Sign in

Jason Parker - ဪ.com

@oink.ing
113 followers 101 following 137 posts

cybersecurity researcher | independent journalist | software developer | telephony engineer | open source contributor jeltz.org linktr.ee/northantara

PostsRepliesMedia
Jason Parker - ဪ.com @oink.ing · 23/12/2025
@rob-sheridan.com Would you consider enabling #Fediverse bridging via @ap.brid.gy ? You should have a DM from them explaining how to easily enable it. xn--8r9a.com/@north/11576...
000
Jason Parker - ဪ.com @oink.ing · 26/11/2025
@pfrazee.com Can we have proper IDN support yet? :( github.com/snarfed/brid... @handle.invalid (related: lol)
github.com
Bsky profile link fails with IDNs · Issue #2222 · snarfed/bridgy-fed
As much as it pains me, Bluesky (...still...despite using domains that I own in their test suite!) doesn't support IDNs in a few places. Notably, it affects brid.gy on the account profile page. Cli...
112
Reposted by Jason Parker - ဪ.com
Zach Everson @zacheverson.com · 11/11/2025
Have any tips about Trump's businesses or other money-in-politics info? Email: z_everson@protonmail.com Mobile/Signal: 202.804.2744 OnionShare (requires Tor): 224medfh4632g3ze5otkskg5onhe27ssw3vghy3swknmdng5yj4n3eqd.onion Suggested reading—
freedom.press
Here’s how to share sensitive leaks with the press
Thinking about securely leaking information to news organizations? This guide will show you how.
5498292
Reposted by Jason Parker - ဪ.com
Common people @uncommonpeople.bsky.social · 05/11/2025
If things go the way they should, Subway should do the right thing and release a new sandwich named Jury Nullification. I also have some ideas for the launch
063
Jason Parker - ဪ.com @oink.ing · 29/09/2025
@gamesdonequick.com Hey, is the venue / hotel info for AGDQ 2026 supposed to be public yet? If not, you should email me, because reasons... #cybersecurity north@ntbox.com
000
Reposted by Jason Parker - ဪ.com
Jason Parker (he/they) @handle.invalid · 31/12/2024
I have something I need to come clean about. On Dec 31, 1999, I shut off the power to my trailer park at exactly midnight.
001
Jason Parker - ဪ.com @oink.ing · 21/11/2024
@piratesoftware.live Would you consider linking to the Fediverse/Mastodon, by following ap.brid.gy? I know there are a lot of people there who would follow you through the bridge.
010
Jason Parker - ဪ.com @oink.ing · 15/11/2024
@good.as.hell.domains @pfrazee.com You made me do this. IDN support soon?
110
Jason Parker - ဪ.com @oink.ing · 14/11/2024
Fedi test?
000
Jason Parker - ဪ.com @oink.ing · 13/11/2024
@alexrkonrad.bsky.social @katiegeeks.bsky.social My timeline. Serendipity.
130
Reposted by Jason Parker - ဪ.com
Jason Parker - ဪ.com @oink.ing · 13/11/2024
A #vulnerability in the #Georgia #voter registration website that is still active as of today. infosec.exchange/@abreacher/1... #infosec #cybersecurity #election #uspol
135
Jason Parker - ဪ.com @oink.ing · 13/11/2024
A #vulnerability in the #Georgia #voter registration website that is still active as of today. infosec.exchange/@abreacher/1... #infosec #cybersecurity #election #uspol
135
Reposted by Jason Parker - ဪ.com
GlitchCat7 @glitchcat7.bsky.social · 06/11/2024
GC7 Bluesky. Welcome. It is I.
2203
Jason Parker - ဪ.com @oink.ing · 10/10/2024
so like does the Bluesky web app still really not do browser notifications or automatic notification refreshes?
000
Jason Parker - ဪ.com @oink.ing · 08/10/2024
@bnewbold.net IDN username support soon? *copium* I'll let you borrow one! How about ӿ.social? I can't stay invalid.handle forever. (or can I?)
000
Jason Parker - ဪ.com @oink.ing · 28/09/2024
I decided it was time that I write up an article on all of my govtech vulnerabilities. northantara.medium.com/critical-fla...
northantara.medium.com
Critical Flaws in Government Systems Put Legal and Voter Data at Risk
A recent wave of cybersecurity disclosures has uncovered alarming vulnerabilities in the platforms that government agencies and courts rely…
100
Jason Parker - ဪ.com @oink.ing · 21/09/2024
According to Discord on HackerOne, this isn't a vulnerability. Sure, okay. xn--8r9a.com/@north/11317...
xn--8r9a.com
Jason Parker (he/they) (@north@ꩰ.com)
#Discord told me on #HackerOne that this isn't a security #vulnerability, so cool, I'll talk about it publicly. You can disable 2FA¹ on another person's account if you get access to their phone momen...
