Foundry

Foundry · moving f0rth

post-incident notice · disclosure

the dashboard is gone. what is left is the lesson.

01

Notice

post-incident notice

that's what happens when you blindly copy a feature from others.

F0RTHSP4CE switched on Telegram's new Community feature the moment it landed, the way you adopt anything everyone else is already using, without checking what it turned on. it quietly opened the entire internal chat history to anyone who wandered in. years of private messages, wide open.

what you would have found here is the gentle version: a public, anonymised analytics dashboard built from that leak, names redacted, nothing weaponised. someone with worse intentions and the exact same access could have done far more than make charts. this was a tap on the shoulder, not the worst that was sitting on the table.

enabling a feature is easy, and that is the trap. read what it exposes, test it, model the threat before you flip it on. the discipline is cheaper than the cleanup.

02

Read before you copy

a/b testing · qa · security
A/B testing Ship changes as measured experiments, not vibes A starter guide to hypotheses, sample size, and letting a test run its full course before you trust the result. contentful.com → QA · security testing OWASP Web Security Testing Guide The framework pentesters use to test a web app before it ships. If a copied feature exposes data, this is where you catch it. owasp.org → Security · reuse OWASP Top 10 — Vulnerable & Outdated Components The risk that comes free with every reused component and copied dependency you never actually vetted. owasp.org →
03

Built on Foundry

the entire page and data ontology was built with Palantir Foundry. Learn more about the ontology, actions, and platform palantir.com/docs/foundry →