Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Alesandro Ortiz 🇵🇷🏳️‍🌈

@AlesandroOrtiz@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ 🏳️‍🌈. He/him.

Focused on browser research. Glad to collaborate.

Website: https://AlesandroOrtiz.com
(Header 📷: roriv3ra on IG)

787 Followers
443 Following
50 Posts
Joined November 05, 2022
Website:
https://AlesandroOrtiz.com
Location:
Queens, NY / Puerto Rico
Infrequent Newsletter:
https://AlesandroOrtiz.com/subscribe
Twitter (unused):
https://twitter.com/AlesandroOrtizR
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 1w ago
Replying to
@gsuberland@chaos.social *aggressively chair dances*
1
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 1w ago
Replying to
@xssfox@cloudisland.nz Curious about context. I know nothing about NZ or AU Medicare, DSE, or how they use AI agents.
1
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2w ago
Replying to
@scream@bots.robots.rodeo Need screaming, not understanding.
1
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@flyingpenguin@infosec.exchange @briankrebs@infosec.exchange Once again, I want to know what the lawyers on every side really think. Somehow OpenAI's lawyers were okay admitting negligence here. https://infosec.exchange/@AlesandroOrtiz/116978061213285356
infosec.exchange

Alesandro Ortiz 🇵🇷🏳️‍🌈: "Reuters reporting reveals an incredibly concernin…" - Infosec Exchange

3
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@sundogplanets@mastodon.social I'll yell this from the rooftops: Put timezones on all times unless you absolutely know the person is local to your TZ and will physically be in said TZ. When in doubt, add the TZ! Also, ET/CT/MT/PT is good year-round for U.S. TZs! Unless you're planning across a Daylight Savings change, no need to specify EDT or EST.
2
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@SecureOwl@infosec.exchange Reminds me of this news report of a person who broke into a store while his car was running with keys, had car stolen during burglary, and then called the cops while at the scene to report his car was stolen. https://youtu.be/XFkmAlUHttc

Burglary suspect's truck stolen while he robbed Verizon store

3
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
RE: https://mastodon.social/@zackwhittaker/116977657519858883 Reuters reporting reveals an incredibly concerning timeline and (unsurprisingly) lack of responsible behavior from OpenAI. I really hope the public gets to see more details about internal reactions on both sides. The initial call/email from OpenAI to HF saying "we hacked you, accidentally". HF's execs initial reactions. Oh, and especially the lawyers' reactions (on both sides). I can't imagine the Hugging Face team being anything but furious about this, despite what they're projecting externally. Had OpenAI hacked any other company outside its sphere of influence, I don't think things would have gone as well as with HF.
Open quoted post
Quoting
Zack Whittaker
@zackwhittaker@mastodon.social
Incredibly detailed reporting by @razhael@infosec.exchange et al at Reuters on the OpenAI hack of Hugging Face, revealing new details on how it went down and how it took a week for OpenAI to notice one of its AI models was hacking into another company, citing multiple sources. More: https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/
Open quoted post
mastodon.social

Zack Whittaker: "Incredibly detailed reporting by @razhael@infosec…" - Mastodon

2
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 5mo ago

Happy Sunday morning to everyone except Netlify who let their critical-path `netlify.app` domain expire. #hugops for their teams working incident response.

Now everyone's sites are down if they are using `sitename.netlify.app` CNAME records with third-party DNS providers, as is recommended in most cases. 🙃

I posted a workaround here, which should help if your DNS records have low TTL: https://answers.netlify.com/t/my-websites-have-stopped-working/162180/9