120
Jason Parker - ဪ.com @oink.ing · 18/09/2024
So, this happened... en.wikipedia.org/wiki/Jason_P...
en.wikipedia.org
Jason Parker (security researcher) - Wikipedia
000
Jason Parker - ဪ.com @oink.ing · 17/09/2024
🤔
120
Jason Parker - ဪ.com @oink.ing · 06/09/2024
@pfrazee.com Please Unicode domains? ꩰ.com deserves a chance at life here. 👉👈 I could let you borrow ӿ.social for testing.
020
Jason Parker - ဪ.com @oink.ing · 06/08/2024
New vulnerability from me. Coverage: www.propublica.org/article/cybe... and www.atlantanewsfirst.com/2024/08/05/s...
propublica.org
“A Terrible Vulnerability”: Cybersecurity Researcher Discovers Yet Another Flaw in Georgia’s Voter Cancellation Portal
The flaw would have allowed anyone to submit a voter registration cancellation request for any Georgian using their name, date of birth and county of residence — information that is easily discoverabl...
022
Jason Parker - ဪ.com @oink.ing · 03/08/2024
I just discovered that I can bypass the SSN / DL requirement on Georgia's #voter deregistration (wtf?) page at cancelmyregistration.sos.ga.gov/s/ All an attacker needs is name, county of residence, and birthdate. #cybersecurity #infosec #georgia #GA #election
cancelmyregistration.sos.ga.gov
Elections Portal
021
Reposted by Jason Parker - ဪ.com
Emily Baker-White @ebakerwhite.bsky.social · 18/06/2024
These vulnerabilities, discovered by security researcher Jason Parker (untaggable but here: bsky.app/profile/did:...) mean that potentially millions of sealed, confidential records could have been captured by identity thieves, extortionists, or foreign governments. www.forbes.com/sites/emilyb...
forbes.com
Massive Court Breach Exposed Confidential Court Testimony, Medical And Psychiatric Records
In more than 50 state and local court systems, vulnerabilities exposed medical records from child abuse victims, police body camera footage, and other sealed documents.
104
Reposted by Jason Parker - ဪ.com
Emily Baker-White @ebakerwhite.bsky.social · 18/06/2024
In Florida, California, and more than 48 other state and local jurisdictions, court system vulnerabilities exposed medical records from child abuse victims, body cam footage, and other sealed documents through unsecured websites. www.forbes.com/sites/emilyb...
forbes.com
Massive Court Breach Exposed Confidential Court Testimony, Medical And Psychiatric Records
In more than 50 state and local court systems, vulnerabilities exposed medical records from child abuse victims, police body camera footage, and other sealed documents.
117
Jason Parker - ဪ.com @oink.ing · 04/06/2024
I've compiled all of my govtech disclosures into one place. This is now the canonical URL for all of them. govtech.cc
govtech.cc
Home | Disclosures
govtech.cc: List of govtech cybersecurity vulnerability disclosures from Jeltz.
010
Jason Parker - ဪ.com @oink.ing · 07/04/2024
xn--8r9a.com/@north/11222... v.jeltz.org/canary
v.jeltz.org
Has Jason been arrested? | Jeltz
I am an arrest canary for Jason.
000
Reposted by Jason Parker - ဪ.com
The Statutes Project @statutes.bsky.social · 26/03/2024
In the light of the #BritishLibrary hack, one wonders if there really is the will to enforce proper IT security: Security flaws in court record systems used in five US states exposed sensitive legal documents techcrunch.com/2023/11/30/u...
techcrunch.com
Security flaws in court record systems used in five US states exposed sensitive legal documents | TechCrunch
Exclusive: The vulnerabilities allowed public access to restricted and sensitive court filings using only a web browser.
012
Jason Parker - ဪ.com @oink.ing · 04/04/2024
I'm on the service list for Georgia v. Trump, so I get stuff well before any media. drive.google.com/file/d/17lBw...
022
Jason Parker - ဪ.com @oink.ing · 28/03/2024
@dholms.xyz If you supported IDN usernames, I could offer <user>.ӿ.social aliases. Food for thought.
100
Jason Parker - ဪ.com @oink.ing · 28/03/2024
So like... am I just allowed to keep "Invalid Handle" forever, or...?
