1. See the bottom of the archived tweet thread: https://archive.ph/qKyA3
It would have been better to have done some verification first, before tweeting, to check whether it was actually doing what it appeared to be. Especially when you know your tweets have considerable reach.
> lololol @ the "security researchers" sliding into my DMs asking me to run shell commands and send them the output
> Go run your Little Snitch and WireShark and tcpdump and mdimport and mitmproxy and system_profiler on yourself; I'm not your SOC
Wow this guy comes across like a right twat. No wonder his apology sounds like it's coming out from furiously gritted teeth.
Still, I hope he learned something useful from this experience. Many of us have gone through a similar period of arrogance in our younger years, only to be shocked into looking back in shame later on.
admit you were wrong and made it all up -> get people to ‘respect’ you and even more twitter followers
Besides the ham fisted approach, the original vuln idea seemed reasonable.
They were wrong, it happens to the best of us.
I’d say the potential security risk was worth raising the flag over.
Better be wrong and safe, having many of us learn something along the way, then overly cautious and leave a potential problem unaddressed.
I don't think "do even the most cursory verification to check if the extraordinary thing I've just seen is actually happening" could be counted as "overly cautious".
I mean, I wouldn't say "great" when you've incited a security panic because you didn't even do the bare minimum of ...
> looking more closely