Featured image of post Thoughts That Talk Back - How ChatGPT Quietly Doxxed Your Name

Thoughts That Talk Back - How ChatGPT Quietly Doxxed Your Name

Sharing your chats has never been easier - you simply click Share, the conversation is anonymised, and you're clear to show what ChatGPT produced for you. There are no privacy implications - unless you pasted personal data into the chat itself, which OpenAI discourages. However, on 16th of April 2025 OpenAI rolled out two new reasoning models, o3 and o4-mini, that unexpectedly leaked the profile name associated with your OpenAI account.

Featured image of post Bypassing SMS OTP Authentication or a story behind $16.5k in bounties

Bypassing SMS OTP Authentication or a story behind $16.5k in bounties

SMS OTPs are often seen as a secure authentication method, but what if they aren't? In this post, I break down how I reverse-engineered an OTP mechanism, leveraged probability theory, and achieved a 32% bypass success rate—exposing weak PRNGs and poor OTP management along the way leading to a 100% bypass success rate