Kata Saya

2.1K posts

Kata Saya banner
Kata Saya

Kata Saya

@Tree_0flife

Love science & philosophy. Eastern Orthodox. Papuan/Indonesian Engaged in preservation of Papuan natural world & culture

Nusantara انضم Temmuz 2025
731 يتبع66 المتابعون
Christa Sydney
Christa Sydney@christasyd·
Kakaknya Paus Leo XIV yang di Chicago, John Prevost, dapet ancaman bom...
Indonesia
1
18
144
2.8K
Kata Saya
Kata Saya@Tree_0flife·
@philvischer Oh he may question Trump only to follow what ever answe I mean instructions his orange master gives him
English
0
0
0
0
Phil Vischer
Phil Vischer@philvischer·
Though some religious leaders may question Donald Trump, Franklin Graham will never question Donald Trump. Never.
Franklin Graham@Franklin_Graham

I had received some questions about President @realDonaldTrump's recent posts, and here are my thoughts: I do not believe President Trump would knowingly depict himself as Jesus Christ—that would certainly be inappropriate. I’m thankful the President has made it very clear that this was not at all what he thought the AI-generated image was representing—he thought it was a doctor helping someone, and when he learned of the concerns, he immediately removed the post. When I looked at the illustration, I didn’t jump to the same conclusion as some. There were no spiritual references—no halo, there were no crosses, no angels. It was a flag, soldiers, a nurse, fighter planes, eagles, the Statue of Liberty, and I think this is a lot to do about nothing. There is so much ill-intended speculation. I think his enemies are always foaming at the mouth at any possible opportunity to make him look bad. And the illustration from someone else he reposted on Truth Social yesterday, I must say that I like the fact that this is a picture of Jesus whispering in his ear, or at least His hand on his shoulder, guiding him. We all need that—we all need to be listening to Jesus. Again, I think there is an attempt to spin this into something that it isn’t. Remember, President Trump didn’t draw this, he didn’t create it, he reposted it on his social media because he thought it was nice—I would have to agree. I’m not a Catholic, I’m an evangelical, but I appreciate how President Trump has defended religious freedom for people of all faiths, including millions of evangelicals and Catholics in the U.S. and around the world. He is the most pro-Christian, pro-life president in my lifetime, and he doesn’t shy away from it. I would hope that the President and Pope Leo can meet at some point, and that the Pope would have the opportunity to thank the President for his efforts to protect religious liberty for Catholics and people of all faiths.

English
61
39
803
28.8K
Kata Saya
Kata Saya@Tree_0flife·
@naomibrockwell Same. Plus it allows me to get rid of clutter - those apps you rarely use and don't really need but have forgotten about!
English
0
0
0
2
Naomi Brockwell priv/acc
Naomi Brockwell priv/acc@naomibrockwell·
When I get a new device, I don't restore from backup. A new device means a fresh start: better privacy, stronger security, and no digital clutter. You’d be shocked at the digital traces that follow when you transfer your setup.
English
24
142
848
20.3K
Kata Saya أُعيد تغريده
Paul Moore - Security Consultant 
I'm genuinely stunned by how many people push back on the #EU #ageVerification issues with "it's a demo, it's not a production app... don't you understand?!" When the President of the EC publicly states it's "technically ready, reaches the highest standard of privacy and go check the code"... it shouldn't come as a surprise when someone does just that. There's a growing number of people screaming "it's protected by Android, this is a non-issue". I don't know about you... but I'd rather have a few layers of substantial security to protect my biometric data than rely on a 3rd-party layer which may fail or have bugs/flaws of its own. This app was supposed to set a standard, not fall back to one.
GIF
English
32
74
328
11.2K
Kata Saya
Kata Saya@Tree_0flife·
I am not Catholic. But the Catholic Church is not a denomination. It is a church. Only protestants have denominations because only protestants are so badly splintered into uncountable splits and schism. I mean for a group insisting "sola scriptura is all you need, it's amazing how completely unsatisfactory that has proven given there isn't one single protestant church. That fact alone shows how ridiculous ss is.
English
0
0
0
3
Bill Mitchell
Bill Mitchell@mitchellvii·
@Postcardstopa Weird that you think the Catholic church is THE Church. There are literally hundreds of Christian denominations and the Catholic church is one of those.
English
18
0
12
507
Bill Mitchell
Bill Mitchell@mitchellvii·
I can't speak for anybody else, but I don't believe in the Pope. I see no biblical justification for his existence. Peter was the rock that Christ was going to build his church upon, but there's no mention of a successor to Peter. I personally don't like the Pope's politics.
English
262
76
676
8.8K
Keith
Keith@gnukeith·
You legitimately don’t need any of these, GSB is pretty good + anti-malware lists in ad-blockers If you are on Windows, Windows defender is more than good As for Linux, Linux doesn’t get viruses everyone knows that MacOS, I have no idea what they have but I have so much shit downloaded on it that it might as well be backdoored
PCMag@PCMag

