66
submitted 1 day ago* (last edited 1 day ago) by spectre@hexbear.net to c/videos@hexbear.net
all 13 comments
sorted by: hot top new old
[-] daniyeg@hexbear.net 28 points 23 hours ago* (last edited 23 hours ago)

based on how coffeezilla talks about it, how easy it is and similar stories from the past, i suspect that their website generated shipping labels, receipts or whatever automatic documentation that is given to customers as a proof of purchase, and stored it on the server in a way that could be publicly served to everyone not just the original customer. this way you just have to know the file's name, which was probably generated in a deterministic way, in order to extract people's information. with this you usually won't get everyone's information so 10k is probably an underestimate.

if this is the exploit, this is basic web security from like early 2000, with reoccurring minor drama about small sites fucking it up until mid 2010s. they either hired some boomer (or worse former government contractor) to shit it out with raw php or some kid (and i mean literal kid, most likely 14 as even 15 year olds won't make this mistake) to do this as a summer job. embarrassing even if this wasn't how it was done.

EDIT: looking again at the coffee video, the data has a column account_status which wouldn't make sense with what i just described. however it could be basic SQL injection, which is still laughable but increases the age rage from 14 to 16. just wanted to say the original comment i made 10 minutes ago is wrong lmao.

[-] microfiche@hexbear.net 41 points 1 day ago* (last edited 1 day ago)

I get that dumbasses like coffeezilla were likely doing it to get info to make content with but wtf did he expect, really? I'm sure he was just getting one to glean whatever info he could, but he also should have used a remailer service and a throwaway cc number. Did anyone expect a secure, seamless experience when dealing with the dang Cheeto in the White House?

[-] spectre@hexbear.net 28 points 1 day ago

I would have to assume that both YouTubers used a PO box for their orders. Im not sure why you would consider coffeezilla a dumbass, I don't think I've ever seen something from his corner that would be objectionable.

[-] microfiche@hexbear.net 9 points 19 hours ago

He states 'my mailing address, phone number, and credit card info'

That's a dumbass move.

[-] AnarchoAnarchist@hexbear.net 9 points 17 hours ago

I haven't seen the actual data leaked, I don't have time to watch a video, but you're paraphrase still doesn't mean that he couldn't have put a PO box, a burner phone, And a temporary credit card number.

The dude has made a career out of exposing scammers, I doubt that he actually put his home address and his personal cell phone number.

[-] FuckyWucky@hexbear.net 30 points 1 day ago

Crime is legal

[-] FlakesBongler@hexbear.net 31 points 1 day ago
[-] SkingradGuard@hexbear.net 9 points 19 hours ago

I love the cope from turboCHUDs saying "it's not a scam, the phone is real!!!"

[-] miz@hexbear.net 21 points 1 day ago

I love that this isn't even the only Trump scam phone, this is just the one that is a real product

[-] spectre@hexbear.net 24 points 1 day ago

In case anyone around here was considering it, it is a bad idea to buy a Trump Phone before they get this fixed.

[-] blarth 1 points 1 day ago

And also if they ever do fix it.

[-] HexReplyBot@hexbear.net 2 points 1 day ago* (last edited 1 day ago)

I found a YouTube link in your post. Here are links to the same video on alternative frontends that protect your privacy:

this post was submitted on 20 May 2026
66 points (100.0% liked)

videos

23304 readers
93 users here now

Breadtube if it didn't suck.

Post videos you genuinely enjoy and want to share, duh. Celebrate the diversity of interests shared by chapochatters by posting a deep dive into Venetian kelp farming, I dunno. Also media criticism, bite-sized versions of left-wing theory, all the stuff you expected. But I am curious about that kelp farming thing now that you mentioned it.

Low effort / spam videos might be removed, especially weeb content.

There is a cytube that you can paste videos into and watch with whoever happens to be around. It's open submission unless there's something important to commandeer it with at the time.

A weekly watch party happens every Saturday (Sunday down under), with video nominations Saturday-Monday, voting Monday-Thursday. See the pin for whatever stage it's currently in.

founded 5 years ago
MODERATORS