Jon_HQ (@jon_hq) 's Twitter Profile
Jon_HQ

@jon_hq

Follow for Web3 security alpha.

My clients include @PudgyPenguins, @Doodles, etc.

Contributor @BoringSecDAO @Server_Forge

I provide Discord audits. DMs open

ID: 14352891

linkhttps://jonhq.com/tweet-threads/ calendar_today10-04-2008 16:46:41

7,7K Tweet

18,18K Followers

3,3K Following

Jon_HQ (@jon_hq) 's Twitter Profile Photo

This is a really good reminder that even if you do everything right, you can still get screwed. This is a good reminder that if you're dealing with size in crypto, having a crypto specific device (laptop) which is the only thing that handles swaps/sending/etc and isn't used for

Jon_HQ (@jon_hq) 's Twitter Profile Photo

If you can't accept a Discord invite to join a server, here are some troubleshooting steps: 1: Did your alt get banned? Your main will be banned too. 2: ...did your main get banned? Hashbot sometimes at fault here. 3: Have you joined a ton of servers? Discord could be rate

Jon_HQ (@jon_hq) 's Twitter Profile Photo

Good morning. I'm here with some tough love, please sit down. If your Discord got compromised (and a fake announcement goes out): Obviously you go and remove the compromised account/patch up any holes the account made. If you stop there, here's a surprise, it'll happen again.

NFT_Dreww.eth (@nft_dreww) 's Twitter Profile Photo

⚠️WTF are backup codes??....⚠️ ALOT of people do not have their backup codes, which means if you lose your 2FA, you have no way of getting back into your account... I'm going to show you how to properly get/store your backup codes for X, Discord, and Gmail below ⤵️⤵️⤵️ 1/ What

⚠️WTF are backup codes??....⚠️

ALOT of people do not have their backup codes, which means if you lose your 2FA, you have no way of getting back into your account...

I'm going to show you how to properly get/store your backup codes for X, Discord, and Gmail below ⤵️⤵️⤵️

1/ What
Jon_HQ (@jon_hq) 's Twitter Profile Photo

Adding new channels in Discord can impact your community in a lot of negative ways. Each new channel introduces a new potential for a security risk. More channels, more permissions, more chances for something to screw up. New channels can split the community in half. It

Jon_HQ (@jon_hq) 's Twitter Profile Photo

One of the greatest security weaknesses for crypto-companies: Marketing People. I wish I was joking, but they're customer facing, and often require elevated access to important information, customer data, and more. I think a big way to impart the seriousness of this industry,

Jon_HQ (@jon_hq) 's Twitter Profile Photo

Faking an account takeover is not a marketing stunt. It is a stunt that will instantly get security people to hate you. You've cried wolf. You will not get help when an actual incident occurs. If you're a marketing person, please head this warning, don't fake hacks, ever.

Jon_HQ (@jon_hq) 's Twitter Profile Photo

Issues with Carl-bot are resolved. Please report issues responsibly and don't 'report them' to teams by publicly abusing them at 6 am :') Thank you to carl-bot dev and team for handling it quickly!

Jon_HQ (@jon_hq) 's Twitter Profile Photo

It is easy to secure a Discord server. Remove permissions from all roles, have a single verified role with non dangerous permissions on it, remove all channel permission overrides. It is, however, damn hard to secure a Discord server and still have a functioning team inside it

Jon_HQ (@jon_hq) 's Twitter Profile Photo

tldr fractionalized share holders forgot to participate and didn't vote down a buyout. not your governance participation, not your keys?

Jon_HQ (@jon_hq) 's Twitter Profile Photo

Discord doesn't let you use "|" or any type of spaces in a channel name. There are a couple different symbols I like to use though: "│" for spacing out an emoji at the start of a channel name. "・" alternative small spacer "┃" alternative thick spacer I really don't

Jon_HQ (@jon_hq) 's Twitter Profile Photo

I spend a good amount of time doing cold outreach to various crypto/defi/web3 Discord servers. I take a quick look, make some general notes and send them to the team about ways they could improve. I usually don't shill my services upfront. If they want more help they'll ask,