little endian

8.1K posts

little endian

little endian

@HWingel

priv/acc@X: ~$

انضم Ağustos 2021
556 يتبع91 المتابعون
little endian
little endian@HWingel·
@Keir_Starmer I think they are more worried about their rights to protest and their right to state their opinion without having to fear immediate repercussions due to surveillance
English
0
0
0
5
Keir Starmer
Keir Starmer@Keir_Starmer·
I know parents are worried about social media and its impact on their children’s safety. They rightly expect fast action. Today, I’m calling on senior leaders from X, Meta, Snap, YouTube and TikTok to step up. I will do whatever it takes to keep children safe online.
English
12K
661
3.6K
926.2K
little endian أُعيد تغريده
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
338
2.8K
11.2K
721.9K
little endian أُعيد تغريده
The Lunduke Journal
The Lunduke Journal@LundukeJournal·
4 reasons why a law enforcing "Age Verification on Operating Systems" is a terrible idea: - Will likely lead to bad actors obtaining more personal information (massive collection of personal data makes too tempting of a target). - Will likely lead to a reduction in Free Speech. (Could cause significant issues for both journalists and whistleblowers.) - Does the opposite of protecting children. It builds a national database of every child who uses a computer. A database which, if the past is any indicator, will be hacked and breached. Thus putting every child in the country in increased danger. - Forcing developers to create this feature would be a violation of Free Speech (see Junger v. Daley, & Bernstein v. United States which both hold that computer code is speech with First Amendment protections). In other words: The law would be illegal, harmful to children, harmful to software developers, harmful to Free Speech and journalism... and generally make people less safe. And that's just off the top of my head.
The Lunduke Journal@LundukeJournal

New Federal Law to Require Age Verification on All Operating Systems H.R. 8250 ("To require operating system providers to verity the age of any user of an operating system, and for other purposes.") has been introduced in the U.S. Congress.

English
49
254
809
11.6K
little endian
little endian@HWingel·
@Ag_EP3 @skylermzx Thanks for your insight... I have read this before, and usually it's from YouTube or Reddit lol. Usually the same category of users that recommend VPN xyz for anonymity
English
0
0
0
21
little endian
little endian@HWingel·
@C_S_Skeptic Define friend, I guess. Probably not in the sense of a deep friendship, nope.
English
0
0
0
4
little endian
little endian@HWingel·
@mjfree Yes, recently he stated he likes to hang with "losers", but not so much "successful people" because they make him feel bad. I believe in this moment he was very sincere. Totally fits his profile so I'd say high probability of being factual
English
0
0
0
9
little endian
little endian@HWingel·
@Hasemoeffin Standard mMn, auch erschwert durch beschränkte Praxisräumlichkeiten
Deutsch
1
0
0
84
Hasemöffin
Hasemöffin@Hasemoeffin·
Arztpraxen und Datenschutz Wenn die Mitarbeiter laut telefonieren und sowohl Patientenname als auch detaillierte Diagnosen mit dem halben Wartezimmer teilen... Spannend!
Deutsch
20
12
290
7.2K
little endian
little endian@HWingel·
@RespectfulMemes I've been wondering for a while if that's a typical ADHD trait or rather widespread independent from ADHD traits
English
1
0
1
1K
little endian
little endian@HWingel·
@elonmusk even though he knows it's ridiculous, he can't help himself continuing making a fool of himself
English
0
0
0
4
Elon Musk
Elon Musk@elonmusk·
The South African laws are literally super racist, plain and simple. It’s not complicated: imagine if the law was called “White Empowerment”, instead of “Black Empowerment”! People would have a seizure 😂 South Africa now has more anti-White laws than Apartheid had anti-Black laws. Think about that for a second … The current South African government has objectively implemented Apartheid 2.0. Shame on them.
Newzroom Afrika@Newzroom405

[WATCH] "Singling out BEE laws is quite dishonest," President Cyril Ramaphosa responds to South African-born American businessman Elon Musk's claims that SA policies are racist. #Newzroom405