We've tested more than 40 antivirus utilities to help you pick the best protection. pcmag.com/picks/the-best…

English
11
1
80
6.7K
Kata Saya أُعيد تغريده
Paul Moore - Security Consultant 
Let's shift focus and explain why the #EU #AgeVerification concept is fundamentally flawed. Assume: 1. The production app is released. 2. It's 100% secure, 100% private (fantasy land, but stick with me) 3. It cryptographically challenges every step, including hardware attestation which requires a physical device. 4. Every single other attack vector in the surrounding environment is somehow magically patched. aka - it's working exactly as intended/designed. It does not protect against a relay attack. This is a threat they considered and somewhat addressed here: github.com/eu-digital-ide… With the current design, there's nothing preventing someone running a verification-as-a-service; a remote Android device which returns a valid attestation. Remember, it's not returning "I am over 18", it returns "someone is over 18". Neither the verifier, nor the app has any way to link the session ID to a physical device. Their own docs state this clearly: Remote Cross-Device Presentation: "Note that the Wallet Instance does not see any difference between the cross-device flow and the same-device flow. In both cases, it receives an OpenID4VP-compliant presentation request over the Wallet Instance-platform API described in the previous section." This is a known & well-understood attack vector in all remote credential presentation models; it's just not mitigated in this one... primarily because they can't. CTAP 2.2 won't work with all app flows, hardware attestation doesn't mitigate relay attacks, on-demand liveness detection would be too intrusive & potentially privacy-invasive & timing calculations don't reveal anything useful... all the available options to resolve this break the core design; completely anonymous age verification. The Architecture & Reference Framework (ARF) is technically sound in some respects. They considered external threat actors and discussed solutions to mitigate them, including ZKP. However, the EC applied the wrong threat model, thus arriving at the wrong conclusion. Yes, you need to protect against malicious verifiers, phishing sites, session hijacks, data brokers et al... but that's addressing external threats, it doesn't protect the architecture from the user itself. In virtually every other scenario, the user and system's interests are aligned; protect my biometric asset at all costs. Specifically for age verification, most users do not want to present ID simply to access a website, so whilst the system may adequately protect from external threats, if the user wants to bypass the system, they can... and the architecture doesn't consider this. Every single applied mitigation assumes the user is the protected party, not the threat actor. To those people claiming "it requires physical access to the device and root, this is BS/hyperbole", you too applied the wrong threat model & completely missed the point. These disclosures demonstrate that you, the user, are the threat actor they haven't considered. You have your device. You can root your device. You can create a chrome extension, just as I did. Ironically, it's precisely those under 18 who can't pass verification who are motivated to bypass it. So where does that leave us? A system which replaces "I am over 18" with "someone is over 18", with absolutely no guarantee that it's true... which is the entire purpose of the app.
Paul Moore - Security Consultant @Paul_Reviews

Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step 3: Continue using the web as normal The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts". This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring. Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.

English
14
111
320
18.6K
Kata Saya
Kata Saya@Tree_0flife·
Putting aside that your point is in complete contradiction to the Gospels/teachings of XC - your argument is philosophically weak. Such a line of reasoning could be be used to justify just about anything. It's also based on your perception rather than objective reality. Because you are maga, you think this is the way to go. If Obama or Biden pulled a stunt like this/these, you would sing a different song.
English
0
0
0
2
Melissa the Hopeful🏠Homemaker
Trump is exactly right. It is "a nasty world," and as president, he is one of God's appointed servants to execute wrath on the evildoer (Rom. 13). He does not have the luxury of piously pontificating from within a walled castle while pretending that peace can always be obtained without the wielding of the sword.
Rapid Response 47@RapidResponse47

.@POTUS: "I have nothing against the Pope... If the Pope looked at the 42,000 people that were killed over the last two or three months, as [protesters] with no weapons, no nothing... I have a right to disagree with the Pope."