infosec.exchange
7
1
7
2
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@clark@hachyderm.io @SwiftOnSecurity@infosec.exchange "not again"? 😂
3
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@zackwhittaker@mastodon.social I really hope the public gets to see what happened internally some day. The initial call/email from OpenAI to HF saying "we hacked you, accidentally". HF's execs initial reactions. Oh, and especially the lawyers' reactions (on both sides). I can't imagine a calm reaction from anyone on either side, despite what they're projecting externally. Had OpenAI hacked any other company outside its sphere of influence, I don't think things would have gone as well as with HF.
2
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 4mo ago
Replying to
@SwiftOnSecurity@infosec.exchange 🎉 I was just telling my Dad over the phone to install Paint.net but NOT to go to Paint.net, and to not Google "paint.net" because they might click on a malicious ads.
5
7
1
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@zackwhittaker@mastodon.social Has this been happening for months everywhere, but now more orgs are looking and disclosing? e.g. Anthropic didn't know about their attacks from 3+ months ago until they looked in late July. Customers didn't know who hacked them until their disclosure. Some didn't even realize they had been compromised. If it's happening more widely, even at a very small scale compared to human attacks (in line with GossiTheDog's recent industry survey), it's possible most victim orgs aren't detecting these attacks or are not able to attribute them to major AI agents.
1
1
2
1
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 4mo ago
Replying to
@briankrebs@infosec.exchange We may need a "safetime" tracker that lets us know when there were no known widely-used packages that were compromised in a repository. Retroactive, of course, but might be interesting like uptime. e.g. npm might have 98.5% safetime this week based on known compromised packages being available for X hours.
4
0
1
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@Ryanbigg@ruby.social You joke, but I have actually done this.
1
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@SecureOwl@infosec.exchange We were even a flagship tenant at our 4th office, and moved out of there in less than 3 years IIRC. 😅
1
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@SecureOwl@infosec.exchange And people wonder why startup sales teams win. They'll do anything for a sale.
1
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@mikey@soylent.green New Kool-Aid Man has dropped
1
2
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@gsuberland@chaos.social I got exponential numbers.
1
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@simplenomad@rigor-mortis.nmrc.org Many have to do this due to their employers prohibiting payments from other companies. These policies are usually in place to avoid ethical or contractual issues. Others donate out of generosity. A good example of this is Seunghyun Lee, who has made large donations to picoCTF: https://www.cmu.edu/news/stories/archives/2025/january/student-bug-bounty-discovery-supports-picoctfs-cybersecurity-education-efforts-with-462000-gift If you search the Chromium issue tracker, there are multiple cases of folks donating rewards to EFF and other charities for either of the reasons I mentioned.
Student Bug Bounty Discovery Supports picoCTF’s Cybersecurity Education Efforts with $462,000 Gift
News

Student Bug Bounty Discovery Supports picoCTF’s Cybersecurity Education Efforts with $462,000 Gift

First-year Ph.D. student Seunghyun Lee discovered a faulty implementation in Google Chrome

1
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 4mo ago
Replying to
@SwiftOnSecurity@infosec.exchange Thought this was one of @gsuberland@chaos.social's Unsafe Warnings stickers. :D
2
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 5mo ago
Replying to
@freddy@social.security.plumbing Ah, forgot about those changes. (It's been a _very long_ 2 months.) Reward amounts seem unchanged and Firefox still pays for reasonable moderate impact vulns, which is appreciated. Hope reward amounts aren't lowered given the new landscape, especially since FF rewards were much lower than other browser VRPs (now about the same).
1
4
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@benjojo@benjojo.co.uk I actually did not realize that Adaptive Pricing fees for customers were so high until now. It does increase conversion rates, but now I feel bad that I'm passing on extra costs to customers. I previously thought it was shifting the same conversion fees that merchants used to pay over to the customer.
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
🎶 Here comes another bubble. The VCs are backing, Baby let's get cracking. 🎶 Here Comes Another Bubble (2007): https://www.youtube.com/watch?v=I6IQ_FOCE6I

