The thread is in the body of the tweet. Here is the start: https://twitter.com/axi0mX/status/1313620262768635904
278 karma · joined June 3, 2013
If the cookie is set through HTTPS and does not have the Secure flag set, the browser will happily send it along when loading HTTP resources.
There is no change to the browser itself at all, just plain javascript that shows a terminal running on a remote computer.
This is the case with all instances of seeking a collision, due to the birthday paradox [0]
http://www.blitzortung.org/Webpages/index.php?lang=en&page=3