Ian Carroll
@iangcarroll
Followers
16K
Following
33K
Media
241
Statuses
2K
Founder at @SeatsAero. Travel/points, application security, security research, etc. https://t.co/q0VuCP7rXz
Ann Arbor, MI
Joined July 2014
We became an admin in the Fédération Internationale de l'Automobile's driver categorisation system, which allowed us to access the PII and password hashes of any rated driver, including Max Verstappen. 🏎️ https://t.co/vdX7OegqmW
ian.sh
We found vulnerabilities in the FIA's Driver Categorisation platform, allowing us to access PII and password hashes of any racing driver with a categorisation rating.
6
44
248
What it feels like to try to be taken seriously after weeks of saying things in jest
51
6K
113K
I use squarespace for my online shop and the AI auto reply suggestion keeps prompting me to lie about a death in my family whenever someone messages me to ask about their order
50
2K
38K
We accidentally got access to every Academy Award nominee's home address and phone number. Before last year's Oscars Ceremony, together with @iangcarroll and @samwcyo, we found a way to leak every nominee's PII, including phone numbers and home addresses of the biggest actors
10
81
482
Many of you do not know the trauma of having to write out Java on paper for the comp sci AP exam and it shows
314
1K
18K
A HackerOne program calculated my report’s CVSS score incorrectly, and instead of fixing it, they seem to be ignoring my comments and just replying with AI arguments. Is the future of bug bounty hunters just arguing with stupid chatbots?
8
0
84
It's 2025. There is no excuse for any product to past tokens into SQL statements like this, much less a security product. Fortinet, a cybersecurity company, has become famous over the last several years for its security flaws. An occasional flaw is forgiveable, but this line of
I just noticed CVE-2025-25257 and had a giggle. Not because it's yet another Fortinet remote bug. But because it's a SQLi, in a WAF product. The irony...
20
110
776
Just setup my @particle Tachyon and am pretty impressed. Lot of possibilities for a Raspberry Pi form factor with a 5G modem built in. Super easy CLI setup, no microSD needed!
4
0
22
Zohran: New York should be affordable for everyone Cuomo: A single mother is homeless because your rent is too low Eric Adams: Deep down, I think I must be little bit Dominican
Deep down, I think I must be little bit Dominican because marching down 6 Avenue in the Dominican Day Parade just felt like coming home! Every time I meet Dominican New Yorkers, I’m inspired by their generosity and energized by their passion. ¡Que viva el pueblo dominicano!
156
6K
85K
One of the biggest growth drivers at Discord over the last year has been the elevation of "Login with your LEGO Account." Incredible how much of Gen Z and Gen Alpha associate their core identity with their LEGO account. Wish we had done this sooner.
97
133
2K
Apparently a pair of Xiaolongbao will serve as the zero-g indicator on this launch
26
488
6K
>hexagonal chip >look inside >squares
45
497
18K
America is already falling behind in technological advancements
234
3K
45K
McDonald's uses an AI bot called "Olivia" for hiring. A pair of hackers found they could access every conversation job applicants had with it—including all the personal info they shared—by exploiting security flaws as basic as using the password "123456".
wired.com
Basic security flaws left the personal info of tens of millions of McDonald’s job-seekers vulnerable on the “McHire” site built by AI software firm Paradox.ai.
23
465
1K
When applying for a job at McDonald's, over 90% of franchises use "Olivia," an AI-powered chatbot. We (@iangcarroll and I) discovered a vulnerability that could allow an attacker to access the over 64 million chat records using the password "123456". https://t.co/dBqpRpdp9T
ian.sh
When applying for a job at McDonald's, over 90% of franchises use "Olivia," an AI-powered chatbot. We discovered a vulnerability that could allow an attacker to access more than 64 million job...
18
123
471
periodic reminder that this is a partner at the most storied firm in Silicon Valley
199
852
10K
As part of its investigation, NTSB found 23 members of the 24 member “door team” had not been directly trained on how to open or close a 737 Max mid-exit door plug at the time the Alaska 1282 aircraft was being built. #24 was out of the country.
NTSB board meeting to determine the probable cause of the January 2024 in-flight separation of a mid-exit door plug on an Alaska Airlines Boeing 737-9 airplane starts at 9:30 am ET. Watch the livestream:
14
76
566