English
31
21
157
5.6K
✝️Pray Without Ceasing✝️
Catholics have been so thoroughly deceived that many sincerely believe the Catholic Church wrote the Bible, that no Scriptures existed before the Church, and that every Pope is personally infallible. Some even claim Jesus was a “Roman Palestinian” and that Mary has the power to forgive sins. This is the inevitable result of following human traditions and church authorities instead of the Scriptures alone. When doctrine is built on the shifting sands of men rather than the unchanging Word of God, it leads souls away from the true Gospel — and Scripture warns that path ends in destruction.
English
146
177
659
9.7K
Kata Saya
Kata Saya@Tree_0flife·
@APBIOonly @brianbeutler really? You haven't read your history books. Would you like a list or would you prefer to google it yourself?
English
0
0
0
4
Brian Beutler
Brian Beutler@brianbeutler·
1. The new MAGA line on Orban—“if your entrenched ruling party can lose everything in a wave election, you are not living in an authoritarian state”—is fallacious, and something they plainly don’t believe. Unless maybe they’re prepared to abide Trump-style abuses turned on them.
Brian Beutler tweet media
English
10
111
570
226.7K
Kata Saya
Kata Saya@Tree_0flife·
Why do protestants call the schism with the RCC a "reformation"? A reformation is, "the act or process of improving something—an institution, practice, or person—by making significant changes to correct faults or enhance its condition. It implies a positive transformation or structural overhaul" What actually happened in Europe when Luther got going: * 100+years of war * estimates of 4 to 12 millions deaths * protestant killed protestants Wow. So positive. Such a reform! It was a revolution, full of blood, death and pain. Calling it a reformation is actually dishonest. Its a lie.
English
0
0
0
4
Kata Saya
Kata Saya@Tree_0flife·
@megbasham Yes, i agree. He does expose hypocrisy. You, Erik, Mohler , Franklin and all you Folk protestants.
English
0
0
0
84
Megan Basham
Megan Basham@megbasham·
This is not just the correct response but politically smart. Love him or despise him, Trump, in his instinctual way, has a habit of exposing hypocrisy and trite religious sloganeering for what it is. In the face of the kind of brutality the IRCG represents, rhetoric about unity and peace is obviously empty.
Andrew Kolvet@AndrewKolvet

A pretty amazing response from President Trump to this reporter question: REPORTER: Iran is going to execute four more protesters, including the first woman protester. What do you tell Iran? TRUMP: Tell that to the Pope.

English
92
265
1.7K
53K
Kata Saya أُعيد تغريده
Paul Moore - Security Consultant 
Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step 3: Continue using the web as normal The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts". This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring. Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

English
261
2.8K
11K
941.5K
Kata Saya
Kata Saya@Tree_0flife·
@AiG Says no creed, foundational church teaching or church father or Jesus XC. Its pure AIG. Technically that's a heresy...
English
0
0
0
12
Answers in Genesis
The age of the earth matters because God’s character matters.
English
28
31
149
3.2K
Kata Saya
Kata Saya@Tree_0flife·
So the European Union has officially released their Age ID app. They claim it's perfectly safe, private and secure. Security programmers have already hacked it. 🤦‍♂️ Never. Ever. Trust. A government when it says "completely safe and secure". Also, never trust big tech with such claims.
English
0
0
0
12
Kata Saya
Kata Saya@Tree_0flife·
@christasyd Well.. you are a woman and you touched it so.. 🤷🏿
English
0
0
3
62
Christa Sydney
Christa Sydney@christasyd·
Met a Benedictine monk who said my art "doesn't have a woman's touch" and last week the AC service guy said my room "doesn't have a woman's touch" Would those have been a good opportunity to come out as genderfluid or
English
3
0
21
471
Kata Saya أُعيد تغريده
Paul Moore - Security Consultant 
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
Paul Moore - Security Consultant @Paul_Reviews

.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRri…

English
622
5.9K
23.4K
3M
Kata Saya
Kata Saya@Tree_0flife·
Reformation?? Why do protestants call it that? A reformation is, "Reformation is the act or process of improving something—an institution, practice, or person—by making significant changes to correct faults or enhance its condition. It implies a positive transformation or structural overhaul" What actually happened in Europe * 100+years of war * estimates of 4 to 12 millions deaths * protestant killed protestants Wow. So positive. Such a reform! It was a revolution, full of blood, death and pain.
English
1
0
0
82
Colin J. Smothers
Colin J. Smothers@colinsmo·
A lot of people this week realizing why there was a Reformation.
English
146
100
945
18.4K