English
9.7K
24.5K
130.4K
12.1M
little endian أُعيد تغريده
Nav Toor
Nav Toor@heynavtoor·
You think your anonymous accounts are safe. Researchers from ETH Zurich and Anthropic built an AI system that can figure out who you really are. They tested it on Reddit, Hacker News, and LinkedIn. It works on raw text. No structured data needed. They collected 338 Hacker News users who had linked their LinkedIn profiles, then stripped all identifying information from their accounts. The AI correctly re-identified 67% of them. When it made a guess, it got the right person 9 out of 10 times. The cost? Between $1 and $4 per person. The system uses GPT-5.2 for reasoning, Gemini for matching, and Grok 4.1 Fast for shortlisting. It reads your posts, builds a profile of who you are, then searches the internet for your real identity. No human needed. Fully automatic. The old way of doing this? A method based on the famous Netflix Prize attack. It found 0.1% of people. The AI found 45.1% of people at 99% precision. That is a 450x improvement. They also tested it on Reddit. They split 5,000 people's posting histories into two halves separated by a full year. Then they asked the AI to reconnect the two halves. It matched 67.3% of people at 90% precision. The old method? 0.4%. The scariest finding: even when only 1 in 10,000 users in the database had a possible match, the AI still found 9% of them at 90% precision. The researchers wrote: "Pseudonymity does not provide meaningful protection online." They also said: "Users who post under persistent usernames should assume that adversaries can link their accounts to real identities." The more you post, the easier you are to find. Reddit users who discussed 10 or more movies across different communities were identified 48.1% of the time at 90% precision. Governments could use this to track activists. Corporations could use it for targeted ads. Stalkers could use it for $4. This is not a future threat. The attack uses publicly available AI models, standard APIs, and costs less than a cup of coffee per person. Your anonymous account is not anonymous anymore.
Nav Toor tweet media
English
32
154
375
25.5K
The Serfs (youtube.com/theserftimes)
It's one thing to feel old because you don't recognize a bunch of the artists on the Coachella poster but I honestly don't know what half these drugs are
The Serfs (youtube.com/theserftimes) tweet media
English
190
285
7.6K
245.4K
little endian
little endian@HWingel·
@herr_ort Eher Freiheit, aber Einsamkeit kommt unweigerlich ab einem gewissen Punkt dazu würde ich sagen. Je nachdem wie selbst genügsam man ist - manche Menschen können längere Zeit gut alleine sein, andere gar nicht - das Spektrum ist breit
Deutsch
0
0
1
8
Herr Dings aus Ort
Herr Dings aus Ort@herr_ort·
Wenn dich morgens niemand weckt - und abends niemand auf dich wartet. Wie nennst du das? Freiheit oder Einsamkeit?
Deutsch
293
12
302
20.5K
little endian
little endian@HWingel·
@RobLzd @flowersslop I don't get it either, what is the point of this? That he also has to eat, like the rest of us? 🤷‍♀️
English
0
0
0
1.1K
Rob
Rob@RobLzd·
@flowersslop what’s the point of this picture?? Let the man eat lunch in peace 😂
English
4
0
8
15.9K
Flowers ☾
Flowers ☾@flowersslop·
Sam Altman in front of metal catering trays during lunch at the OpenAI HQ
Flowers ☾ tweet media
English
146
62
2.3K
489.1K
little endian
little endian@HWingel·
@mel__aura Nur Schröder kann Kubicki das Wasser reichen. Hoffe er ist noch mobil
Deutsch
0
0
1
31
little endian
little endian@HWingel·
@SchopenhauerOn @KDHabibi Ehrlich gesagt nicht, finde die Performance der Regierung auch nicht besonders überraschend angesichts des Personals - Merz, zweiter Wahlgang, Spahn (!!), etc
Deutsch
0
0
2
94
Schopenhauer on Prozac
Schopenhauer on Prozac@SchopenhauerOn·
@HWingel @KDHabibi Noch nicht mitbekommen, dass die Merz-Regierung von der SPD am Nasenring durch die Manege geführt wird und im wesentlichen die linke Merkel-Katastrophe fortsetzt ?
Deutsch
1
0
6
219
Kurosch D. Habibi
Kurosch D. Habibi@KDHabibi·
Selten erlebt, dass die Stimmung im Land so schnell und drastisch kippt wie jetzt gerade…
Deutsch
70
17
582
61.1K
little endian
little endian@HWingel·
@BLUECOW009 I think it's not only due to AI but the progressing gap between the poor and (super) rich. The upward redistribution of wealth has been quickly progressing, and we already see the socioeconomic effects of it.
English
1
1
1
100
@bluecow 🐮
@bluecow 🐮@BLUECOW009·
we are so close to massive riots over AI
@bluecow 🐮 tweet media
English
2
0
6
363
Schopenhauer on Prozac
Schopenhauer on Prozac@SchopenhauerOn·
Das ist eine Illusion. "Jetzt kippt die Stimmung aber wirklich" hört man alle paar Wochen seit der Kölner Silvesternacht vor 10 Jahren. Gekippt ist nix. Im Gegenteil: Medien und Regierung werden immer noch grüner, linker, woker. Warum ? Weil die Stimmung von den Mainstream-Massenmedien fabriziert wird. Diese verfügen immer noch über hundertmal mehr Reichweite als alle rechts-alternativen Twitter-Blasen zusammen.
Deutsch
5
1
77
5.7K