220
Jason Parker - ဪ.com @oink.ing · 28/03/2024
@timcarvell.bsky.social Want to see something really wild? bsky.app/profile/did:... Cybersecurity in a dozen or more court platforms. You have no idea how deep this rabbit hole goes. For more info, see jeltz.org/blog.html or github.com/qwell/disclo... Signal: north.01 Email: north@ntbox.com
110
Reposted by Jason Parker - ဪ.com
Mike Lissner @michaeljaylissner.com · 27/03/2024
This is some damning stuff.
121
Reposted by Jason Parker - ဪ.com
Free Law Project ⚖ @free.law · 26/03/2024
Use PACER? Install RECAP. We’ll make permanent, scalable, reliable links for you in seconds.
063
Jason Parker - ဪ.com @oink.ing · 07/03/2024
Disclosure day! Insufficient permission check vulnerabilities in Granicus's GovQA allowed unauthorized access to view, edit, and change ownership of open records requests, including restricted-access confidential records. github.com/qwell/disclo... www.nextgov.com/cybersecurit...
nextgov.com
Flaws in public records management tool could let hackers nab sensitive data linked to requests
The GovQA platform, created by IT company Grancius, contained vulnerabilities that could have let cybercriminals retrieve tranches of sensitive files tied to public records requests, a security resear...
000
Jason Parker - ဪ.com @oink.ing · 02/12/2023
On the public response to my U.S. court platform disclosures and the future:
xn--8r9a.com
Jason Parker (@north@ꩰ.com)
The response I've seen from my disclosure of vulnerabilities in U.S. court platforms[1] has been incredible. There have been articles in TechCrunch[2] and Law360[3], an advisory from CISA[4], and a p...
010
Jason Parker - ဪ.com @oink.ing · 30/11/2023
Disorder in the Court Insufficient permission check vulnerabilities in public court record platforms from multiple vendors allowed unauthorized public access to sealed, confidential, unredacted, and/or otherwise restricted case documents. More info: github.com/qwell/disord...
github.com
GitHub - qwell/disorder-in-the-court: Court platform vulnerability disclosure(s).
Court platform vulnerability disclosure(s). Contribute to qwell/disorder-in-the-court development by creating an account on GitHub.
342
Jason Parker - ဪ.com @oink.ing · 30/11/2023
@pogue.omg.lol I remembered. 20 minutes.
110
Jason Parker - ဪ.com @oink.ing · 23/11/2023
Oh, hey, they fixed RTL fuckiness with user's names. Also, damn.
110
Jason Parker - ဪ.com @oink.ing · 16/11/2023
I finally have a concrete publication date for my next set of vulnerabilities -- Nov 30, 2023. Eight platforms from eight separate vendors that leak data with life threatening consequences. I can't wait.
110
Jason Parker - ဪ.com @oink.ing · 05/11/2023
I really need to spend more time working on jeltz.org at some point.
jeltz.org
Home | Jeltz
Lifting the Covers, Revealing the Darkness
100
Jason Parker - ဪ.com @oink.ing · 13/09/2023
Lets exploit link cards and make them say whatever we want, for fun and profit. I tried to report this; I was ignored. Details: github.com/qwell/bsky-exploits
cnn.com
World Leader dead at 42.
According to their spokesperson, World Leader was found dead in their home on Tuesday night. They were 42.
21310
Jason Parker - ဪ.com @oink.ing · 06/09/2023
As expected, a vulnerability I reported to #bluesky (see bsky.app/security.txt) >3/mo ago is now an easily exploitable DDoS. They acknowledged the report via email and then...nothing. We've exceeded reasonable CVD timelines at this point. So now what? Full disclosure is usually the next step.
133
Jason Parker - ဪ.com @oink.ing · 28/08/2023
@good.as.hell.domains Does fuckin' invalid as hell qualify as fuckin' good as hell?
020
Jason Parker - ဪ.com @oink.ing · 28/08/2023
@handle.invalid
020
Jason Parker - ဪ.com @oink.ing · 25/07/2023
Once again, I've done a thing. I am the proud new owner of ӿ.social. Why am I like this?
070
Jason Parker - ဪ.com @oink.ing · 09/06/2023
This is fine.
33011
Jason Parker - ဪ.com @oink.ing · 08/06/2023
Why am I like this?
1304
Jason Parker - ဪ.com @oink.ing · 02/06/2023
Can I mute myself? Let's find out.
110
Jason Parker - ဪ.com @oink.ing · 01/06/2023
@why.bsky.team @bnewbold.bsky.team @ansh.bsky.team So, like, this seems not ideal. The good news, however, is that I found a workaround to my Punycode issue. 😏
040