GlobeSec's Avatar

GlobeSec

@globesec.net

We're a collective of software developers and infosec professionals investigating privacy and security risks in web and mobile apps developed by flat earthers.

10
Followers
7
Following
6
Posts
17.03.2025
Joined
Posts Following

Latest posts by GlobeSec @globesec.net

Cybernews also say "there was no way to effectively compare the data between different datasets" which also reeks of bs. If it's all packaged in the url + username + password format they say it is, that's an easy parse, load into database, and query exercise.

A lot here doesn't pass sniff tests.

20.06.2025 00:46 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Probably needless to say, but we strongly advise not using the app, at least until the issues are fixed.

If you have an account and have not done so already, change your password ASAP! If you're worried about your location, go away from home/work, update your location, then don't open the app again

18.03.2025 09:03 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Flat Earth Dave's App Massive Security Breach
Flat Earth Dave's App Massive Security Breach YouTube video by Conspiracy Toonz

If video is more your style, check @mctoon.bsky.social's video where he covers the findings listed in our repo.

At the time we started investigating the app, it was leaking user passwords (as featured recently in @haveibeenpwned.com)
www.youtube.com/watch?v=71FR...

18.03.2025 08:59 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
GitHub - globesec/flatearthsun_public: Publicly disclosed notes and tools regarding the Flat Earth Sun & Moon Clock app and related API Publicly disclosed notes and tools regarding the Flat Earth Sun & Moon Clock app and related API - globesec/flatearthsun_public

The first flat earth app we dug into is the "Flat Earth Sun, Moon & Zodiac Clock" app by "Flat Earth Dave" aka DIRTH.

We've published what we've found (and are able to publicly disclose) so far at github.com/globesec/fla...

Most things, least of all the broken auth, have still yet to be fixed.

18.03.2025 08:57 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

We're here now! ๐Ÿ˜„ Our research (so far ๐Ÿ‘€) is on our Github
github.com/globesec/fla...

17.03.2025 11:26 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Flat Earth Dave's App Massive Security Breach
Flat Earth Dave's App Massive Security Breach YouTube video by Conspiracy Toonz

New breach: The flat earth sun, moon & zodiac app by "Flat Earth Dave" had 33k unique email addresses breached in Oct. Data included plain text passwords and users' lat and long (their position on the globe). 73% were already in @haveibeenpwned.com. More: www.youtube.com/watch?v=71FR...

02.03.2025 05:40 ๐Ÿ‘ 34 ๐Ÿ” 9 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 6
Preview
GlobeSec A collective of software development and infosec professionals dedicated to investigating apps published by flat earthers. - GlobeSec

I finally got around to creating this account ๐Ÿ˜…

We're GlobeSec, a collective of developers and #infosec people investigating privacy and security risks in apps made by flat earthers (yes, those people do exist).

We publish our research over on our github github.com/globesec

#introduction

17.03.2025 11:10 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0