
25 Aug 2025
Dude where’s my Chartio.
229
23 Jun 2025
There's a relatively well-crafted spear phishing campaign floating around to compromise X accounts. It exploits an X API security issue and stale previews of link preview cards to make things look almost legit. It all starts with a DM...
1
341
23 Jun 2025
P.S. Despite reporting this 10 days ago. The domain in question is still operating (behind CloudFlare) and their X Developer account is still actively phishing user accounts. @XSecurity DM me if you want more details. Be safe out there!
1
243
23 Jun 2025
P.P.S They hide links from tweets too 🫠 That tweet contains a link to 'nimble.li/jmo57pvd' not jetbrains.com and hovering shows 't.co / AzNOkFoo4F' with no hint of the original link whatsoever. Sigh🙃 x.com/notpeter/status/193724…
23 Jun 2025
Replying to @notpeter
Also, redirects can change. This is my favorite editor: nimble.li/jmo57pvd
345
23 Jun 2025
(note: twitter silently removed the www prefix inside the double quotes so you see "calendar . google . com" in the previous message instead of the "www . calendar . google . com" I actually typed.
1
117
23 Jun 2025
Because of two bad security choices (hiding links and allowing X Developers to impersonate Google) users are two clicks away from takeover of their accounts. Lame sauce!
1
106