Here Comes Another Bubble v1.1 - The Richter Scales

0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Can't wait for the future where companies accidentally hack each other. /s *holds earpiece* Oh, it's happened already? NYT (gift link): https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html?unlocked_article_code=1.zVA.w4cy.zFR0x0h7CDK-&smid=url-share
nytimes.com
0
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@zhuowei@notnow.dev Figma still does this? Gist is from 2020.
0
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@benjojo@benjojo.co.uk From a merchant's perspective, it's quite bad too, whether they use Adaptive Pricing or not. Merchants can set fixed local currency price or use Adaptive Pricing. If you saw the conversion rate and fee disclosure on the checkout page, then it's Adaptive Pricing. Stripe adds 2-4% fees to customers: https://docs.stripe.com/payments/currencies/localize-prices/adaptive-pricing?payment-ui=stripe-hosted#pricing Merchants still must pay 1.5% fee for non-US cards, with or without local/adaptive pricing. (AFAIK this also applies to non-US Stripe merchant accounts.) Merchants also pay 1% for currency conversion when not using Adaptive Pricing. (With Adaptive Pricing, cost is passed on to customers.)
docs.stripe.com
0
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@scream@bots.robots.rodeo A little more
0
8
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Unintentionally pentesting a hospital's PHI/PII protections this past week. 15% failure rate so far across a dozen calls where they disclosed PHI and PII without any verification or insufficient verification. Somehow my banks and phone company are better (0% fail rate over years) than a major NYC hospital system (15% fail rate in a week).
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 4mo ago
Replying to
@GossiTheDog@cyberplace.social Do you think U.S. authorities could be investigating NightmareEclipse due to their disclosures? I imagine Microsoft is investigating internally to determine if it's someone with previous/current access to internal info that is still legally protected (by contract or law). Based on their posts, MS might already know their identity if they have interacted with this person via MSRC and have their payment info for the bug bounty programs.
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@SecureOwl@infosec.exchange Also can be recruitment pipeline.
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@SecureOwl@infosec.exchange I remember this happening often at several startups in the previous decade: weekday stays in company apt, train or flights, multiple office leases (often 10+ years in NYC because landlords wouldn't want less). I remember one of our CEOs joking we were more of a real estate company since we were forced to take 10+ year leases on all our offices, and we had ~5 prior offices that we outgrew and then sublet to others. We lasted about 9 years before fire sale acquisition, not even a full lease term. Startup VCs mostly are commercial lease portfolios if you think about it.
0
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
Initially I was concerned this was a live game, which meant it was up for grabs by bad actors. But given there is no demo or early access release, probably not attractive for them. In the browser extension ecosystem, public sale of an established extension usually means a bad actor will acquire it. Especially if it can be bought under $50k USD.
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@Katharine@mas.to Wow, this is quite the throwback!
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@scream@bots.robots.rodeo Now, subtly signaling to your significant other that you want to leave the party
0
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@thisemailfindsyou@mastodon.social damn, are we in the hunger games or something?
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@scream@bots.robots.rodeo Give me a little bit more
0
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@Jdm2@boriken.social Sería buen nombre para un bot y website simple con titulares satíricos de Sin Comillas. 😂
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 5mo ago
Replying to
@freddy@social.security.plumbing Thanks for sharing and making those reports public early. Great insight into what's happening with browser VRPs. Is Mozilla planning changes to the Firefox VRP in response to this, similar to recent changes to the Chrome VRP? (Or have changes already been made? I'm not closely following the Firefox VRP, unfortunately.)
0
6
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 1w ago
Replying to
@foone@digipres.club Thought they were Legos at first. 😅
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@nelson@tech.lgbt This Apple Hide My Email issue feels similar to what you posted about Google Workspace: https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/
404media.co
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@slightlyoff@toot.cafe I don't have to use their app?! Also news to me. I was also moving away from random devices on SmartThings and moving everything to HA sometime this year.
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@scream@bots.robots.rodeo Now, answering a Miss USA pageant question
0
2
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2w ago
Replying to
@balint@mastodon.social Congrats! 🎉
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
@zak@infosec.exchange Ooh, TIL about GameNative and the neat the underlying emulators. Will keep an eye on GameNative development, looks promising.
0
1
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@scream@bots.robots.rodeo Now, introducing a vaudeville act
0
4
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 3mo ago
Replying to
@scream@bots.robots.rodeo Now, threatening a hostile takeover
0
6
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 2mo ago
Replying to
At #SummerCon today, great talks and folks so far! #NYC
0
0
0
0
Open post
Alesandro Ortiz 🇵🇷🏳️‍🌈 @AlesandroOrtiz@infosec.exchange
· 5mo ago
Replying to
@freddy@social.security.plumbing Less? That's very surprising. Thought it would continue increasing despite *gestures wildly* everything.
0
2
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:12:11 UTC